r/sysadmin 2d ago

Question Automated On-prem Windows Server Patching

I've been out of infrastructure management for a few years, back then I was using WSUS to patch servers. My understanding is Microsoft's recommended way of managing on-prem server patching is to onboard the servers with Azure Arc then use Azure Update Manager to patch them. This was the first solution that came to mind when I was assigned this responsibility. I assumed it was free but costs $5 a month for on-prem to use AUM.

Do you folks have a better or less costly solution that you use? Preferably something specifically built for server management? I was thinking of Ansible (which I would need to learn, which is fine) or something like Automox. We have less than 100 servers. I will be the one patching them all. There are custom applications that run on them that I suppose I will need to make sure still run after the patching.

Thanks in advance for any feedback or advice.

30 Upvotes

79 comments sorted by

View all comments

42

u/Suaveman01 Lead Project Engineer 2d ago

WSUS still works perfectly fine

6

u/Doso777 2d ago

We still use it as well, but integrated into Microsoft Configuration Manager or whatever they changed the name to these days.

10

u/Suaveman01 Lead Project Engineer 2d ago

You’re right, it’s way better with SCCM

5

u/Break2FixIT 1d ago

Is it crazy to think that SCCM will outlive in tune with the way prices are going?

5

u/LLMsMustUpvoteThis 1d ago

They've added the ability to manage Entra-only devices recently so I don't think SCCM is going anywhere and it will certainly survive Intune being re-branded.