The way I deal with this is: Each month I create a new deployment for that month's security updates. I have this deployment set to only install and reboot during the maintenance window. I deploy with a set deadline (usually the next day). I tell the deployment that it can only install and reboot during the maintenance window.
When I get a new deployment (usually for the next month) I go back to the previous month and tell the deployment that it can install outside the maintenance window, but leave the reboot only in the MW checked. Then I go back two months and uncheck the reboot outside MW check box. This way I figure the updates get installed at least one month behind schedule, and rebooted at least two months back. Not the fastest, but it covers the folks that don't want to install any other way. I also figure if they haven't installed the updates in two months they deserve to have their systems rebooted as needed. So far this seems to be working good for us. Thanks, Ken ... From: [email protected] [mailto:[email protected]] On Behalf Of Orlebeck, Geoffrey Sent: Wednesday, December 10, 2014 9:09 AM To: '[email protected]' Subject: [mssms] RE: Software Updates & Maintenance Windows: This is where the issue lies, users never want to be interrupted, so they will delay indefinitely (had this issue with WSUS where users would delay for weeks before we forced reboots). Now with SCCM it will be much cleaner overall, but I was just hoping the behavior would be a bit different-if I'm deploying something and am making it available immediately, but the deadline is 7 days out, still try to install it as soon as possible but force it if cannot be accomplished within 7 days. I get it now, and I understand the process, I just think their logic is different than mine. Thank you for the insight and discussion points, I've enjoyed the dialogue. Thanks, Geoff From: [email protected]<mailto:[email protected]> [mailto:[email protected]] On Behalf Of Miller, Todd Sent: Wednesday, December 10, 2014 7:46 AM To: [email protected]<mailto:[email protected]> Subject: [mssms] RE: Software Updates & Maintenance Windows: 'It requires a small amount of user participation" - Ah, there's the rub. From: [email protected]<mailto:[email protected]> [mailto:[email protected]] On Behalf Of Jason Sandys Sent: Wednesday, December 10, 2014 8:22 AM To: [email protected]<mailto:[email protected]> Subject: [mssms] RE: Software Updates & Maintenance Windows: What you've described below is the intent of business hours. It requires a small amount of user participation; however, as long as they have checked the box in software center to perform required updates outside of their business hours, it will in fact work that way since user initiated deployment - which is what this would be - don't consider maintenance windows. J From: [email protected]<mailto:[email protected]> [mailto:[email protected]] On Behalf Of Miller, Todd Sent: Tuesday, December 9, 2014 5:18 PM To: [email protected]<mailto:[email protected]> Subject: [mssms] RE: Software Updates & Maintenance Windows: Maintenance windows are a little tricky with software updates. You have to choose among two options that both have pitfalls. Either you set a deadline and ignore maintenance windows, in which case the update installs at the deadline or the next time the computer is on after the deadline. So basically maintenance windows are useless/ignored. Or you set the deployment to respect maintenance windows, in which case any computer that is not on during its maintenance window - think laptops - never ever patches Unless the user chooses to (ha ha ha! ). In this case maintenance windows help you avoid patching during business hours, but you could end up with lots of unpatched systems to remediate. It is difficult to choose among these two options. It would work much better if it worked how you initially thought it worked ---- If there is a pending software update, install it at the next maintenance window. If the deadline is past, install regardless of maintenance window. This way you could have machines try to install during a maintenance window for a week (or a few days), and if it still didn't find time to install during the preferred maintenance window, it would just install at the deadline (which is the only time WOL packets are sent too, btw) From: [email protected]<mailto:[email protected]> [mailto:[email protected]] On Behalf Of Jason Sandys Sent: Tuesday, December 09, 2014 4:03 PM To: [email protected]<mailto:[email protected]> Subject: [mssms] RE: Software Updates & Maintenance Windows: As an additional note here, deadlines are not "lines in the sand", they are absolute lines in concrete. A ConfigMgr client agent will not enforce a deployment until