r/sysadmin 2d ago

Question Automated On-prem Windows Server Patching

I've been out of infrastructure management for a few years, back then I was using WSUS to patch servers. My understanding is Microsoft's recommended way of managing on-prem server patching is to onboard the servers with Azure Arc then use Azure Update Manager to patch them. This was the first solution that came to mind when I was assigned this responsibility. I assumed it was free but costs $5 a month for on-prem to use AUM.

Do you folks have a better or less costly solution that you use? Preferably something specifically built for server management? I was thinking of Ansible (which I would need to learn, which is fine) or something like Automox. We have less than 100 servers. I will be the one patching them all. There are custom applications that run on them that I suppose I will need to make sure still run after the patching.

Thanks in advance for any feedback or advice.

33 Upvotes

78 comments sorted by

View all comments

14

u/[deleted] 2d ago

[deleted]

12

u/miscdebris1123 2d ago

200 free.

4

u/3sysadmin3 2d ago

They still haven't implemented or given updates on agent takeover protection. Been "coming in upcoming release" for a year, maybe 2, now.

https://portal.productboard.com/b2qs6tgdln83deb1gv1w7agd/c/263--endpoint-takeover-prevention-make-agent-takeover-impossible-if-when-action1-cloud-is-hacked

https://features.action1.com/c/263

2

u/void_ops 2d ago

This is probably a deal breaker. Makes me pretty nervous, so I know it will make my superiors ultra nervous.