congratulations – you survived the keynote with stan & ollie

24
Congratulations – you survived the keynote with Stan & Ollie

Upload: len

Post on 26-Feb-2016

51 views

Category:

Documents


4 download

DESCRIPTION

Congratulations – you survived the keynote with Stan & Ollie. 10 min is all it takes - Managing Microsoft & 3rd party updates with SC 2012 Configuration Manager. Kent Agerlund. Who am I. Kent Agerlund Chief System Management Architect Coretech A/S, Denmark - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Congratulations – you survived the keynote  with  Stan  &  Ollie

Congratulations – you survived the keynote with Stan & Ollie

Page 2: Congratulations – you survived the keynote  with  Stan  &  Ollie

10 min is all it takes - Managing Microsoft & 3rd party updates with SC 2012 Configuration Manager

Kent Agerlund

Page 3: Congratulations – you survived the keynote  with  Stan  &  Ollie

Who am I Kent Agerlund

Chief System Management Architect Coretech A/S, Denmark Microsoft MVP: Enterprise Client Management Microsoft Certified Trainer, MCITP Enterprise Admin

I love questions – but DON’T ask me about hockey and the world cup

Page 4: Congratulations – you survived the keynote  with  Stan  &  Ollie

Agenda Patch Tuesday

Let’s spend 5 min together Why worry about 3rd party updates What are your options

SCUP 2011 (System Center Updates Publisher) Solarwinds Secunia

Page 5: Congratulations – you survived the keynote  with  Stan  &  Ollie

So….What is patch management?

PDPatch Deployment

PCPatch Creation

+

Vulnerability Scanning

VS +VIVulnerability Intelligence

+ PM=

Page 6: Congratulations – you survived the keynote  with  Stan  &  Ollie

Plan for Software Updates Define you Update process

Pilot environments Servers with automatic restart Servers with manual requirements Logically grouped servers Workstations in production Excluded devices

Define you SLA’s When is your Boss a “Happy Camper” Can you track compliance

Collection design Maintenance Windows

CD+IT+RT=MW

Page 7: Congratulations – you survived the keynote  with  Stan  &  Ollie

Workstation restarts Automatic restart? No restart = No compliance = No Make sure you have a restart plan Create custom report

Last Computer Restart

Page 8: Congratulations – you survived the keynote  with  Stan  &  Ollie

Give me 5 minutesDEMO Wake up it’s, Patch Tuesday or early Wednesday

Page 9: Congratulations – you survived the keynote  with  Stan  &  Ollie

Microsoft Programs

14%Third Party Programs

86%

Why worry about 3rd party Business

View

Criminals

ViewWhat criminals

attack

Business criticalprograms

Programs you know about

Programs you don’t know about

What do you patch today

Vendors

Page 10: Congratulations – you survived the keynote  with  Stan  &  Ollie

The numbers speaks for themselves – TOP 50 apps

Cybercriminals know:patch available

patch installed

Vulnerabilitiesin 2012 TOP 50 Apps

1137

421 in 2009229 in 2007

Page 11: Congratulations – you survived the keynote  with  Stan  &  Ollie

0 10 20 30 40 50 600%

20%

40%

60%

80%

100%

Percentage of risk remediated by patching N programs

Number of programs patched

Perc

enta

ge o

f risk

rem

edia

ted

Patching N of 200 programs

80% risk reduction achieved by either patching the 12 most critical programs, or by patching the 37 most prevalent programs

12 37

Strategy 2: By CriticalityRisk remediated by patching the N most critical programs

Strategy 1: StaticRisk remediated by patching the N most prevalent programs

Where to begin

Page 12: Congratulations – you survived the keynote  with  Stan  &  Ollie

Are we doomed?

Page 13: Congratulations – you survived the keynote  with  Stan  &  Ollie

SCUP 2011

Page 14: Congratulations – you survived the keynote  with  Stan  &  Ollie

SCUP 2011 What is SCUP

Authoring tool Publishing tool

3rd Party Updates with SCUP Same experience for all updates in ConfigMgr Supports EXE, MSI and MSP based updates MSU workaround :

http://blogs.technet.com/b/dominikheinz/archive/2011/10/17/deploying-custom-msu-updates-with-sccm-and-scup.aspx

Page 15: Congratulations – you survived the keynote  with  Stan  &  Ollie

SCUP Process Flow

Author customSCUP catalog WSUS Server

Catalogs downloaded from web

ConfigMgr ServerSCUP Console

Publish Updates Sync Updates

ConfigMgr Clients

Scan Updates Deploy Updates

Author Updates

Import Updates

Page 16: Congratulations – you survived the keynote  with  Stan  &  Ollie

The signing certificate Used by SCUP to sign updates

Trusted Publishers Trusted Root

Configure WSUS GPO Allow self signed certificates

Create the self-signed certificate with SCUP External certificate - http://

blogs.msdn.com/b/steverac/archive/2011/09/18/using-system-center-update-publisher-2007-with-verisign-certificates.aspx

KB2720211 & KB2661254

Page 17: Congratulations – you survived the keynote  with  Stan  &  Ollie

Available Catalogs Free catalogs

Adobe Reader and Flash

Dell Client and Server updates

Hewlett-Packard Client and Server updates

Fujitsu ConfigMgr Cumulative updates

$$ catalogs SCUPdates from Shavlik, VMWARE

no wait today it’s LANDESK PatchMyPC

Page 18: Congratulations – you survived the keynote  with  Stan  &  Ollie

SCUPDEMOPatch ConfigMgr clients…..the easy way

Page 19: Congratulations – you survived the keynote  with  Stan  &  Ollie

Secunia

Page 20: Congratulations – you survived the keynote  with  Stan  &  Ollie

Secunia Products

CSI – Corporate edition SSB – Small Business edition PSI – Consumer and free

Cloud Based solution Database contains vulnerabilities in

software products since 2003 40k+ programs, applications and

plug-ins from thousands of software vendors

Automated patch repackaging Fully integrated with 2012

Page 21: Congratulations – you survived the keynote  with  Stan  &  Ollie

Reporting Integrated with Configuration Manager Custom Dashboard Custom reports E-Mail subscriptions

Page 22: Congratulations – you survived the keynote  with  Stan  &  Ollie

Deploying patches Custom created Secunia packages

Silent installations Can detect running applications like JAVA

Script support PowerShell VB Java

Updates are injected into WSUS

Page 23: Congratulations – you survived the keynote  with  Stan  &  Ollie

SecuniaDEMO3rd party patching

Page 24: Congratulations – you survived the keynote  with  Stan  &  Ollie

UTVÄRDERING Fyll i utvärderingen så att vi kan bli

ännu bättre till nästa gång! Antigen via länken du fick med

din biljett eller vid någon av datorerna i TrueSec:s monter

Tävla samtidigt om en HP Elitepad 900 (Vinnaren presenteras i Utställarfoajén direkt efter sista sessionen).

KVÄLLSMINGEL Best of MMS avslutas med ett

gigantiskt mingel på närliggande Dubliner direkt efter dagens sista session!

Microsoft och LabCenter bjuder på god öl och ett unikt tillfälle för experter, branschkollegor och eventdeltagare att mingla tillsammans.

Vi ses väl där?