I have one goal. I want to detect and deploy any patches that are considered "Important" Windows patches that are the "Important" patches when you manually run Windows Update. I just ran a "Detect All" patch schedule on my laptop and ran the Windows Update check and the numbers are off. Windows detected 45 "Important" Updates whereas KACE only detected 38! Maybe windows is not discounting the "Superseeded" patches, but I want to be certain. Anyone have a patching smart label that you use to get these patches specifically?

0 Comments   [ + ] Show Comments

Comments

Please log in to comment

Answers

1

easterdaymatt,

First, if you are using the Severity field to identify "important" patches, you should know that Severity is assigned by Lumension (KACE's patching partner), NOT by Microsoft.  Second, why are you so concerned with only "important" patches.  What is the definition of "important" to you?

One of the "important" points I always discuss with customers, when I train them on K1000 patching, is how nonsensical terms like Security, Non-Security, Critical, Recommended, OS-patch, App-patch, are.  There are no industry-standard definitions for these, which means that even if the vendors (MS, Adobe, Oracle, Apple, etc.) provided definitions of these terms, they wouldn't agree with one another.

Also, even if they did agree, they aren't always going to get it right for YOUR environment.  For instance, there are countless "security-related" patches that aren't marked as "security" type patches.

Just some food for thought.  I certainly can help you create any kind of patch label you might want, though.  Lemme know what you need.

Ron Colson

KACE Koach

Answered 01/22/2014 by: ronco
Second Degree Brown Belt

  • What I am looking for is the best way to patch servers and workstations. We never have any problems using the Windows Update tool that comes with Windows to run "Important" updates according to Microsoft. I suppose if I can get a match between that and a Smart Label in KACE then I will be happy. I'm open to hear any kind of options, this is just my thoughts thus far.
    • We're you ever able to get this working?
  • "One of the 'important' points I always discuss with customers, when I train them on K1000 patching, is how nonsensical terms like Security, Non-Security, Critical, Recommended, OS-patch, App-patch, are."

    Of course, my manager didn't get your training, so he just wants his Windows Update to have 0 updates in the "Important" section. You're right, it's nonsensical, but I can't do anything about it! :)
    • That's our goal as well to get to 0 updates. How close have you gotten?
Please log in to comment
1

Matt,

First, can you identify a single specific patch, that I can research, that is marked as "important" in WindowsUpdate, but NOT in KACE?  Or vice versa?

Second, have you watched our Patching Week KKE videos? (http://www.kace.com/support/training/kke/archive?tag=patching&language=en)  They'll provide a good basic primer on "KACE" patching.

Ron Colson

KACE Koach

Answered 01/22/2014 by: ronco
Second Degree Brown Belt

Please log in to comment
Answer this question or Comment on this question for clarity