ConfigMgr (SCCM) 2012 what’s new in Software updates

Configuration Manager 2012 is introducing a lot of changes in update deployment procedures. Most of the changes are around the "HOW" part while there are some new concepts too.

In this post I'll talk about what some of the changes are around:

  • Configuration of Software Updates components
  • Deployment of software updates to endpoints
  • Monitoring and tracking deployment status

 

Configuration of Software Updates Components

1. Software Update Point

a. If you have a Central Administration site in your design, you'll first need to have the Software Updates Management Site role installed on your Central Administration Site (CAS) server before you install this role on any other primary site server. The CAS Software update point will work as the upstream server for all updates and all primary sites.

b. If you have a single primary site server, you can install Software update point on the same server.

2. Now you'll find the Software Update Point configuration option under sites, Configure Site Components on the ribbon bar or if you right click on the site server

3. Supersedence Rules - helps you to control when a superseded update should be expired, so that the changes reflect accordingly on your SCCM compliance reports.

a. You can now opt to immediately expire a superseded software update

b. OR expire a superseded update after a specified time

clip_image002

4. Under Client Settings, Software Updates, now you'll see an additional option to install all updates meeting deadline in a specified future time. This option will save you from multiple restarts on computers.

clip_image003

Software Update Deployment

1. Filter Updates - The same concept of search folders , and you can easily add a criteria from the drop down list. Save search criteria with a name and use it every next time. Very helpful for your monthly deployments for different categories of machines.

clip_image004

2. Software Update Groups - Same concept of Update lists, but it will also include the deployment. Saves you from going to another folder to manage deployment.

clip_image006

3. Automatic Deployment Rules - This is what most of SMB customers were looking for. Now you can automate your monthly patch deployments for Workstations (or even servers) as well as for Forefront Endpoint Antivirus definition updates. You can also opt to perform deployment manually, by simply doing a right click and select "Run now".

clip_image008

4. More controls to end users under Software Center.

clip_image010

Monitoring and tracking deployment status

Alerts and Deployment status summary - In console alerts save you from switching screens between console and SCCM reports to track compliance data.

clip_image011

Click on the View Status hyperlink and you'll get detailed status summary.

clip_image013

Finally, you can also view and control alerts from the console.clip_image015

Additional Resources

Via http://blogs.technet.com/b/ptsblog/archive/2011/12/19/configuration-manager-2012-rc-what-s-new-in-software-update-management.aspx

2 Responses to "ConfigMgr (SCCM) 2012 what’s new in Software updates"

  1. I hope someone can answer this question. I have a software update group with nothing but windows xp updates in it. It is deployed to a device collection called windows xp computers that has only 9 xp computers in it. when I highlght the software update group and then click the summary tab at the bottom it tells me there are 36 compliant machines.... but I only have 9 computers in the device collection it is deployed too. I do have a windows 7 device collection with 40 something machines in it... but this to me should only pull numbers from the xp device collection that has 9 members... im confused as to why this is happening and going nuts trying to understand it.

    Reply
    1. Hi,
      the patches which you created in SU group as scanned by other computers in the organisation and can be reported to SCCM saying required or not required or installed. compliant machines doesnt mean they are installed with all the required patches. compliant is something that,computers are reporting back with their patch status.more information about compliance status here http://technet.microsoft.com/en-us/library/bb694299.aspx

      Reply

Leave a Reply to dan Cancel reply