Werbung: SecurityConsole.de verwaltet Ihre Computer mit Security Essentails aus der Cloud!
30 Tage kostenfrei testen und 20% Rabatt für Ihre Bestellung mit Promocode: WBF2685582
(Promocode gültig bis 31.12.2011)

Group:  English: Windows Server » microsoft.public.windows.server.update_services
Thread: Updates showing as needed when not approved.

HTVi
TV Discussion Newsgroups

Updates showing as needed when not approved.
Kiv 6/14/2007 2:40:00 PM
We have moved to WSUS 3 recently and I have noticed that when an update is
approved on a single group it then shows as needed even on the groups it is
not approved for.

An example is that we have approved .NEt 2 framework to go to desktop
machines but it is showing up as needed by every machine on the estate. Is
there a way for WSUS 3 to show updates as not applicable on the groups that
it is not approved on?

Thanks

KIV
Re: Updates showing as needed when not approved.
"John J. Jobst" <john.j.jobst[ at ]us.army.mil> 6/14/2007 2:46:47 PM
I believe "needed" means that the computer has the appropriate software and
conditions such it is eligible for the patch to be installed. Whether you
want to install it is up to you, which is why you have segregated your
machines into groups and have approved the patch for certain groups but not
for others. WSUS would appear to be working properly.


"Kiv" <Kiv[ at ]discussions.microsoft.com> wrote in message
news:AD5F0BF2-5736-4B9F-BE68-482BF514B91B[ at ]microsoft.com...
[Quoted Text]
> We have moved to WSUS 3 recently and I have noticed that when an update is
> approved on a single group it then shows as needed even on the groups it
> is
> not approved for.
>
> An example is that we have approved .NEt 2 framework to go to desktop
> machines but it is showing up as needed by every machine on the estate.
> Is
> there a way for WSUS 3 to show updates as not applicable on the groups
> that
> it is not approved on?
>
> Thanks
>
> KIV


Re: Updates showing as needed when not approved.
BigEd 6/14/2007 3:07:01 PM

Re: Updates showing as needed when not approved.
"John J. Jobst" <john.j.jobst[ at ]us.army.mil> 6/14/2007 6:01:03 PM
I believe "needed" means that the computer has the appropriate software and
conditions such it is eligible for the patch to be installed. Whether you
want to install it is up to you, which is why you have segregated your
machines into groups and have approved the patch for certain groups but not
for others. WSUS would appear to be working properly.



"Kiv" <Kiv[ at ]discussions.microsoft.com> wrote in message
news:AD5F0BF2-5736-4B9F-BE68-482BF514B91B[ at ]microsoft.com...
[Quoted Text]
> We have moved to WSUS 3 recently and I have noticed that when an update is
> approved on a single group it then shows as needed even on the groups it
> is
> not approved for.
>
> An example is that we have approved .NEt 2 framework to go to desktop
> machines but it is showing up as needed by every machine on the estate.
> Is
> there a way for WSUS 3 to show updates as not applicable on the groups
> that
> it is not approved on?
>
> Thanks
>
> KIV


Re: Updates showing as needed when not approved.
"Lawrence Garvin \(MVP\)" <onsitech[ at ]community.nospam> 6/15/2007 3:36:17 AM

"Kiv" <Kiv[ at ]discussions.microsoft.com> wrote in message
news:AD5F0BF2-5736-4B9F-BE68-482BF514B91B[ at ]microsoft.com...
[Quoted Text]
> We have moved to WSUS 3 recently and I have noticed that when an update is
> approved on a single group it then shows as needed even on the groups it
> is
> not approved for.

Actually, it does that for any group, regardless of approval. It's the
default configuration, by design, of WSUS 3. All updates are immediately
detectable, and any computer that does not have that update installed (and
the update would be installable, if attempted), will be reported as
"Needed". If you want the update installed, set the status to "Install",
othewise, leave it at "Needed". But the client will continue to report that
the update is "Needed". (aka "Not Yet Installed").

> An example is that we have approved .NEt 2 framework to go to desktop
> machines but it is showing up as needed by every machine on the estate.
> Is
> there a way for WSUS 3 to show updates as not applicable on the groups
> that
> it is not approved on?

Nope. For the aforementioned reason concerning the auto-detect design of
WSUS 3, plus the fact that "Installed/Not Applicable" is the same status
category in WSUS 3, and finally, because it's *not* a true statement that
the update is "Not Applicable". The only true statement is that you, as a
WSUS Administration, have determined for whatever reason (and WSUS cannot
possibly anticipate what those might be), that you're not going to install
that update.

It does not, however, change the simple fact that it is an installable
update, and it's not installed.

