ESU Updates - ConfigMgr

%3CLINGO-SUB%20id%3D%22lingo-sub-1070575%22%20slang%3D%22en-US%22%3EESU%20Updates%20-%20ConfigMgr%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1070575%22%20slang%3D%22en-US%22%3E%3CP%3EWhat%20will%20be%20the%20best%20process%20for%20adding%20updates%20into%20ConfigMgr%20and%20deployments%3F%26nbsp%3B%20Are%20we%20able%20to%20use%20Software%20Updating%20to%20deploy%20ESU%20updates%20or%20would%20we%20need%20to%20create%20Applications%20or%20Packages%2FPrograms%20for%20each%20update%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAlso%20in%20the%20'How%20to%20get%20Extended%20Security%20Updates%20for%20eligible%20Windows%20devices'%20blog%20it%20mentions%20we%20are%20able%20to%20use%20ConfigMgr%20to%20deploy%20slmgr%20scripts.%26nbsp%3B%20Is%20there%20an%20example%20script%20we%20are%20able%20to%20use%20or%20is%20there%20any%20specific%20syntax%20that%20is%20needed%20for%20deployment%20via%20ConfigMgr%3F%26nbsp%3B%20Thanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1070592%22%20slang%3D%22en-US%22%3ERe%3A%20ESU%20Updates%20-%20ConfigMgr%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1070592%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F491717%22%20target%3D%22_blank%22%3E%40CheckEngine%3C%2FA%3E%26nbsp%3BDeployment%20and%20activation%20of%20the%20MAK%20can%20be%20accomplished%20via%20script%20deployment%20from%20Configuration%20Manager%20as%20documented%20at%3A%26nbsp%3B%3C%2FP%3E%3CH3%20id%3D%22toc-hId-1059390103%22%20id%3D%22toc-hId-1059390103%22%20id%3D%22toc-hId-1059390103%22%20id%3D%22toc-hId-1059390103%22%3EHow%20to%20get%20Extended%20Security%20Updates%20for%20eligible%20Windows%20devices%3C%2FH3%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FWindows-IT-Pro-Blog%2FHow-to-get-Extended-Security-Updates-for-eligible-Windows%2Fba-p%2F917807%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FWindows-IT-Pro-Blog%2FHow-to-get-Extended-Security-Updates-for-eligible-Windows%2Fba-p%2F917807%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1070620%22%20slang%3D%22en-US%22%3ERe%3A%20ESU%20Updates%20-%20ConfigMgr%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1070620%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F491717%22%20target%3D%22_blank%22%3E%40CheckEngine%3C%2FA%3E%20please%20see%26nbsp%3B%3CA%20title%3D%22Extended%20Security%20Updates%20and%20Configuration%20Manager%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fconfigmgr%2Fcore%2Fplan-design%2Fconfigs%2Fsupported-operating-systems-for-clients-and-devices%23bkmk_ESU%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fconfigmgr%2Fcore%2Fplan-design%2Fconfigs%2Fsupported-operating-systems-for-clients-and-devices%23bkmk_ESU%3C%2FA%3E%20regarding%20the%20story%20on%20ConfigMgr%20and%20ESU.%20Security%20patches%20released%20under%20the%20ESU%20program%20will%20be%20published%20to%20the%20normal%20distribution%20channels%2C%20which%20includes%20WSUS.%20So%2C%20by%20default%2C%20these%20patches%20will%20be%20displayed%20in%20ConfigMgr%20for%20normal%20SUM%20deployment.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThere%20is%20a%20separate%20conversation%20that%20includes%20a%20sample%20script%20provided%20by%20the%20community.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1070626%22%20slang%3D%22en-US%22%3ERe%3A%20ESU%20Updates%20-%20ConfigMgr%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1070626%22%20slang%3D%22en-US%22%3E%3CP%3EGreat%20question%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F491717%22%20target%3D%22_blank%22%3E%40CheckEngine%3C%2FA%3E.%20I'm%20guessing%20you're%20referring%20to%3A%3C%2FP%3E%3CDIV%3E%3CH3%20id%3D%22toc-hId-1059390103%22%20id%3D%22toc-hId--748064360%22%3ECan%20all%20supported%20versions%20of%20Configuration%20Manager%20current%20branch%20be%20used%20to%20deploy%20and%20install%20security%20updates%20released%20under%20the%20extended%20security%20updates%20program%3F%3C%2FH3%3E%3CP%3ENo.%20Only%20the%20latest%20released%20version%20of%20Configuration%20Manager%20current%20branch%20should%20be%20used.%3C%2FP%3E%3CDIV%3ESource%3A%20%3CA%20title%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fconfiguration-manager-blog%2Fextended-security-updates-and-configuration-manager%2Fba-p%2F825618%22%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FConfiguration-Manager-Blog%2FExtended-Security-Updates-and-Configuration-Manager%2Fba-p%2F825618%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FConfiguration-Manager-Blog%2FExtended-Security-Updates-and-Configuration-Manager%2Fba-p%2F825618%3C%2FA%3E%3C%2FDIV%3E%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%3EAlso%2C%20for%20other%20reading%20this%20thread%2C%20the%20link%20to%26nbsp%3B%3CSPAN%3E%26nbsp%3B'How%20to%20get%20Extended%20Security%20Updates%20for%20eligible%20Windows%20devices'%26nbsp%3Bis%3A%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%3E%3CSPAN%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FWindows-IT-Pro-Blog%2FHow-to-get-Extended-Security-Updates-for-eligible-Windows%2Fba-p%2F917807%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FWindows-IT-Pro-Blog%2FHow-to-get-Extended-Security-Updates-for-eligible-Windows%2Fba-p%2F917807%3C%2FA%3E%3C%2FSPAN%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FLINGO-BODY%3E
Occasional Visitor

What will be the best process for adding updates into ConfigMgr and deployments?  Are we able to use Software Updating to deploy ESU updates or would we need to create Applications or Packages/Programs for each update?

 

Also in the 'How to get Extended Security Updates for eligible Windows devices' blog it mentions we are able to use ConfigMgr to deploy slmgr scripts.  Is there an example script we are able to use or is there any specific syntax that is needed for deployment via ConfigMgr?  Thanks

1 Reply

@CheckEngine please see https://docs.microsoft.com/en-us/configmgr/core/plan-design/configs/supported-operating-systems-for-... regarding the story on ConfigMgr and ESU. Security patches released under the ESU program will be published to the normal distribution channels, which includes WSUS. So, by default, these patches will be displayed in ConfigMgr for normal SUM deployment. 

 

There is a separate conversation that includes a sample script provided by the community. 

www.000webhost.com