Installation and Patching

How can we improve the installation and patching of Windows Server?

(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can support and comment on it.

If it doesn't exist, you can post your idea so others can support it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. KB4015553 on Windows Server 2012 R2 with SQL 2008 R2 creates System Kernel Process Handle/Thread Leak

    KB4015553 on a Windows Server 21012 R2 with SQL 2008 R2 creates a System Kernel Process Handle/Thread Leak. It is easy to see in the Task Manager after adding the Handle/Thread count columns. The counts increase nearly 1 per second until the OS and system is unresponsive and collapses.

    Another indicator is in the event logs, 4231 events appear: Description:
    A request to allocate an ephemeral port number from the global TCP
    port space has failed due to all such ports being in use.

    But the ephemeral port alert is not the root cause.

    7 votes
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      I agree to the terms of service
      Signed in as (Sign out)

      We’ll send you updates on this idea

      4 comments  ·  Patch Behaviors  ·  Flag idea as inappropriate…  ·  Admin →
    • KB3213986 Causes Logon Failures When Starting BITS Service - Please fix

      After installing update KB3213986 on Server 2016 Desktop Experience, a failed logon is logged every time the BITS service is started.

      Failed Logon Event:
      Log Name: Security
      Source: Microsoft-Windows-Security-Auditing
      Date: 2/27/2017 1:27:10 PM
      Event ID: 4625
      Task Category: Logon
      Level: Information
      Keywords: Audit Failure
      User: N/A
      Computer: PLB-DXX-TP01.dev-products.local
      Description:
      An account failed to log on.

      Subject:
      Security ID: SYSTEM
      Account Name: PLB-DXX-TP01$
      Account Domain: DEV-PRODUCTS
      Logon ID: 0x3E7

      Logon Type: 5

      Account For Which Logon Failed:
      Security ID: NULL SID
      Account Name: -
      Account Domain: -

      Failure Information:
      Failure Reason: An Error occured during Logon.
      Status: 0xC0000073
      Sub Status: 0xC0000073

      13 votes
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        I agree to the terms of service
        Signed in as (Sign out)

        We’ll send you updates on this idea

        7 comments  ·  Patch Behaviors  ·  Flag idea as inappropriate…  ·  Admin →
      • Implement complete removal of unsused products in WSUS 3.x

        Please implement an ability to really get rid off unused products in WSUS 3.x

        Example:
        A company once used XP and 7 and now upgraded to Windows 10. However it is not possible to really purge old products from the WSUS database.

        The Update files can be removed using the cleanup wizard, but the entries in the MSSQL DB will remain.

        Especially if one has once used the older drivers category that has been reorganized for Windows 10, this causes a lot of performance issues and only a fresh WSUS without adding old products and categories will help.

        This is…

        1 vote
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          I agree to the terms of service
          Signed in as (Sign out)

          We’ll send you updates on this idea

          1 comment  ·  WSUS  ·  Flag idea as inappropriate…  ·  Admin →
        • Add Windows Update Group Policy Feature to allow clients to download approved updates directly from Microsoft

          I have a local WSUS server, it stores all my updates for my local users, I approve the updates and everything is great. At the same time I have bunch of remote offices that have faster WAN connections than VPN/MPLS.

          I can setup a second WSUS server, point it at my upstream server at HQ and tell it to not store the updates. All clients connecting to this server will fetch updates from Microsoft.

          Why not make this a simple binary GPO overwrite instead of adding the complexity?

          Force client to fetch windows update binaries from Microsoft

          2 votes
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            I agree to the terms of service
            Signed in as (Sign out)

            We’ll send you updates on this idea

            0 comments  ·  WSUS  ·  Flag idea as inappropriate…  ·  Admin →
          • NoAutoRebootWithLoggedOffUsers - Windows Server OS

            Considering the server availability, we administrators are not getting downtime as we desired. So, Microsoft should give the support for server OS to prevent the reboot the server in logged-off mode after windows update installation. I have a suggestion that I'm giving below. If it is possible, it is very helpful to the world of Windows administrators. Add the registry value in server at least in all available server operating systems

            [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU]

            "NoAutoRebootWithLoggedOffUsers"=dword:00000001

            1 vote
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              I agree to the terms of service
              Signed in as (Sign out)

              We’ll send you updates on this idea

              0 comments  ·  Windows Update  ·  Flag idea as inappropriate…  ·  Admin →
            • Separate Windows 10 by branch / version

              Actually Windows 10 on WSUS is only reflected by a major product category and LTSB.