And... to borrow from my other post a few minutes ago, because I think this
point needs to be reinforced vis-a-vis this particular quirk of WSUS 3.0:

======================
Also, consider the alternative scenario to how WSUS 3 currently works:

Consider that the report really did only show the status of the updates
you had APPROVED for Installation. Consider that... ooops... you forgot to
approve a security update that should have been approved. Well, in the
alternative, your computer would show 100% GREEN, because it's installed all
of the =approved= updates, even though it has not installed all of the
=needed= updates. Now, answer this question: The pie chart shows 100% GREEN.
Is the computer compliant with your security update policy? Or, would you
rather see that "Missing, but Not Approved" status reflected in the
computer's report?

Personally, I'd rather *know* that I have to discount those three
updates that are making 2% of my pie chart yellow, and that I'm 98%
compliant BY CHOICE with the =available= updates, than to be misled into
believing I've installed 100% of the =needed= updates, only to find out
after a security breach that I missed a critical security update that never
got installed.

======================



--
Lawrence Garvin, M.S., MCTS, MCP
Independent WSUS Evangelist
MVP-Software Distribution (2005-2007)
https://mvp.support.microsoft.com/profile=30E00990-8F1D-4774-BD62-D095EB07B36E

Everything you need for WSUS is at
http://technet2.microsoft.com/windowsserver/en/technologies/featured/wsus/default.mspx

And, almost everything else is at
http://wsusinfo.onsitechsolutions.com
.....


Re: Updates showing as needed when not approved.
Kiv 6/15/2007 7:47:03 AM
I had a feeling this was the way it was designed to work but the management
like to see a nice field of green when looking at the console.

Thanks for the excellent explanation which I'm sure will help the people who
raised the question realise that it's not necessarily a bad thing that we
aren't 100% green.

kiv

"Lawrence Garvin (MVP)" wrote:

[Quoted Text]
>
> "Kiv" <Kiv[ at ]discussions.microsoft.com> wrote in message
> news:AD5F0BF2-5736-4B9F-BE68-482BF514B91B[ at ]microsoft.com...
> > We have moved to WSUS 3 recently and I have noticed that when an update is
> > approved on a single group it then shows as needed even on the groups it
> > is
> > not approved for.
>
> Actually, it does that for any group, regardless of approval. It's the
> default configuration, by design, of WSUS 3. All updates are immediately
> detectable, and any computer that does not have that update installed (and
> the update would be installable, if attempted), will be reported as
> "Needed". If you want the update installed, set the status to "Install",
> othewise, leave it at "Needed". But the client will continue to report that
> the update is "Needed". (aka "Not Yet Installed").
>
> > An example is that we have approved .NEt 2 framework to go to desktop
> > machines but it is showing up as needed by every machine on the estate.
> > Is
> > there a way for WSUS 3 to show updates as not applicable on the groups
> > that
> > it is not approved on?
>
> Nope. For the aforementioned reason concerning the auto-detect design of
> WSUS 3, plus the fact that "Installed/Not Applicable" is the same status
> category in WSUS 3, and finally, because it's *not* a true statement that
> the update is "Not Applicable". The only true statement is that you, as a
> WSUS Administration, have determined for whatever reason (and WSUS cannot
> possibly anticipate what those might be), that you're not going to install
> that update.
>
> It does not, however, change the simple fact that it is an installable
> update, and it's not installed.
>
> And... to borrow from my other post a few minutes ago, because I think this
> point needs to be reinforced vis-a-vis this particular quirk of WSUS 3.0:
>
> ======================
> Also, consider the alternative scenario to how WSUS 3 currently works:
>
> Consider that the report really did only show the status of the updates
> you had APPROVED for Installation. Consider that... ooops... you forgot to
> approve a security update that should have been approved. Well, in the
> alternative, your computer would show 100% GREEN, because it's installed all
> of the =approved= updates, even though it has not installed all of the
> =needed= updates. Now, answer this question: The pie chart shows 100% GREEN.
> Is the computer compliant with your security update policy? Or, would you
> rather see that "Missing, but Not Approved" status reflected in the
> computer's report?
>
> Personally, I'd rather *know* that I have to discount those three
> updates that are making 2% of my pie chart yellow, and that I'm 98%
> compliant BY CHOICE with the =available= updates, than to be misled into
> believing I've installed 100% of the =needed= updates, only to find out
> after a security breach that I missed a critical security update that never
> got installed.
>
> ======================
>
>
>
> --
> Lawrence Garvin, M.S., MCTS, MCP
> Independent WSUS Evangelist
> MVP-Software Distribution (2005-2007)
> https://mvp.support.microsoft.com/profile=30E00990-8F1D-4774-BD62-D095EB07B36E
>
> Everything you need for WSUS is at
> http://technet2.microsoft.com/windowsserver/en/technologies/featured/wsus/default.mspx
>
> And, almost everything else is at
> http://wsusinfo.onsitechsolutions.com
> .....
>
>
>
Re: Updates showing as needed when not approved.
"Asher_N" <ashernat[ at ]gmail.com> 6/15/2007 6:41:33 PM
If you are not going to approve an update, you can always decline it.

