What's up, guys?
This is Sohan and you are
watching Technical Spark.
In our WSUS series,
in this episode,
we are going to see how
to approve and deploy
patches on your Windows
Client Machines step by step.
This is one of the very
important and crucial part
of the WSUS because when we
install and configure WSUS,
our main purpose is to serve the
updates to all manager machines.
And in earlier
videos, we already
saw how to install
and configure WSUS,
as well as we already saw how to
configure the GPO so that when
any new machine
joins your domain,
it will automatically
report to your WSUS server.
So similar way, what
I have done here
is I have approved some
patches in my WSUS.
For example, let me
go to the Updates
and then expand
this, All Updates.
If you see, right now, these
are the unapproved updates
which is showing here.
So which means this will not
install to any of the machines.
But however, if any system
requires any patches,
then it will show you
in here, Needed Count.
If you don't know
how to get that,
simply right click
here and choose
what are the desired field
you would like to add
into this particular dashboard.
If you want to deploy
any of the software,
then you can simply right click
and then go to the Approve.
Choose the group
where you would like
to add [INAUDIBLE] app
updates to be deployed.
Right now, I'm not
going to approve this.
But if I go to the
top, then you will
observe that some of the updates
have already been approved.
So let me show you that.
Simply click on here,
Approve Updates.
Refresh.
So these are the updates
which I have already
approved in my WSUS, like
Microsoft Defender Antivirus,
Software Removal Tool.
So these are very crucial
and very important
updates which should be
served on a day-to-day basis.
And if I go to the Computers.
So guys, in Computers,
what I'm going to do here
is since both the
machines are 100% patched
so we'll add one more machine
into our this particular WSUS.
We have already configured
the policy in GPO.
So if we join any machine in
[INAUDIBLE] Active Directory,
then that machine
will automatically
report to our WSUS server.
We don't have to do any
manual configuration.
So next what we will do, I
have another machine which
I have joined into the domain.
But after joining
domain, I haven't
started that machine, which
means the first reboot
is not completed yet.
For that, let me
turn on that machine.
Here we go, the
machine is powered on.
Let me enter the credentials.
OK, guys, now we'll log in
with our domain administrator.
So Technical Spark is my domain,
backslash, administrator.
So this is the first time
I'm logging into the domain.
So machine has started now.
Technicalspark.com is my domain.
And the host name is Patching.
Now let's go to the Windows,
then Settings, Updates.
Great, friends, it looks like
my this particular machine
has already detected
and has downloaded
one update from our WSUS server
and it's asking us to install.
It didn't get installed
automatically.
Why?
Because in our GPO policy, we
have configured these settings
that download updates
automatically and ask
for install.
So it's completely working
as per our group policy.
And as you can see in
the top, some settings
are managed by
your organization.
Click on Install Now and
it will start installing.
Meanwhile, let's
check out in our WSUS
server whether this machine
is showing in our WSUS or not.
For that, let me jump
to the WSUS server.
OK, let's refresh the screen.
Yeah, perfect guys.
It just got updated here,
Patching.technicalspark.com.
And patch level is 96%.
And there are almost 67 patches
which are needed by this server.
Right now, only one software
is getting installed.
But yeah, there are
almost 67 softwares
which we need to approve.
So how we can do that?
Let's go to the
All Updates again.
Or you can also go to the WSUS.
And if you observe here,
Update Status, it says,
updates needed by computer.
Click on that.
[AUDIO LOGO]
So these are basically
updates which need
to be approved for our server.
So how we can do that?
Just review all the updates
which are available here.
Scroll down.
If you think that one of
the updates is not required,
you can unselect that
particular update like this.
But right now, I'm going to
select all the updates just
for your demonstration and
then right click, Approve.
So where exactly my this
particular machine is present?
Then it's in unassigned group.
So we have to select that and
click on Approve or Install.
OK.
Now it's approving
all the updates.
Click on Close.
My updates have been approved.
Now if I go to
the WSUS, then you
can see there are almost
7 GB of updates which
are getting downloaded now.
Where exactly all
the updates will
download in your WSUS server?
So as I said earlier
in this PC, I
have created one
directory that is D drive.
In D drive under WSUS Directory,
here your all the patch updates
will get stored.
Now let's go back
to All Updates.
Now, guys, let's go
to our client machine
to see whether updates
got installed or not.
Perfect, the update
is installed.
Click on Check for updates.
Right now it's not
showing any updates.
It's just because our WSUS
server is yet to be updated.
Now let me check out
the Update History.
Driver update is
installed on 19/01.
Other updates is
installed today.
So, guys, now let's go
back to our WSUS server.
All Computers, perfect, WSUS.
As of now, [INAUDIBLE]
has been downloaded.
So I'm not going to cover
the other things here
but I'll let you know
what exactly will happen.
It will download
all the 7 GB of data
in our server, which means all
the updates will be downloaded
in our WSUS server.
And then it will start
distributing this update
to the PC to which
these updates are
required, like my recently
domain joined machine,
Patching server.
So all these updates
will be deployed
on that particular machine.
And once the machine
is updated, then you
will be able to see
100% status here,
which is right now showing 96%.
And the exclamation
mark you are seeing here
will be gone automatically.
So hopefully, friends, now you
are very much or pretty much
clear that how
these things works.
Friends, I hope you
have learned something
in this video about
WSUS patching.
Friends, if you have
found this video useful,
then please click
on the Like button
and don't forget to
share and subscribe.
Additionally, if you think
that the content which
I upload on this
channel is meaningful,
then don't forget to share this
channel link with your friends
and colleagues so that we can
grow our community very faster.
And based on your response,
I will start uploading videos
more frequently.
If in case if you still
have any question, queries,
then feel free to
comment down below.
I will definitely try to
answer all of your queries.
This is Sohan signing out.
I'll catch you in the
next amazing WSUS video.
Till then, bye-bye.