On TechRepublic: Beware of crazy recruiter tricks
BNET Business Network:
BNET
TechRepublic
ZDNet

November 21st, 2007

How Microsoft could save businesses time & money when it comes to patching Windows

Posted by David Berlind @ 3:27 pm

Categories: General, IT Management, Security, Software Infrastructure, Web technology

Tags: Software-as-a-service, Microsoft Windows Update, Microsoft Windows Server Update Services, Customer, Server, Truth, Microsoft Corp., Option, Microsoft Windows, Operating Systems

A ZDNet reader that goes by the name of R.E. Riker posed an interesting question to me via e-mail the other day. He asked if maybe, giving the high frequency of updates that it issues for its operating systems (in his case, Windows XP), if offering more frequent Service Packs or update roll-ups wouldn’t be the more sensible thing to do for some of Microsoft’s customers.

In my back and forth exchange with Riker, I learned that he maintains about 70 systems in an environment where new updates from Microsoft must be tested before they are deployed. This can’t an unusual requirement out there in the business world.

For Riker, Microsoft’s monthly issue of such updates (on the second Tuesday of each month) makes such testing impractical. On the other hand, if Riker waits for Microsoft to issue the next Service Pack (which could be years), that’s too long for the systems he oversees to go without certain critical updates. Especially security-related ones. In his first e-mail, Riker wrote:

I would like to see Microsoft offer an option for security patch rollups at least on an annual basis (maybe semi-annually). In other words, compile an update containing all of the security patches for the past year (or half-year) that we could download, test, and then apply to our machines. I know ideally it would be better to apply the monthly updates, but that just isn’t feasible for many people, myself included. But I don’t want to stay completely unpatched or wait years on end for the next service pack. Trying to talk directly to Microsoft is next to impossible for us small fries. Would you be willing to maybe at least broach the topic either directly with them or through a blog? Thank you for your consideration.

I responded to Riker asking why he just doesn’t turn off automatic updates and then deploy them on a less frequent basis. Riker responded:

The option to turn off automatic updates and only update manually would be fine if it were only one or two machines. Going beyond that it becomes rather inefficient considering just the bandwidth alone.

And, well, I currently support 30 XP boxes with probably 40 more yet to upgrade (that’s right, we have 40+ machines on older OSs) . Of course, MS’s solution would be to upgrade all our PCs and set up a [Windows Server Update Services] Server. Ummh, well, first, if I had the resources for that, I probably wouldn’t be here begging. Second, I have a problem with a company asking us to shell out even more money to solve coding problems in their software! [DB's note: He has a good point. According to the WSUS requirements page, Windows Server 2003 is required. In other words, keeping XP up-to-date requires additional software licensing and hardware investments, not to mention time].

I guess what I am trying to find is some balance between not patching immediately (which just doesn’t work for us for multiple reasons) and going unpatched until a service pack is released (which is too long to go unpatched). I don’t feel like that is too much to ask especially in an environment where the hacking has gone professional. It was bad enough trying to cope with the script kiddies. We can’t compete with professional hackers as it is, but we don’t stand any chance at all with unpatched boxes. As small as we are, we’ve already seen some spear phishing attacks.

Finally, if he could have it his way, Riker writes:

Realistically, I don’t think I could do it more than twice a year. And I am certainly open to some other mechanism as long as it is relatively user friendly and I can download it once (even if it involves multiple files as long at that doesn’t get completely out of hand like the update catalog), test it out on a machine, and then apply it to the rest of them.

So, I did what Riker asked. I checked-in with Microsoft and here’s the response that was offered by a spokesperson:

Customers have many choices for servicing Windows. Windows Update is designed for customers who want to update individual PCs as Microsoft releases updates – either automatically or when the customer is ready. A second option is Windows Server Update Services, a free server role for Windows Server customers, which allows network administrators to control the distribution of updates across their network. Other options include full-featured software management tools like System Center as well as 3rd party programs.

Microsoft traditionally releases security updates on the second Tuesday of each month and encourages all customers to install them as quickly as possible. The servicing tools mentioned above are designed to make this as seamless as possible. Microsoft is in constant communication with its customers to better understand their needs and desires and builds its products and services to meet those needs.

Unfortunately, Microsoft’s response will be of little consolation to Riker who would easily fall behind if he relied on self-patching via Windows Update, but according to a schedule he sets (instead of Microsoft’s). Furthermore, I think Riker’s subtle point about who should bear the cost associated with patching numerous systems in a business environment is dead-on. After all, a good many of the patches that Microsoft issues are to deal with defects in the operating system.

I’m not saying “defect” in a negative way nor am I derogating Microsoft for the situation. The truth is that no software — not Windows, nor any of its competitors, nor any applications — is without its defects. The question is, if software is defective and the customer will require it to be patched and there’s a need for something like WSUS in order to manage the that patching according to business requirements (as is proven by the very existence of WSUS), then should the customer be expected to bear additional cost to get that WSUS functionality, or should it be offered for free? Or, should the customer be expected to bear the additional time and expense of aquiring, deploying, and maintaining a server on which to run WSUS? (WSUS is a free download but Windows Server 2003 is not).

