scugbe_lowlands_unite_2017_servicing your new windows workplace like a boss

34
Servicing your modern Windows workplace like a boss.

Upload: kenny-buntinx

Post on 21-Jan-2018

140 views

Category:

Presentations & Public Speaking


0 download

TRANSCRIPT

Page 1: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

Servicing your modern Windows workplace like a boss.

Page 2: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

About Kenny

@KennyBuntinx

http://be.linkedin.com/in/kennybuntinx/

http://scug.be/sccm

Page 3: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

About Tim

@Tim_DK

http://be.linkedin.com/in/timdekeukelaere/

http://www.dekeukelaere.com

Page 4: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

Multiple ways of patching

Page 5: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

Infrastructure requirements

Page 6: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

Do you have the following symptoms ?

- High CPU on your WSUS server – 70-100% CPU in w3wp.exe hosting WsusPool

- High memory in the w3wp.exe process hosting the WsusPool – customers have reported memory usage approach 24GB

- Constant recycling of the W3wp.exe hosting the WsusPool (identifiable by the PID changing)

- Clients failing to scan with 8024401c (timeout) errors in the WindowsUpdate.log

- Mostly 500 errors for the /ClientWebService/Client.asmx requests in the IIS logs

Do you have the following symptoms ?

Page 7: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

Index and Clean

&

Page 8: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

Getting your WSUS infrastructure ready

The complete guide to Microsoft WSUS and Configuration Manager SUP maintenance :

- https://blogs.technet.microsoft.com/configurationmgr/2016/01/26/the-complete-guide-to-microsoft-wsus-and-configuration-manager-sup-maintenance/

Page 9: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

WSUS - Hotfixes Go for Windows Server 2012 R2 with following hotfixes

https://support.microsoft.com/en-us/kb/3095113

https://support.microsoft.com/en-us/kb/3159706

https://support.microsoft.com/en-us/kb/4039871/

Be aware to follow the guidelines of KB3159706

• Select HTTP Activation under .NET Framework 4.5 Features in the Server Manager Add Roles and Features wizard.

• "C:\Program Files\Update Services\Tools\wsusutil.exe" postinstall /servicing

Go for Windows Server 2016 with following hotfixes

https://support.microsoft.com/en-us/kb/4039396

Page 10: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

Getting your WSUS infrastructure ready Prepare the mime type .esd file on IIS

Error 0x8024200d ? – Check for duplicate .esd mime file extensions

Page 11: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

Getting your WSUS infrastructure ready Configure your IIS for WSUS correctly and modify the following settings:

a. Queue Length: 9000

b. Make sure that you do not have any CPU limit configurated. Should be 0 by default.

c. Under Rapid-Fail Protection. Set Failure Interval (Minutes): 30, and Maximum Failures: 60

d. Private Memory Limit should not be set to unlimited (e.g. 0).

e. Next modify the web.config file for the clientwebservice virtual application:

Changing webconfig for clientwebservice (located in prog files\update services\webservices\clientweb..)

<httpRuntime executionTimeout="500" maxRequestLength="4096" />

f. Next navigate to %Windir%\ and then run: IISReset.

Page 12: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

Getting your WSUS infrastructure ready - Want to include your Surface Drivers as pre-release feature ?

Page 13: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

Content Management

Page 14: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

Windows 10 Quality UpdatesExpress Updates require WSUS

Delta updates for non WSUS(1607 – 1703 - 1709)

Delta and Cumulative have the same KB number, with the same classification, and release at the same time. Updates can be distinguished by either the update title in the catalog, or by the name of the msu:

◦ 2017-02 \Delta Update** for Windows 10 Version 1607 for x64-based Systems (KB1234567)

◦ 2017-02 \Cumulative Update** for Windows 10 Version 1607 for x86-based Systems (KB1234567)

Page 15: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

Express UpdatesSupported in Configuration Manager as of version 1702

Requires Windows 10 1607 w April CU

As of 1706◦ Performance Improvements

◦ Client peer cache support for express installation files for Windows 10 and Office 365

Page 16: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

Express UpdatesEnabled in the SUP Component Properties

Page 17: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

Express UpdatesConfigured through client settings

Page 18: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

Peer CacheNative ConfigMgr solution for peer-to-peer content sharing

All content in the ConfigMgr client cache can be shared to peers

Currently in pre-release

Continuous investments - 1702:◦ Peer cache sources can reject clients when busy

◦ Low battery mode.

◦ CPU load exceeds 80% at the time the content is requested.

◦ Disk I/O has an AvgDiskQueueLength that exceeds 10.

◦ There are no more available connections to the computer.

◦ Additional out of the box reports

Future:

◦ Support for Windows express files

◦ Support for Office 365 delta files

Page 19: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

Peer Cache

Page 20: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

Cloud Management Gateway

AD CA

Windows Update

Page 21: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

Configuring Settings

Page 22: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

WSUS Group policyConfigure the GPO of Windows Components/Windows Update for Windows 10 :

• Configure Automatic Updates: Not Configured • Do not connect to any Windows Update

Internet locations: Enabled• Specify intranet Microsoft update service

location: Enabled• Allow updates from an intranet Microsoft

update service location: Enabled

Page 23: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

OSD WSUS Scan behaviorCreate a Group called ‘Configure Windows Update Settings’ just before the Windows Update Step and add a new ‘Run Command Line’ :

REG ADD HKLM\SOFTWARE\Policies\Microsoft\Windows\DeliveryOptimization /v DODownloadMode /t REG_DWORD /d 100

REG ADD HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate /v DoNotConnectToWindowsUpdateInternetLocations /t REG_DWORD /d 1

Add a ‘Restart Computer’ Step after the above Step.

Then create a second Group called ‘Remove Windows Update Settings’ just below the last Windows Update Step and add a new ‘Run Command Line’ :

REG DELETE HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate /v DoNotConnectToWindowsUpdateInternetLocations /f

REG DELETE HKLM\SOFTWARE\Policies\Microsoft\Windows\DeliveryOptimization /v DODownloadMode /f

Page 24: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

Client Settings for Peer Cache

Page 25: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

Different settings for SUP

Page 26: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

Servicing

Page 27: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

Servicing ChannelsFeature updates - Released twice per year (around March and September)

Servicing channels allow organizations to choose when to deploy new features

Do not say : ◦ CB, CBB and LTSB

Do say:◦ Semi-Annual Channel Targeted

◦ Semi-Annual Channel

◦ Long-Term Servicing Channel (LTSC)

Source : https://technet.microsoft.com/en-us/windows/release-info

Page 28: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

WAAS – Release Cadence

Page 29: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

WAAS – Release Support

Page 30: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

WAAS – What about Office?

Page 31: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

Approaches for servicing

Windows Update Windows Server Update Services

Windows Update for Business

System Center Configuration Manager

Page 32: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

ConfigMgr - In practice …

Policies / MSB

Pro--- Full Control--- Add / Preserve customizations--- Application lifecycle--- Tattooing--- Software Updates--- Control User Experience

Contra--- Operational Cost (recurring)

Pro--- ADR alike--- Set and forget

Contra--- Control level--- No customizations--- Limited scheduling--- User Experience like regular SU

Page 33: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

Phased Deployment - Process

Page 34: SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss

Thanks to our event sponsors

Silver

Gold