Translate

Showing posts with label Windows 10. Show all posts
Showing posts with label Windows 10. Show all posts

Monday, January 27, 2020

What does this 0xC00000... errorcodes mean

Sometimes you get in Windows some strange error codes without any meaning behind.

Like 0xC0000005 or many other ones.


There is a simple Microsoft command line tool available to reveal the meaning of them. This tool was recently updated to the latest version. You find it here: https://www.microsoft.com/en-us/download/details.aspx?id=100432

Compared to the older version there are know approx. 8000 new return codes from more resources added. So its worth to download the latest version.

When you download it simply execute the executable followed
by the error code: e.g.  err 0xC0000005


The error code may be used on more than on place in the OS. So you need to figure out the source (or OS area) where the issue happend.

winerror.h, ntstatus.h and bugcodes.h are handled typically by the OS kernel and relate to core os functions like file access etc.



USAGE: err [opt] {value} [value] [value] ...
 where <value> must be of one of the following forms:
   1. decorated hex (0x54f)
   2. implicit hex  (54f)
   3. ambiguous     (1359)
   4. exact string  (=ERROR_INTERNAL_ERROR)
   5. substring     (:INTERNAL_ERROR)
...and <opt> may be one of:
   /:xml         - causes the output to be in XML-parseable form.
                   To understand the output, try it.  It's pretty obvious.
   /:listTables  - lists all the tables below in XML format.
                   Again, the format is pretty straightforward.
   /:outputtoCSV - lists all the tables below in CSV format.
   /:outputtoJS  - lists all the tables below for use in JS.
   /:outputtoCPP - lists all the tables below for a C++ header.
   /:hresultfromwin32 - prints HRESULT_FROM_WIN32 errors for a C++ header.

All values on the command line will be looked up in our internal
tables and presented to you.  If available, informational data
associated with the value(s) will also be shown (see below).
All tables are searched by default, but you can restrict the
output to those tables you deem appropriate by adding
"/<tablename>" to the beginning of the commandline.

Example:

> err /winerror.h /ntstatus.h 0
# winerror.h selected.
# ntstatus.h selected.
# for hex 0x0 / decimal 0 :
  STATUS_WAIT_0                                             ntstatus.h
  ERROR_SUCCESS                                             winerror.h
# The operation completed successfully.
  NO_ERROR                                                  winerror.h
  SEC_E_OK                                                  winerror.h
  S_OK                                                      winerror.h
# 5 matches found for "0"

This app has support derived from the following headers and privates:

