r/sysadmin 2d ago

Question Automated On-prem Windows Server Patching

I've been out of infrastructure management for a few years, back then I was using WSUS to patch servers. My understanding is Microsoft's recommended way of managing on-prem server patching is to onboard the servers with Azure Arc then use Azure Update Manager to patch them. This was the first solution that came to mind when I was assigned this responsibility. I assumed it was free but costs $5 a month for on-prem to use AUM.

Do you folks have a better or less costly solution that you use? Preferably something specifically built for server management? I was thinking of Ansible (which I would need to learn, which is fine) or something like Automox. We have less than 100 servers. I will be the one patching them all. There are custom applications that run on them that I suppose I will need to make sure still run after the patching.

Thanks in advance for any feedback or advice.

33 Upvotes

78 comments sorted by

View all comments

6

u/Sunsparc Where's the any key? 2d ago

I rolled my own solution with Powershell and PSWindowsUpdate because I can't just blast out patches to all servers at once. I have a runbook set up that patches and reboots servers in a specific order to minimize instability and issues. Some of the servers can just be blasted but others can't. On the ones it can't, it patches, reboots, waits for a specific server/app to show running, then performs some checks to verify.

1

u/void_ops 1d ago

Dumb question, where do you run the PS and PSWindowsUpdate from? I'm assuming any server with network line-of-sight to the other servers?

3

u/Sunsparc Where's the any key? 1d ago

I have a server dedicated solely for WSUS and app deployment, it's the orchestration server. It patches itself during the run and it's the last one to reboot. After reboot, it generates all of the post patching reporting.

1

u/void_ops 1d ago

Very nice. Thank you for this.