System Center Essentials 2007 provides update management capabilities to enable administrators to view, download, and deploy software updates required by operating systems and other software on managed computers.

To manage updates in Essentials 2007, you need to access the Updates Overview pane by clicking the Updates button in the Essentials 2007 console. The overview pane allows you to easily view updates, determine which updates are needed by managed computers, centrally deploy updates to those computers, and then view deployment and other related reports.

Note
If you did not run the Computer and Device Management Wizard to discover computers or did not run the Updates Management Configuration Wizard to configure Update Management, you cannot manage updates. In this case, the Updates Overview screen displays a notice stating that essential configuration is incomplete. You must complete the listed tasks before you can manage updates.

Before you start managing updates, you should become familiar with the following terms.

Update


A software package that fixes an issue with a specific operating system or application.
Security updates


Updates that help protect your operating system or applications from exploitation.
Essentials 2007 required updates


Updates published by Microsoft that are related to Essentials 2007.

Update Management Process on the Management Server

Microsoft publishes security updates and other updates on the Microsoft Updates Web site. Essentials 2007 accesses that Web site to download information about available updates and to download the updates that are needed in your organization.

Deploying updates to managed computers consists of the following phases:

  1. Synchronize Essentials 2007 information about available updates with the information at the Microsoft Updates Web site.

  2. If you configured Update Management to store updates locally on the Management Server (in the %SYSTEMDRIVE%\SCE\WSUSContent folder by default, or in a folder you specify), Essentials 2007 downloads the updates and stores them locally.

  3. View available updates, and identify any updates that need to be deployed.

  4. Identify the computers that need the respective update. If necessary, create a new computer group that contains those computers.

  5. Approve the update for deployment to the specified computer group.

  6. Run reports to track the progress of the deployment and to identify any potential problems.

Using Computer Groups for Update Deployment

To deploy an update to a managed computer, the computer must be a member of a computer group. You can either use Essentials 2007 predefined computer groups or create a new group. In a single update deployment, you can deploy multiple updates to multiple computer groups.

Initial Synchronization

To start deploying updates to managed computers, Essentials 2007 must complete an initial synchronization with Microsoft Updates. During this initial synchronization, Essentials 2007 downloads information about updates and then downloads the updates according to the criteria that you specified. This process might require extensive resources, depending on your settings.

Subsequent synchronization runs on a regular schedule; however, it is faster than the initial synchronization because Essentials 2007 downloads only those updates that were published since the previous synchronization. When you configure update management for the first time after installing Essentials 2007, you can choose to perform the initial synchronization.

Automatic Approval

You can configure update management with automatic approval for selected types of updates and for select computer groups. After you configure automatic approval, the selected updates are automatically approved for the specified groups when Essentials 2007 downloads updates of the specified type. Deployment of those updates starts immediately with no further administrative intervention.

Update Management Process on the Managed Computers

The agent on managed computers checks for new updates every 22 hours. After the administrator approves updates for deployment, in its next cycle, the agent on an approved computer detects that a new update is available. The agent then determines when the update needs to be installed and displays a notification icon in the computer's notification area.

If an update requires a reboot, the agent complies with the current domain reboot policies that are in effect on the computer.

Important
Automatic Updates must be enabled on the managed computer to allow Essentials 2007 to deploy updates to that managed computer. To view the status of Automatic Updates, open the Control Panel and select Automatic Updates.

Installation Schedule

The installation schedule of an approved update depends on whether you set an installation deadline for the update and on the Automatic Updates settings:

  • If you set a deadline, the update is automatically installed during the next check-in from the client computer.

  • If you did not set a deadline, the installation time depends on how Automatic Updates is configured on the computer:

    • If Automatic Updates is configured to automatically download and install at a certain time, the update installs automatically at that time unless the user manually installs it before that time.

    • If Automatic Updates is configured for automatic download and manual install, the user can install the update at anytime.

See Also