While you contemplate that question, perhaps Microsoft will consider this suggestion which I’ve sent to it through my contacts: If there was ever a great opportunity to leverage the benefits of software-as-as-service, then perhaps this is it. Why, for example, couldn’t Microsoft host a multi-tenant WSUS server on the Internet for free? One that system administrators like Riker could turn to for the same WSUS functionality that they’d get if they ran WSUS locally, but without the headaches of running their own WSUS server? Would there be issues (like security) to work through? Sure. But Microsoft is capable of working through them and to the extent that it’s always looking for ways to better service its customers — especially the finicky small to medium businesses that are tough to satisfy — wouldn’t a hosted version of WSUS make sense?

Are you (or should you be) running a WSUS server to better manage the patching of your client systems? If Microsoft offered a cloud-based version of it — one that was integrated into its Windows Update service in a way that allowed you manage all of Windows’ patches on your schedule, would you take it? Or, even if you wouldn’t, should you still be asked to bear the cost of running a local WSUS server even though the purpose of it is largely to manage “manufacturer defects?”

What do you think?

David Berlind has been Executive Editor at ZDNet since 1998 and has been a technology journalist since 1991. Although he can't respond to all e-mails, he reads them all. You can reach David at david.berlind AT cnet.com. If you don't want the content of your e-mail to turn up in a blog entry, make sure you say so. To the extent that most e-mail he receives looks to sway his opinion about something, he usually looks to pass those points of view onto ZDNet's audience members for their consideration . For disclosures on David's industry affiliations, click here.
  • Talkback
  • Most Recent of 56 Talkback(s)
try this
https://addons.mozilla.org/en-US/firefox/addon/2699... (Read the rest)
Posted by: Hrothgar - PCLinuxOS User Posted on: 11/29/07 You are currently: a Guest | | Terms of Use
And, that is the advantage of open source. You can look for a provider that  DonnieBoy | 11/21/07
Yeah! absolutely  5ri | 11/21/07
At least you have someone to beg with MS  mdemuth | 11/22/07
Yeah right  tonymcs@... | 11/22/07
My - aren't you on the ball..  done@... | 11/26/07
Well, I must say..  Hrothgar - PCLinuxOS User | 11/29/07
I agree with WSUS as SAS  5ri | 11/21/07
RE: How Microsoft could save businesses time & money when it comes to patching Windows  chrisporter@... | 11/22/07
There is no Microsoft solution  jorjitop | 11/22/07
By dog!  done@... | 11/26/07
Well dog my cats!  Ole Man | 11/26/07
Zealots  robertcape@... | 11/26/07
Nail, meet Hammer.  Dr. John | 11/26/07
There are problems with cloud based WSUS  georgeou | 11/22/07
the challenges you identify are trivial  dberlind | 11/22/07
Some bad assumptions on your part  georgeou | 11/26/07
A crude remark about assumptions  Ole Man | 11/26/07
What does you mean by this?  t_mohajir | 11/26/07
Doh!  t_mohajir | 11/26/07
Fingers got tongue tied.  Dr. John | 11/26/07
3. = Bad Assumption  Dr. John | 11/26/07
the challenges you identify are trivial  dberlind | 11/22/07
Server Tax  t_mohajir | 11/26/07
Why do you defend?  Ole Man | 11/26/07
Licensing  t_mohajir | 11/26/07
What this specifically applies to  Ole Man | 11/26/07
Nobody is forcing you to buy it  t_mohajir | 11/26/07
Too late, done already bought it  Ole Man | 11/27/07
I think my main point is that...  dberlind | 11/26/07
Ok,  t_mohajir | 11/26/07
There are still some  Freebird54 | 11/26/07
So to repair defects...  Hrothgar - PCLinuxOS User | 11/29/07
Yup. It works..  done@... | 11/26/07
Apple has it right; Microsoft can and should follow  spstanley | 11/26/07
Why not SUS for WinXP Pro  JBeharry | 11/26/07
It's all about money.  Resuna | 11/26/07
RE: How Microsoft could save businesses time  shysick@... | 11/26/07
Testing Patches  MichP | 11/26/07
You need to update more frequently than twice per year  cjc5447 | 11/26/07
Actually..  done@... | 11/26/07
Call me goofy  Ole Man | 11/26/07
Financial responsibility...  bjbrock | 11/26/07
Here, Here  Sheeva | 11/26/07
No Way!!!  nottheusual1 | 11/26/07
RE: A Fix to MS Update  rxtxau | 11/26/07
Hey, no fair!  Ole Man | 11/26/07
RE: How Microsoft could save businesses time & money when it comes to patching Windows  shohom67 | 11/26/07
M$ BackFront Motivation  pobstar1@... | 11/26/07
David,  Update victim | 11/26/07
Autopatcher was one solution  jaybyrd | 11/26/07
RE: How Microsoft could save businesses time  rjshanor@... | 11/26/07
Of course they did!  Ole Man | 11/27/07
RE: How Microsoft could save businesses time  nv_tech700 | 11/26/07
For serious mem-hog issues, consider Prefetch  seanferd | 11/26/07
RE: How Microsoft could save businesses time  waynebrt@... | 11/27/07
try this  Hrothgar - PCLinuxOS User | 11/29/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Top Rated

    advertisement

    Archives

    Favorite Links

    ZDNet Blogs

    White Papers, Webcasts, and Downloads

    SmartPlanet

    • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
    • More from IBM
    • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
    • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
    Click Here