<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://192.168.2.20/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>SBS 2003</title><link>http://192.168.2.20/forums/7.aspx</link><description /><dc:language /><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Re: SBS 2003 Patching Guidelines</title><link>http://192.168.2.20/forums/thread/428.aspx</link><pubDate>Sat, 13 May 2006 06:07:30 GMT</pubDate><guid isPermaLink="false">72050d9c-4f41-4a16-9f70-ebbf2c98a2c7:428</guid><dc:creator>David Overton</dc:creator><slash:comments>0</slash:comments><comments>http://192.168.2.20/forums/thread/428.aspx</comments><wfw:commentRss>http://192.168.2.20/forums/commentrss.aspx?SectionID=7&amp;PostID=428</wfw:commentRss><description>&lt;P&gt;Andrew,&lt;/P&gt;
&lt;P&gt;Sorry this has taklen so long to reply to, I naturally assumed someone else might answer this, but ho hum.&lt;/P&gt;
&lt;P&gt;The best person to talk about patching is the infamous Susan Bradly, who is a SBS MVP and known as a Diva. Before I point you off to some of her blogs on it, I thought I would answer some of your other questions about the area:&lt;/P&gt;
&lt;P&gt;You always have to make a decision regarding patching vs risk.&amp;nbsp; How much time would you spend testing the fix for blaster vs deploying it asap. Likewise, how many times do patches break machines - if they do, find out why that system needs extra care and only evaluate vs that piece of software / hardware, but deploy to the rest.&lt;/P&gt;
&lt;P&gt;Also remember, support to fix problems as a result of a patch (or service pack)&amp;nbsp;is free from Microsoft, so you can always pickup the bat phone.&lt;/P&gt;
&lt;P&gt;Personally, I deploy all application patches from microsoft to desktops immediately via WSUS.&amp;nbsp; I evaluate drivers, but rarely deploy them 'cos if they ain't broke, don't fix and I would normally be looking for drivers only when I am setting up a system or if it is causing problems.&lt;/P&gt;
&lt;P&gt;On my server, I auto deplpy critical patches and then hand manage the rest.&amp;nbsp; However I also read the security bulletins to see if there is something coming I need to worry about.&lt;/P&gt;
&lt;P&gt;For places of info, there is no better than Susan Bradley's blog - &lt;A href="http://msmvps.com/blogs/bradley"&gt;http://msmvps.com/blogs/bradley&lt;/A&gt;&amp;nbsp;- and you can always ask her a question.&amp;nbsp; She also covered this is a webcast on the SBSShow - &lt;A href="http://www.vladville.com/sbsshow/2005/12/sbs-show-8-patch-management-with-susan.html"&gt;http://www.vladville.com/sbsshow/2005/12/sbs-show-8-patch-management-with-susan.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;ttfn&lt;/P&gt;
&lt;P&gt;David&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>SBS 2003 Patching Guidelines</title><link>http://192.168.2.20/forums/thread/199.aspx</link><pubDate>Tue, 28 Mar 2006 09:36:45 GMT</pubDate><guid isPermaLink="false">72050d9c-4f41-4a16-9f70-ebbf2c98a2c7:199</guid><dc:creator>andrewbettany</dc:creator><slash:comments>0</slash:comments><comments>http://192.168.2.20/forums/thread/199.aspx</comments><wfw:commentRss>http://192.168.2.20/forums/commentrss.aspx?SectionID=7&amp;PostID=199</wfw:commentRss><description>&lt;p class="MsoNormal"&gt;Hi fellow SBSers&lt;br&gt;
&lt;br&gt;
What are your generally accepted guidelines regarding patching of a SBS server?&lt;br&gt;
&lt;br&gt;
I appreciate that this for many SME's the SBS box is their only/critical
server, and that therefore we cannot allow a rogue patch to bring it down (or
not install it - leaving a potential vulnerability open), however, I do get
frustrated by the potential duplication of effort with regard to the "best
practice" of testing the patches on a test machine first.&lt;br&gt;
&lt;br&gt;
The general arguments are that any patch/update could potentially bring a
server down, since nearly every server is unique (at least until virtualisation
removes this issue), and therefore each patch should be tested prior to
deployment.&amp;nbsp; I can of course test the patch myself on my test SBS server,
but even this machine lacks some of the LOB apps and hardware that my clients
have, and therefore it is impossible to guarantee the success of an incubated
patch.&lt;br&gt;
&lt;br&gt;
Also MS do test extensively the patches before release, and therefore the
problems that are encountered, tend to be on the non standard setup servers
running bespoke LOB applications etc.&lt;br&gt;
&lt;br&gt;
How can we, as a community, collaborate to make the patching process simpler?
How safe, in the SBS&amp;nbsp;world is it to simply switch on the update service
and walk away?&amp;nbsp; Do all SBSC consultants currently test each patch, or do
they allow the critical patches to update your customers, and then become
reactive when a problem arises?&lt;br&gt;
&lt;br&gt;
Is there, or should there be a central depository of the issues surrounding the
patches that we can turn to, to quickly see if a particular server, with a LOB,
and various choices of hardware will be ok - like a matrix or database of
patches/software/equipment - perhaps that the community subscribe and update?&lt;br&gt;
&lt;br&gt;
Of course our primary concern is to keep our customers safe and
protected.&amp;nbsp; My concern (and dilemma) is that if we adopt established
"enterprise level" best practices, which is to test/incubate/test
deploy/full deploy the patches then we all duplicate a vast amount of effort
when in reality we (and our customers) have the least resources to do this, and
yet with many of our customers, all of our eggs are in one basket and therefore
more at&amp;nbsp;vulnerable to the&amp;nbsp;problem.&lt;br&gt;
&lt;br&gt;
I look forward to your comments....&lt;br&gt;
&lt;br&gt;
Regards&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
Andrew in Sheffield&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>