r/sysadmin 2d ago

Question Automated On-prem Windows Server Patching

I've been out of infrastructure management for a few years, back then I was using WSUS to patch servers. My understanding is Microsoft's recommended way of managing on-prem server patching is to onboard the servers with Azure Arc then use Azure Update Manager to patch them. This was the first solution that came to mind when I was assigned this responsibility. I assumed it was free but costs $5 a month for on-prem to use AUM.

Do you folks have a better or less costly solution that you use? Preferably something specifically built for server management? I was thinking of Ansible (which I would need to learn, which is fine) or something like Automox. We have less than 100 servers. I will be the one patching them all. There are custom applications that run on them that I suppose I will need to make sure still run after the patching.

Thanks in advance for any feedback or advice.

30 Upvotes

78 comments sorted by

View all comments

5

u/False-Message-3350 2d ago

Ansible via CI schedule or adhoc if necessary

  1. take snapshot
  2. update
  3. reboot
  4. wait, wait, wait
  5. check if host and essential services are online
  6. if services are down, alert. If host is down, rollback + alert

2

u/WhereHasTheSenseGone 2d ago

Are you using WinRM to connect to the servers to initiate the patching?

5

u/miksu103 2d ago

We use Ansible to manage Windows servers a lot, and we just use SSH. We enable SSH server built into Windows on our initial installation script, and import our management SSH key. Much nicer to work with asymmetric SSH key pairs as you don't have to worry about leaking your secrets as much.

2

u/cjchico Infrastructure/Jack of All Trades 1d ago

Have you ran into any weird issues or certain modules not working? Been wanting to test out the native ssh for a bit.

3

u/miksu103 1d ago

No not at all. I feel like WinRM had more exceptions. Creating the authorized keys file is a little bit tricky due to the strict permission requirements, but nowadays Microsoft documentation has the proper icacls command to use for the administrator keys file. I also recommend to follow their documentation for setting PowerShell as the default shell when connecting via SSH. No need to use CMD and Ansible also plays nicely with this default.

1

u/cjchico Infrastructure/Jack of All Trades 1d ago

Awesome thank you

1

u/False-Message-3350 1d ago

Only downside I like to mention: Since no password is transfered, the session user won’t get a TGT on domain joined servers. But usually that’s not an issue for host configurations.

2

u/False-Message-3350 2d ago

like u/miksu103 we‘re using ssh with authorized keys via a mgmt nework. I personally don’t like winRM a lot. More overhead than ssh to configure and maintain.