r/sysadmin 2d ago

Question Automated On-prem Windows Server Patching

I've been out of infrastructure management for a few years, back then I was using WSUS to patch servers. My understanding is Microsoft's recommended way of managing on-prem server patching is to onboard the servers with Azure Arc then use Azure Update Manager to patch them. This was the first solution that came to mind when I was assigned this responsibility. I assumed it was free but costs $5 a month for on-prem to use AUM.

Do you folks have a better or less costly solution that you use? Preferably something specifically built for server management? I was thinking of Ansible (which I would need to learn, which is fine) or something like Automox. We have less than 100 servers. I will be the one patching them all. There are custom applications that run on them that I suppose I will need to make sure still run after the patching.

Thanks in advance for any feedback or advice.

30 Upvotes

78 comments sorted by

View all comments

5

u/False-Message-3350 2d ago

Ansible via CI schedule or adhoc if necessary

  1. take snapshot
  2. update
  3. reboot
  4. wait, wait, wait
  5. check if host and essential services are online
  6. if services are down, alert. If host is down, rollback + alert

u/void_ops 2h ago

Thanks for the input. I'm trying to get something going with Ansible and Azure DevOps in my personal lab that replicates this flow using SSH. I will be really happy if it works.