Rechercher dans ce blog

Affichage des articles dont le libellé est WSUS. Afficher tous les articles
Affichage des articles dont le libellé est WSUS. Afficher tous les articles

mardi 4 juin 2019

MISES A JOUR WINDOWS 10. PB RÉCURENT CHEZ NOS CLIENT PME

Tout d’abord Windows 10 ne change plus de nom, cela n’empêche pas l’évolution des versions.
Cela correspond a une évolution du système donc une réinstallation du système.
« Pour info les mises à jour sont automatiques et gérées par Microsoft, alors que le changement de version peuvent être provoqué, ou pas. »

Les version WINDOWS 10 depuis 1507 a la 1903 pourraient s’apparenter schématiquement aux Versions suivantes:
« La 1903 dernière évolution pas encore très diffusée par Microsoft »

Version 1507.                                                                      Windows 10
Version 1511 (November Update)                                    Windows 10.1
Version 1607 (Anniversary Update)                                 Windows 11
Version 1703 (Creators Update)                                       Windows 12
Version 1709 (Fall Creators Update)                                Windows 12.1
Version 1803 Springs Fall Creators.                                 Windows 13
Version 1809 October 2018 Update.                                 Windows 13.1
Version 1903 Mai 2019 (avec beaucoup de retard)             Windows 14


Ceci dit Microsoft ne supporte plus que Windows Version N-2 , en gros a partir du moment ou la Version est complètement diffusée Microsoft considère qu’en dessous la version N-2 c’est en fin de vie. (en moyenne 18 & 20 Mois)

CAD : pour la version en cours : la 1809 sera supportée jusques Mai 2020 alors que sa petite sœur N-2 ne sera plus supportée en terme de mise à jour et de mise a jour de services en avril 2019 . (Pour la 1709 c’est aujourd’hui.



Comparativement,
sur les anciennes versions, l’échéance était plus ou moins 5 ans ca fait tout de même la différence et le support allait jusqu’à 10 Ans.


Quelles implications de la fin de vie de Windows 10 ?

Les conséquences et implications d’une fin de support de Windows 10 sont multiples mais parmi les principales :
§  Plus aucune mise à jour dont les mises à jour de sécurité ne sont publiées pour cette version
§  Les éditeurs de logiciels vont petit à petit abandonner cette version et plus tard passera, plus vous rencontrerez des difficultés pour trouver des logiciels qui fonctionne sur cette version de Windows 10
Vous trouverez plus de détails et explications autour des implications 
sur l’article : Fin de support de Windows


WSUS
Pour avoir essayé WSUS dans tous les sens et vu avec différents techniciens d’autres services informatiques,
le constat est malheureusement très mauvais avec W10.
Le produit ne fonctionnerait correctement qu’avec des versions OPEN ENTREPRISE et LSTB. « Mais le prix n’est pas le même ».
Autrement dit la solution WSUS est une source de PBs qui n’apporte aucun avantage sur Windows 10, sans compter le besoin en ressource, la volumétrie, et la gestion de ce produit, alors qu’elle pouvait être très intéressante sur les versions précédentes il faut éviter celle-ci pour W10.
REF WSUS:
Je n’ai pas essayé la version OFFLINE.

REF DOC.

POUR LES TECHS
W10
Outils de création et de mise à jour W10
ou
OFFICE / WINDOWS
Outils de création ISO pour les Office et autres systèmes Microsoft
https://www.heidoc.net/joomla/technology-science/microsoft/67-microsoft-windows-and-office-iso-download-tool
ET BIEN EVIDEMENT RUFUS
https://rufus.ie/

vendredi 24 septembre 2010

GPO – WSUS - SBS2008

Comment recréer les GPO WSUS pour SBS 2008.

http://blogs.technet.com/b/sbs/archive/2009/09/03/how-to-manually-create-the-sbs-2008-and-wsus-group-policies-objects.aspx

Certain Group Policy Objects (GPOs) are created and configured by default during the installation of SBS 2008. This blog post will cover how to create these GPOs manually in the event that they are missing or have been accidentally deleted without a backup. Note: If one or more of these GPOs are missing as the result of a failed install, you should not follow this procedure. We recommend that you call Microsoft Product Support as other components are likely to be broken. The steps have been broken down into two types of Group Policies:

Update Services Policies:

  • Update Services Client Computers Policy
  • Update Services Common Settings Policy
  • Update Services Server Computers Policy

Windows SBS Policies:

  • Windows SBS Client – Windows Vista Policy
  • Windows SBS Client – Windows XP Policy
  • Windows SBS Client Policy
  • Windows SBS CSE Policy
  • Windows SBS Users Policy
  • Small Business Server Folder Redirection Policy (Optional)

We do not cover the steps to create the Default Domain Controllers Policy or the Default Domain Policy in this post. Either restore these policies from backup or contact Microsoft Product Support Services for assistance.