One of the reporting items requested during the beta phase was a pie chart
of the status of approved updates. Unfortunately, it did not make it to the
release.

You can always make a new 'update' query showing the status of approved
updates. While it won't directly show you which computers are deficient, it
will give you a count of the number of updates.

=?Utf-8?B?S2l2?= <Kiv[ at ]discussions.microsoft.com> wrote in
news:07305A40-8225-48BD-BD00-A78AFE3E8951[ at ]microsoft.com:

[Quoted Text]
> I had a feeling this was the way it was designed to work but the
> management like to see a nice field of green when looking at the
> console.
>
> Thanks for the excellent explanation which I'm sure will help the
> people who raised the question realise that it's not necessarily a bad
> thing that we aren't 100% green.
>
> kiv
>
> "Lawrence Garvin (MVP)" wrote:
>
>>
>> "Kiv" <Kiv[ at ]discussions.microsoft.com> wrote in message
>> news:AD5F0BF2-5736-4B9F-BE68-482BF514B91B[ at ]microsoft.com...
>> > We have moved to WSUS 3 recently and I have noticed that when an
>> > update is approved on a single group it then shows as needed even
>> > on the groups it is
>> > not approved for.
>>
>> Actually, it does that for any group, regardless of approval. It's
>> the default configuration, by design, of WSUS 3. All updates are
>> immediately detectable, and any computer that does not have that
>> update installed (and the update would be installable, if attempted),
>> will be reported as "Needed". If you want the update installed, set
>> the status to "Install", othewise, leave it at "Needed". But the
>> client will continue to report that the update is "Needed". (aka "Not
>> Yet Installed").
>>
>> > An example is that we have approved .NEt 2 framework to go to
>> > desktop machines but it is showing up as needed by every machine on
>> > the estate. Is
>> > there a way for WSUS 3 to show updates as not applicable on the
>> > groups that
>> > it is not approved on?
>>
>> Nope. For the aforementioned reason concerning the auto-detect design
>> of WSUS 3, plus the fact that "Installed/Not Applicable" is the same
>> status category in WSUS 3, and finally, because it's *not* a true
>> statement that the update is "Not Applicable". The only true
>> statement is that you, as a WSUS Administration, have determined for
>> whatever reason (and WSUS cannot possibly anticipate what those might
>> be), that you're not going to install that update.
>>
>> It does not, however, change the simple fact that it is an
>> installable update, and it's not installed.
>>
>> And... to borrow from my other post a few minutes ago, because I
>> think this point needs to be reinforced vis-a-vis this particular
>> quirk of WSUS 3.0:
>>
>> ======================
>> Also, consider the alternative scenario to how WSUS 3 currently
>> works:
>>
>> Consider that the report really did only show the status of the
>> updates
>> you had APPROVED for Installation. Consider that... ooops... you
>> forgot to approve a security update that should have been approved.
>> Well, in the alternative, your computer would show 100% GREEN,
>> because it's installed all of the =approved= updates, even though it
>> has not installed all of the =needed= updates. Now, answer this
>> question: The pie chart shows 100% GREEN. Is the computer compliant
>> with your security update policy? Or, would you rather see that
>> "Missing, but Not Approved" status reflected in the computer's
>> report?
>>
>> Personally, I'd rather *know* that I have to discount those three
>> updates that are making 2% of my pie chart yellow, and that I'm 98%
>> compliant BY CHOICE with the =available= updates, than to be misled
>> into believing I've installed 100% of the =needed= updates, only to
>> find out after a security breach that I missed a critical security
>> update that never got installed.
>>
>> ======================
>>
>>
>>
>> --
>> Lawrence Garvin, M.S., MCTS, MCP
>> Independent WSUS Evangelist
>> MVP-Software Distribution (2005-2007)
>> https://mvp.support.microsoft.com/profile=30E00990-8F1D-4774-BD62-D095
>> EB07B36E
>>
>> Everything you need for WSUS is at
>> http://technet2.microsoft.com/windowsserver/en/technologies/featured/w
>> sus/default.mspx
>>
>> And, almost everything else is at
>> http://wsusinfo.onsitechsolutions.com
>> .....
>>
>>
>>
>

Home | Search | Terms | Imprint Contact
Newsgroups Reader - provided by WiredBox.Net
Suche nach Orten, Städten, Postleitzahlen, Vorwahlen, Kfz-Kennzeichen