question

Roberto-9646 avatar image
0 Votes"
Roberto-9646 asked Amandayou-MSFT commented

Implement clients update strategy on SCCM

Hello.

I need to say that I'm still new to SCCM delivering updates to clients.

I'd like to implement the following updating strategy:

1) WSUS synchronization from Microsoft, once per month, after Patch Tuesday
2) SCCM Deployment packages: Windows 10, Office, Windows Defender, Windows Defender definitions
3) automatic deployment to PCs scheduled in three fases:
3a) a few Test PCs, once per month, right after Patch Tuesday
3b) larger pool of test PCs, one week after 2a
3c) All PCs, three weeks after 2a
4) WSUS should deny direct access from clients. Only source of updates has to be SCCM

Could anybody guide me through the steps to achiving the above?

Thank you and best regards.
Roberto

mem-cm-general
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

Amandayou-MSFT avatar image
0 Votes"
Amandayou-MSFT answered Amandayou-MSFT commented

Hi @Roberto-9646

1) WSUS synchronization from Microsoft, once per month, after Patch Tuesday
2) SCCM Deployment packages: Windows 10, Office, Windows Defender, Windows Defender definitions

We could use automatic deployment rule to deploy update, the relevant settings are below:

About product: Please navigate to the tab of software updates, select the product, and select Windows 10, Office, Windows Defender, kindly refer to the picture:

80426-3231.png

About once per month, after Patch Tuesday: Please navigate to the tab of Evaluation schedule, select the tab of run the rule on a schedule, related setting coule be referred to this picture:
80473-323.png

3) automatic deployment to PCs scheduled in three fases:
We could create a collection which includes a few Test PCs, and then add larger pool of test PCs in the collection, finally deploy to all pcs.

4) WSUS should deny direct access from clients. Only source of updates has to be SCCM
Please check if the device was previously managed by WSUS. If yes, delete the record of the tab of set the intranet update service for detecting and set the intranet statistics server. Related setting coule be referred to this picture:
80463-3232.png

About creating an automatic deployment rule (ADR), please refer to this article:
https://docs.microsoft.com/en-us/mem/configmgr/sum/deploy-use/automatically-deploy-software-updates



If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.



3231.png (38.0 KiB)
323.png (33.0 KiB)
3232.png (37.4 KiB)
· 2
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hello @Amandayou-MSFT.

Thank you for your detailed explanation. :-)

I still have a few questions on this, but I'll post more question on this forum.

Best regards.
Roberto

0 Votes 0 ·

Hi,

Thank you very much for the update and we're glad the part of problem is solved now. If you have any questions, we warmly welcome you to post other question on this forum.

Have a nice day!

Regards,
Amanda

0 Votes 0 ·