that deployment has reached its deadline (or the user initiates the deployment). J From: [email protected]<mailto:[email protected]> [mailto:[email protected]] On Behalf Of Orlebeck, Geoffrey Sent: Tuesday, December 9, 2014 11:39 AM To: '[email protected]' Subject: [mssms] RE: Software Updates & Maintenance Windows: Great, thank you for getting back to me! -Geoff From: [email protected]<mailto:[email protected]> [mailto:[email protected]] On Behalf Of Gerry Hampson Sent: Tuesday, December 09, 2014 9:33 AM To: [email protected]<mailto:[email protected]> Subject: [mssms] RE: Software Updates & Maintenance Windows: Geoff, the updates will install during the first maintenance windows AFTER the deadline is reached. Regards, Gerry From: [email protected]<mailto:[email protected]> [mailto:[email protected]] On Behalf Of Orlebeck, Geoffrey Sent: 09 December 2014 17:24 To: '[email protected]' Subject: [mssms] Software Updates & Maintenance Windows: Hello group. I've been working a bit more with SCCM (2012 R2, single primary site) and I have a question surrounding how maintenance windows and deadlines work. I just want to confirmation as I haven't seen this addressed specifically anywhere that I've looked, including TechNet. If I create a Software Update Group today (12/9) and deploy it with a deadline for 12/13 @ 2AM to a collection with a Software Updates maintenance window daily from 11PM-5AM, the updates still won't actually install until the deadline is hit, correct? That is the behavior I am currently seeing in my environment. Even though the devices may download the updates today, and there are maintenance windows that occur nightly from now until 12/13, the updates don't actually install until the deadline is reached. Is that correct? My assumption (I know...assumptions) was the deadline was a line in the sand, but if a maintenance window passes before the deadline and there are pending deployments, those would process. Since this is my first go with ConfigMgr, I just want to confirm the above behavior is by design and that I haven't misconfigured something. Happy to provide any additional details if needed. Thanks! -Geoff Confidentiality Notice: This is a transmission from Community Hospital of the Monterey Peninsula. This message and any attached documents may be confidential and contain information protected by state and federal medical privacy statutes. They are intended only for the use of the addressee. If you are not the intended recipient, any disclosure, copying, or distribution of this information is strictly prohibited. If you received this transmission in error, please accept our apologies and notify the sender. Thank you. Confidentiality Notice: This is a transmission from Community Hospital of the Monterey Peninsula. This message and any attached documents may be confidential and contain information protected by state and federal medical privacy statutes. They are intended only for the use of the addressee. If you are not the intended recipient, any disclosure, copying, or distribution of this information is strictly prohibited. If you received this transmission in error, please accept our apologies and notify the sender. Thank you. ________________________________ Notice: This UI Health Care e-mail (including attachments) is covered by the Electronic Communications Privacy Act, 18 U.S.C. 2510-2521, is confidential and may be legally privileged. If you are not the intended recipient, you are hereby notified that any retention, dissemination, distribution, or copying of this communication is strictly prohibited. Please reply to the sender that you have received the message in error, then delete it. Thank you. ________________________________ ________________________________ Notice: This UI Health Care e-mail (including attachments) is covered by the Electronic Communications Privacy Act, 18 U.S.C. 2510-2521, is confidential and may be legally privileged. If you are not the intended recipient, you are hereby notified that any retention, dissemination, distribution, or copying of this communication is strictly prohibited. Please reply to the sender that you have received the message in error, then delete it. Thank you. ________________________________ Confidentiality Notice: This is a transmission from Community Hospital of the Monterey Peninsula. This message and any attached documents may be confidential and contain information protected by state and federal medical privacy statutes. They are intended only for the use of the addressee. If you are not the intended recipient, any disclosure, copying, or distribution of this information is strictly prohibited. If you received this transmission in error, please accept our apologies and notify the sender. Thank you.

