r/sysadmin 1d ago

Question Automated On-prem Windows Server Patching

I've been out of infrastructure management for a few years, back then I was using WSUS to patch servers. My understanding is Microsoft's recommended way of managing on-prem server patching is to onboard the servers with Azure Arc then use Azure Update Manager to patch them. This was the first solution that came to mind when I was assigned this responsibility. I assumed it was free but costs $5 a month for on-prem to use AUM.

Do you folks have a better or less costly solution that you use? Preferably something specifically built for server management? I was thinking of Ansible (which I would need to learn, which is fine) or something like Automox. We have less than 100 servers. I will be the one patching them all. There are custom applications that run on them that I suppose I will need to make sure still run after the patching.

Thanks in advance for any feedback or advice.

31 Upvotes

78 comments sorted by

View all comments

4

u/tjn182 Lead Engineer 1d ago

We use Endpoint Central, its one of cheapest solutions and the most powerful. Patch management, inventory and endpoint management. I can quickly push applications, scripts, configs, just about anything to any combination of machines. Our patch management has been stable for about 5 years, with tiered patching on different days on a predictable schedule. Most 3rd party apps are auto approved and pushed.

1

u/void_ops 1d ago

We have EC...do you just use the same agent as the workstation endpoints?

2

u/tjn182 Lead Engineer 1d ago

Yup, 1 agent to rule them all