              It would be much better if you could add a product category for each branch / release:

              such as:
              Windows 10 1507 (LTSB 2015)
              Windows 10 1511
              Windows 10 1607 (LTSB 2016, CBB)
              Windows 10 1703 (CB)

              This would allow companies with a good patch management to effectively avoid downloading CU patches for Windows 10 that they do not use and also would help to categorize updates in the views.

              1 vote
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                I agree to the terms of service
                Signed in as (Sign out)

                We’ll send you updates on this idea

                0 comments  ·  WSUS  ·  Flag idea as inappropriate…  ·  Admin →
              • URGENT: Seperate Category for Preview Update Rollups needed!

                Actually it is not really possible to use automatic acknowledgement rules without acknowledgeing any Preview security or preview feature upates for Windows 7, 8.1 etc.

                Please put them a seperate WSUS Category e.g. preview rollups so that an effective testing can be made with rulesets and a test group of computers.

                1 vote
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  I agree to the terms of service
                  Signed in as (Sign out)

                  We’ll send you updates on this idea

                  0 comments  ·  WSUS  ·  Flag idea as inappropriate…  ·  Admin →
                • Implement WID reindexing and DB shrinking for WSUS on WID

                  There exist a technet site with a maintenance SQL script to reindex the WID for WSUS 3.x, it would be great if you could implement this into the GUI, aside having a capability to backup and restore, aswell as shrinking the WID database.

                  1 vote
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    I agree to the terms of service
                    Signed in as (Sign out)

                    We’ll send you updates on this idea

                    0 comments  ·  WSUS  ·  Flag idea as inappropriate…  ·  Admin →
                  • BUG: Cleaning up WID for WSUS on Windows 2008 R2 causes DB timeouts

                    this is a known bug but I think rather than reindexing and cleaning up the WSUS DB with a SQL script you could fix this programmatically.

                    The issue is know an happens during the first stage of the wizard when cleaning up old updates.

                    1 vote
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • facebook
                    • google
                      Password icon
                      I agree to the terms of service
                      Signed in as (Sign out)

                      We’ll send you updates on this idea

                      0 comments  ·  WSUS  ·  Flag idea as inappropriate…  ·  Admin →
                    • Implement GUI and easier XML rule creation for USMT (Windows 10 ADK)

                      It is cool to see that ADK will be updated with every new Windows 10 release but USMT seems to complicated for new admins.

                      Please implement a GUI and a visual creation for the XML files to control this service.

                      I personally don't want to study a book to make it work right.

                      1 vote
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • facebook
                      • google
                        Password icon
                        I agree to the terms of service
                        Signed in as (Sign out)

                        We’ll send you updates on this idea

                        0 comments  ·  Deployment & Installation  ·  Flag idea as inappropriate…  ·  Admin →
                      • 1 vote
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • facebook
                        • google
                          Password icon
                          I agree to the terms of service
                          Signed in as (Sign out)

                          We’ll send you updates on this idea

                          1 comment  ·  Windows Update  ·  Flag idea as inappropriate…  ·  Admin →
                        • Increase Active Hours from 12 hours to 22 hours

                          The current 12 hour window for "Active Hours" needs to be longer so the updates/reboots can happen in the middle of the night.

                          5 votes
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • facebook
                          • google
                            Password icon
                            I agree to the terms of service
                            Signed in as (Sign out)

                            We’ll send you updates on this idea

                            1 comment  ·  Patch Management  ·  Flag idea as inappropriate…  ·  Admin →
                          • Change update behavior on Windows Server 2016

                            In server 2016 when downloading an update it also installs the same time (no option to only download), then the 12hour window begins, when this is over and time is outside worktimeframe (which is a somehow strange setting for a server) the server automatically reboots.

                            The same when I install something microsoft related during workhours which normaly has no effect on user experience, but if setup installs also a patch then the reboot countdown also starts.

                            Please change back to the old behavior where downloading updates and installing them where different tasks and also rebooting had to be user initiated.

                            1 vote
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • facebook
                            • google
                              Password icon
                              I agree to the terms of service
                              Signed in as (Sign out)

                              We’ll send you updates on this idea

                              0 comments  ·  Windows Update  ·  Flag idea as inappropriate…  ·  Admin →
                            • Increase limit of 3rd party categories in WSUS

                              Currently there is a limit of 100 3party (non-microsoft) categories in WSUS.

                              We are using a 3party patchsupplier (Shavlik, now Ivanti) and this limit of 100 categories is a big limitation for us.

