Quantcast
Channel: Symantec Connect - Endpoint Management - Discussions
Viewing all articles
Browse latest Browse all 6689

What are preferred patch management settings for Windows Servers?

$
0
0
I need a solution

Traditionally, we use WSUS to patch all of our Windows systems, including our servers.  For our client endpoints we have the systems configured to do the installs without prompting the users.  On the windows servers, we have it configured to automatically download the software updates but to not perform the installs.  This allows the server administrators to patch the systems on their schedule as long as it gets done by a certain time. 

 In the Symantec Management Console > Settings > All Settings > Agents/Plug-ins > Software > Patch Mgmt > Windows, I created two seperate policies, one for clients, and one for servers.  I am trying to configure our server policy to match our current group policy as close as possible.  Is there a way to configure the agents on our servers to download the update policies but to not install them until they are run by a server admin?  In our experience, if you let a server sit with an update installed but a reboot pending the CPU tends to run away and we dont want that to happen.  Thank you.

1412954718

Viewing all articles
Browse latest Browse all 6689

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>