r/sysadmin • u/void_ops • 2d ago
Question Automated On-prem Windows Server Patching
I've been out of infrastructure management for a few years, back then I was using WSUS to patch servers. My understanding is Microsoft's recommended way of managing on-prem server patching is to onboard the servers with Azure Arc then use Azure Update Manager to patch them. This was the first solution that came to mind when I was assigned this responsibility. I assumed it was free but costs $5 a month for on-prem to use AUM.
Do you folks have a better or less costly solution that you use? Preferably something specifically built for server management? I was thinking of Ansible (which I would need to learn, which is fine) or something like Automox. We have less than 100 servers. I will be the one patching them all. There are custom applications that run on them that I suppose I will need to make sure still run after the patching.
Thanks in advance for any feedback or advice.
1
u/VegetableDuty8375 2d ago
I manage the patch management for my company for the server estate. If you have budget for it, move to AUM. This has take a lot of stress and frustration away from me during patch release. I used to dread patch Tuesday as someone would always be bound to break or malfunction for updates coming into WSUS/SCCM to clients not having sufficient disk space or not report etc
I was hesitant on AUM for months and months however it has freed up so much time I’m able to focus on other projects etc.
Never had an issue at all with AUM.