                              1 vote
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • facebook
                              • google
                                Password icon
                                I agree to the terms of service
                                Signed in as (Sign out)

                                We’ll send you updates on this idea

                                0 comments  ·  WSUS  ·  Flag idea as inappropriate…  ·  Admin →
                              • WSUS does not display the operating system for Windows 2016 servers as 2016 servers. It shows them as Window 10 machines.

                                WSUS 2012 does not display the operating system for Windows 2016 servers as 2016 servers. It shows them as Window 10 machines.

                                . Background
                                WSUS 2012 does not display the operating system for Windows 2016 servers as 2016 servers. It shows them as Window 10 machines.

                                Problem Description
                                This creates a fair amount of confusion as we know these are Server 2016 systems but we can’t be certain that they’re being updated properly without examining each system to ensure it has the current platform-specific updates

                                3 votes
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • facebook
                                • google
                                  Password icon
                                  I agree to the terms of service
                                  Signed in as (Sign out)

                                  We’ll send you updates on this idea

                                  0 comments  ·  WSUS  ·  Flag idea as inappropriate…  ·  Admin →
                                • Get-WsusComputer -ComputerUpdateStatus failed -ComputerTargetGroups clients <-- this lists ALL in the target group, instead of only those

                                  Get-WsusComputer -ComputerUpdateStatus failed -ComputerTargetGroups clients <-- this lists ALL in the target group, instead of only those that have status=failed

                                  Same result if I use -IncludedInstallationStates Failed too.

                                  2 votes
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • facebook
                                  • google
                                    Password icon
                                    I agree to the terms of service
                                    Signed in as (Sign out)

                                    We’ll send you updates on this idea

                                    0 comments  ·  WSUS  ·  Flag idea as inappropriate…  ·  Admin →
                                  • PowerShell for Windows Deployment Services lacking and/or broken

                                    Trying to automate the process of building boot image and installation image into WDS. It is nice to see some PowerShell commands, but there are still things that appear not to be possible to do with PowerShell and must resort to WDSutil. For example, I cannot find a cmdlet to create a new driver group. I have to issue the wdsutil command to create the driver group. I can then add all my drivers into the group using PowerShell, but then there does not appear to be a way to use PowerShell to filter the drivers by group to be…

                                    2 votes
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • facebook
                                    • google
                                      Password icon
                                      I agree to the terms of service
                                      Signed in as (Sign out)

                                      We’ll send you updates on this idea

                                      0 comments  ·  WDS & MDT  ·  Flag idea as inappropriate…  ·  Admin →
                                    • Remove supersedence logic from Server 2012 R2 security patches

                                      Currently the non quality security updates are superseded by the security quality updates. This causes most of the standard reporting to break for companies that do not need or want the quality updates for security patches. 3rd party scanners also will show servers as non patched if a company only installs the non quality package. Please do not set the quality updates to supersede the non quality updates. This will prevent companies from having to spend large amounts of development time to rework their processes that worked for several years.

                                      5 votes
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • facebook
                                      • google
                                        Password icon
                                        I agree to the terms of service
                                        Signed in as (Sign out)

                                        We’ll send you updates on this idea

                                        0 comments  ·  Patch Behaviors  ·  Flag idea as inappropriate…  ·  Admin →
                                      • KB3159706 make WSUS console crash.

                                        After install KB3159706, WSUS console can't be opened. Need to do post installation action. It did make trouble. At firs, user doesn't know what cause this problem. After spending time to search for solution, user figure out that this problem is caused by KB3159706. It waste user's time. It's better to have a way to warning user that there is known issue in the update patch when user install the update patch.

                                        1 vote
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • facebook
                                        • google
                                          Password icon
                                          I agree to the terms of service
                                          Signed in as (Sign out)

                                          We’ll send you updates on this idea

                                          0 comments  ·  WSUS  ·  Flag idea as inappropriate…  ·  Admin →
                                        • IIS logging for WSUS

                                          Minimize number of 500 errors in IIS logs due to recycling of WSUS AppPool during client scans as it causes excessive false positives in monitoring systems.

                                          5 votes
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • facebook
                                          • google
                                            Password icon
                                            I agree to the terms of service
                                            Signed in as (Sign out)

                                            We’ll send you updates on this idea

                                            0 comments  ·  WSUS  ·  Flag idea as inappropriate…  ·  Admin →
                                          ← Previous 1 3
                                          • Don't see your idea?

                                          Feedback and Knowledge Base