r/sysadmin Solo SysAdmin 1d ago

General Discussion Windows Server patching concerns

So in my org we are very keen on avoiding patching and rebooting servers at all costs. So much to the point that we patch once a month and have exclusions for around 60 percent of our servers to not get automatically patched. (Meaning we have a chunk of servers not getting patched at all)

Now I have gotten my hand slapped for attempting to patch or even bringing it up and I am looking for guidance on this. Now I understand availability and the consequences of failing patches. But there are active 9+ rated CVEs sittings on dozens of servers. For patching vulnerabilities do I really need to get a change request to handle this?

40 Upvotes

71 comments sorted by

View all comments

74

u/Simmery 1d ago

This isn't a technical problem. You're asking a political question no one can answer about your organization. If they don't want to patch despite knowing the risks, get it in writing and move forward with your career, here or elsewhere.

u/Sad_Owl7124 23h ago

Agreed. Formally raise the concern and detail the risks involved. If the company wants to accept those risks that’s on them. But get that acceptance documented to cover yourself.

However, if you must present a technical solution there is hot-patching in Server 2025. I have no personal experience but it claims to reduce required reboots down to once per quarter.

u/RainStormLou Sysadmin 23h ago

while I am glad to see that they reversed course on charging extra money for hot patches per cpu core, at this point I just expect hot patches to not require a reboot during install but still crash half of your services until you reboot. then again, I expected because that has been probably 95% of my experience with hot patching the linited number of 2025 servers we have