Implement clients update strategy on SCCM

Roberto 646 Reputation points
2021-03-22T15:00:48.81+00:00

Hello.

I need to say that I'm still new to SCCM delivering updates to clients.

I'd like to implement the following updating strategy:

1) WSUS synchronization from Microsoft, once per month, after Patch Tuesday
2) SCCM Deployment packages: Windows 10, Office, Windows Defender, Windows Defender definitions
3) automatic deployment to PCs scheduled in three fases:
3a) a few Test PCs, once per month, right after Patch Tuesday
3b) larger pool of test PCs, one week after 2a
3c) All PCs, three weeks after 2a
4) WSUS should deny direct access from clients. Only source of updates has to be SCCM

Could anybody guide me through the steps to achiving the above?

Thank you and best regards.
Roberto

Microsoft Configuration Manager
0 comments No comments
{count} votes

Accepted answer
  1. Amandayou-MSFT 11,046 Reputation points
    2021-03-23T03:12:43.147+00:00

    Hi @Roberto

    1) WSUS synchronization from Microsoft, once per month, after Patch Tuesday
    2) SCCM Deployment packages: Windows 10, Office, Windows Defender, Windows Defender definitions

    We could use automatic deployment rule to deploy update, the relevant settings are below:

    About product: Please navigate to the tab of software updates, select the product, and select Windows 10, Office, Windows Defender, kindly refer to the picture:

    80426-3231.png

    About once per month, after Patch Tuesday: Please navigate to the tab of Evaluation schedule, select the tab of run the rule on a schedule, related setting coule be referred to this picture:
    80473-323.png

    3) automatic deployment to PCs scheduled in three fases:
    We could create a collection which includes a few Test PCs, and then add larger pool of test PCs in the collection, finally deploy to all pcs.

    4) WSUS should deny direct access from clients. Only source of updates has to be SCCM
    Please check if the device was previously managed by WSUS. If yes, delete the record of the tab of set the intranet update service for detecting and set the intranet statistics server. Related setting coule be referred to this picture:
    80463-3232.png

    About creating an automatic deployment rule (ADR), please refer to this article:
    https://learn.microsoft.com/en-us/mem/configmgr/sum/deploy-use/automatically-deploy-software-updates


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


0 additional answers

Sort by: Most helpful