Jump to content
OBK

Strange behaviour installing WSUS-Patche

Recommended Posts

Hi,

I disabled Windows Update search mode in a Agent-Policy (see 01 policy network Agent.png). The policy is applied to all devices (02 policy network agent applied.png). In Group "Application Management/Software updates" are listed many windows-patche (see 03 list of patches.png). Until this moment, everything is okay.

When i choose one software (see 04 screenshot1.png), "to be installed" shows counts 1 (Update approval is Undefined) (see 05 screenshot2.png and 05a overview.png).

As you can see on "07 not assigned but installing.png", there are several software products, which are not assigned for Installation, but they will be installed.

I have these problem with all Application of Office 10, but not with Windows 7 and Windows 10.

Kind regards,

OBK

01 policy network agent.JPG

02 policy network agent applied.JPG

03 list of patches.JPG

04 screenshot1.JPG

04 screenshot1.JPG

05 screenshot2.JPG

05a overview.JPG

07 not assigned but installing.JPG

Share this post


Link to post

Hello!

Please kindly provide us with administration server traces, console traces and problem nagent traces, simultaneously  collected during the issue reproducing.

Thank you!

Share this post


Link to post
vor 1 Stunde schrieb Vitaly Kravtsov:

Please kindly provide us with administration server traces, console traces and problem nagent traces, simultaneously  collected during the issue reproducing.

see attaced file

I just remember, that I have choose the Action "Approved". Shall I redo it with Action "Undefined"?

traces.zip

Edited by OBK

Share this post


Link to post
On 19.12.2017 at 12:19 PM, OBK said:

see attaced file

I just remember, that I have choose the Action "Approved". Shall I redo it with Action "Undefined"?

traces.zip

Hello.

Please note that the WSUS setting in the Network Agent policy does not affect the list of MS updates in KSC, or the "Install updates" task settings. If the task is configured to install already known available MS updates that meet certain criteria, it will. Change the task settings of disapprove the updates to avoid this.

Thank you.

Share this post


Link to post
vor 6 Minuten schrieb Kirill Tsapovsky:

Please note that the WSUS setting in the Network Agent policy does not affect the list of MS updates in KSC, or the "Install updates" task settings. If the task is configured to install already known available MS updates that meet certain criteria, it will. Change the task settings of disapprove the updates to avoid this.

All my update task are configured for special software. I only have update tasks for third party software and not for microsoft patche.

Share this post


Link to post
20 hours ago, OBK said:

All my update task are configured for special software. I only have update tasks for third party software and not for microsoft patche.

Settings specified in the opening post only affect Windows updates. MS Office vulnerabilities can be found by Network Agent even if KSC is not used as WSUS and interaction with WUA is disabled.

Thank you.

Share this post


Link to post
vor 4 Stunden schrieb Kirill Tsapovsky:

Settings specified in the opening post only affect Windows updates. MS Office vulnerabilities can be found by Network Agent even if KSC is not used as WSUS and interaction with WUA is disabled.

Please compare the screenshot of kes 11 beta with the video of kes 10 sp2. https://www.magentacloud.de/share/hgh6itcltq

I am not surprised, that the Network Agent find Micrsoft-Patche. I am surprised, that KSC install Microsoft-Patche without a configured task!

Share this post


Link to post

I am really irritated. :unsure: Or am I wacko :wacko:?

Is it possible, that with a new Installation of KSC 10 SP3, a default task "Install required updates and fix vulnerabilities" will be created, wich runs every day at 1 AM and install "Aproved updates", "Fixes for critical vulnerabilites" and "Windows Update: critical updates, security updates, and Definition updates" with setting "Allow Installation of new application versions during updates". Perhaps I forget it, but I really can't remember, that I created the task myself.

But now is clear, why Office Pathes are installed automatically.

If you want, you can close the topic now. But I think, it's a better desire, to create the task in further versions of KSC with Schedule Manually!!!

Kind regards,

OBK

Edited by OBK

Share this post


Link to post

Hello.


Task is created automatically to ensure protection for a least experienced administrators.

Those who have some background can alter tasks settings to suit their needs after installation.

 

Share this post


Link to post
vor 17 Minuten schrieb Evgeny_E:

Task is created automatically to ensure protection for a least experienced administrators.

Those who have some background can alter tasks settings to suit their needs after Installation.

Thank you. You can close the topic.

One question for you to think about: Why nobody think about this task and figured out why my KSC automatically installed WSUS-Patches?

My answer: Because it's a strange behaviour of the task.

Edited by OBK

Share this post


Link to post

×
×
  • Create New...

Important Information

We use cookies to make your experience of our websites better. By using and further navigating this website you accept this. Detailed information about the use of cookies on this website is available by clicking on more information.