Create the three Update Services Policies
  1. Open Start > Run and enter gpmc.msc to open the Group Policy Management Console.
  2. Expand Forest: <SBS Forest>\Domains\<SBS Domain>\Group Policy Objects

  3. image

 

 

 

 

 

 

  1. Right-click the Group Policy Objects key and choose New
  2. Enter Update Services Client Computers Policy as the name
  3. Select OK
    image
    ***The name must be entered exactly as shown, DOUBLE CHECK your spelling before selecting OK
  4. Create the two remaining WSUS policies in this way
    • Update Services Common Settings Policy
    • Update Services Server Computers Policy
Configure the Update Services Client Computers Policy
  1. Right-click Update Services Client Computers Policy and choose Edit. On the Group Policy Management Editor, open Computer Configuration\Policies\Administrative Templates\Windows Components\Windows Update
  2. Configure the settings as shown in the report below

image

Configure the Update Services Common Settings Policy
  1. Right-click Update Services Common Settings Policy and choose Edit. On the Group Policy Management Editor, open Computer Configuration\Policies\Administrative Templates\Windows Components\Windows Update
  2. Configure the settings as shown in the report below

image

Important: The Set the intranet update service for detecting updates and Set the intranet statistics server policies are specific to your server and must be configured with http://<YourServerName>:8530

Note: The above report for this GPO shows the “enabled” and “disabled” policy settings only. Any policy that does not appear in the above report should be set to “Not configured” on your server.

Configure the Update Services Server Computers Policy
  1. Right-click Update Services Server Computers Policy and choose Edit. On the Group Policy Management Editor, open Computer Configuration\Policies\Administrative Templates\Windows Components\Windows Update
  2. Configure the settings as shown in the report below

image

Configure the scope of the new Update Services Policies

The configuration on the Scope tab for each new Update Services GPO needs to be as follows:

  1. Update Services Client Computers Policy
    • Leave “Links” empty
    • Remove any object under “Security Filtering”
    • Set “WMI Filtering” to <none>
  2. Update Services Server Computers Policy
    • Leave “Links” empty
    • Remove any object under “Security Filtering”
    • Set “WMI Filtering” to <none>
  3. Update Services Common Settings Policy
    • Leave “Links” empty
    • “Authenticated Users” must be listed under “Security Filtering”
    • Set “WMI Filtering” to <none>
Link the new Update Services Policies
  1. In the Group Policy Management Console, right-click on your SBS domain and select Link an Existing GPO
    image
  2. Select the following 3 policies
    • Update Services Client Computer Policy
    • Update Services Common Settings Policy
    • Update Services Server Computer Policy
  3. Click OK

Once the WSUS policies have been updated and applied, Security Filtering on the Client Computers and Server Computers GPOs will begin populating with the machine accounts of your domain joined clients and servers. This is done automatically by SBS.

Create the Windows SBS Policies

Create the Small Business Server Folder Redirection Policy (Optional):

This is an optional GPO. Follow these steps only if you wish to use folder redirection

  1. On the SBS 2008 Console, select the Shared Folders and Web Sites tab
  2. On the Right hand side, under “Tasks” select Redirect folders for user accounts to the server
  3. Complete the wizard

image

Create the remaining SBS GPOs

These steps will create the following GPOs:

  • Windows SBS Client – Windows Vista Policy
  • Windows SBS Client – Windows XP Policy
  • Windows SBS Client Policy
  • Windows SBS CSE Policy
  • Windows SBS Users Policy
  1. Copy the following file and save it to an easily accessible path, such as c:\windows\temp, on the SBS 2008 server:
    http://cid-d5fe25afb6c3615f.skydrive.live.com/self.aspx/.Public/gpofix.txt
  2. Right-click on the Command Prompt and select Run as Administrator
    image
  3. Run the following command from the Administrator Command prompt, substitute the path to the gpofix.txt file as needed (We recommend that you DO NOT copy & paste the command directly from the blog post):

    “C:\Program Files\Windows Small Business Server\Bin\GPOTask.exe” /config:c:\windows\temp\gpofix.txt
  4. The task will take a few moments to complete, after which it will return to the command prompt
    image
  5. Verify that the GPOs have been created in the Group Policy Management Console
  6. Run and complete the Internet Address Management Wizard from the SBS 2008 Console to complete the configuration.