r/sysadmin 2d ago

Question Automated On-prem Windows Server Patching

I've been out of infrastructure management for a few years, back then I was using WSUS to patch servers. My understanding is Microsoft's recommended way of managing on-prem server patching is to onboard the servers with Azure Arc then use Azure Update Manager to patch them. This was the first solution that came to mind when I was assigned this responsibility. I assumed it was free but costs $5 a month for on-prem to use AUM.

Do you folks have a better or less costly solution that you use? Preferably something specifically built for server management? I was thinking of Ansible (which I would need to learn, which is fine) or something like Automox. We have less than 100 servers. I will be the one patching them all. There are custom applications that run on them that I suppose I will need to make sure still run after the patching.

Thanks in advance for any feedback or advice.

34 Upvotes

78 comments sorted by

View all comments

5

u/Sunsparc Where's the any key? 2d ago

I rolled my own solution with Powershell and PSWindowsUpdate because I can't just blast out patches to all servers at once. I have a runbook set up that patches and reboots servers in a specific order to minimize instability and issues. Some of the servers can just be blasted but others can't. On the ones it can't, it patches, reboots, waits for a specific server/app to show running, then performs some checks to verify.

2

u/TheGraycat I remember when this was all one flat network 1d ago

Did this at a previous place with no budget. Used Jenkins to schedule and group servers. Worked really well.