  activprof.h             activscp.h             adoint.h               adserr.h
  asferr.h                audioclient.h          audioenginebaseapo.h   bitsmsg.h
  bthdef.h                bugcodes.h             cderr.h                cdosyserr.h
  cfgmgr32.h              cierror.h              corerror.h             corsym.h
  ctffunc.h               d3d.h                  d3d9.h                 d3d9helper.h
  d3dx10.h                d3dx10core.h           d3dx9.h                d3dx9xof.h
  daogetrw.h              dbdaoerr.h             dciddi.h               ddeml.h
  ddraw.h                 dhcpssdk.h             difxapi.h              dinput.h
  dinputd.h               dlnaerror.h            dmerror.h              drt.h
  dsound.h                dxfile.h               eaphosterror.h         ehstormsg.h
  esent.h                 fherrors.h             filterr.h              fltdefs.h
  hidpi.h                 iiscnfg.h              imapi2error.h          imapi2fserror.h
  imapierror.h            ime.h                  intshcut.h             ipexport.h
  iscsierr.h              iscsilog.h             jscript9diag.h         legacyErrorCodes.h
  lmerr.h                 lmerrlog.h             lmsvc.h                lpmapi.h
  lzexpand.h              mciavi.h               mdmregistration.h      mdmsg.h
  mediaerr.h              mferror.h              mmstream.h             mobsync.h
  mpeg2error.h            mprerror.h             mq.h                   mqoai.h
  msctf.h                 msdrmerror.h           msime.h                msiquery.h
  msopc.h                 mswmdm.h               msxml2.h               nb30.h
  ndattrib.h              netcfgx.h              netevent.h             netmon.h
  netsh.h                 nserror.h              ntdddisk.h             ntdsapi.h
  ntdsbmsg.h              ntiologc.h             ntstatus.h             odbcinst.h
  ole.h                   olectl.h               oledberr.h             oledlg.h
  p2p.h                   patchapi.h             patchwiz.h             pbdaerrors.h
  pdhmsg.h                photoacquire.h         portabledevice.h       qossp.h
  raserror.h              rdcentraldb.h          reconcil.h             routprot.h
  rtcerr.h                sberrors.h             scesvc.h               schannel.h
  setupapi.h              shellapi.h             sherrors.h             shimgdata.h
  shobjidl_core.h         slerror.h              snmp.h                 spatialaudioclient.h
  spatialaudiometadata.h  sperror.h              stierr.h               synchronizationerrors.h
  tapi.h                  tapi3err.h             tcerror.h              textserv.h
  textstor.h              thumbcache.h           tpcerror.h             txdtc.h
  upnp.h                  upnphost.h             urlmon.h               usb.h
  usp10.h                 vdserr.h               vfw.h                  vfwmsgs.h
  vsserror.h              wbemcli.h              wcmerrors.h            wcntypes.h
  wdfstatus.h             wdscpmsg.h             wdsmcerr.h             wdstptmgmtmsg.h
  werapi.h                wiadef.h               winbio_err.h           wincrypt.h
  windowsplayready.h      windowssearcherrors.h  winerror.h             winfax.h
  winhttp.h               wininet.h              winioctl.h             winldap.h
  winsnmp.h               winsock2.h             winspool.h             wpc.h
  wsbapperror.h           wsmerror.h             wuerror.h              xapo.h
  xaudio2.h               xmllite.h              xpsdigitalsignature.h  xpsobjectmodel.h
  xpsobjectmodel_1.h
There are currently 25259 return codes registered from 173 sources.


Wednesday, January 15, 2020

Tune up your old SurfacePro4

I have a Surface Pro4 for a while. And it got every half year its nice fine upgrade. 

Since beginning the Surface Pro4 supported 2 external full HD monitors via the dock but then the internal screen was blacking out. Checked the specs and it was as it was by design. The gaphic adapter did not support 3 monitors (while external are full HD 1080 and the internal was in native 2k mode)

In October I realized that after a certain update (could not found which one) the WLAN becomes also very clunky (bad WLAN performance). Sometimes packet loss or ping roundtrip times in the 900ms or more milliseconds. Did here also some research and all hints just improved from time to time so no real solution.

So what is the best advice when in trouble?


  1. Reboot
  2. Reinstall
  3. Rebuy newer hardware


Then I thought ok its now worth to reinstall my machine completely fresh from ground. (2. Reinstall option). Due to Onedrive not really a big data loss. Just the hazzle of reinstalling latest version of my software suites.



And it turned out it was a refreshing living cell injection for my PC!

After processing all the updates the machine is supporting things out of the box I had never before automatically.


  1. It now supports 2 external screens while still having native resolution shown on the internal screen (= 1 screen more!)
  2. The bad WLAN performance was gone
  3. It supports now out of the box space reservation for upgrades (fresh installed systems since 1903 (afaik) will create a extra free space reserved for future upgrades. So no showblocker for upgrades anymore with HDDs full of data. This only works with fresh installed machines beginning with 1903. So migrations from 1507 over and over again do not support this)
  4. My important user profile documents are automatically migrated to Onedrive out of the box! So everything you store them will integrate automatically to Onedrive. Just be aware of your picture archive. It automatically syncs down and blows your HDD. So you should keep it "cloud only" with the Files On Demand feature!!!)


All over my advice is from time to time it is still worth to take a fresh restart! (Ensuring that all your precious data is stored in OneDrive)

Tuesday, December 3, 2019

Windows 10 - 1909 whats new

Windows 10 - Version 1909 (aka 19H2)
Build 10.0.18363.476


Windows 19H2 is considered to be more a quality update than a major feature upgrade. But this is part of Microsofts product politics right now. So each H1 version will come now with new features for home and business users. The support is currently limited to 18 months for this versions. 

The H2 releases where 1909 is the one we are talking about is supported for 30 months so far. This is the one where businesses looking for to have the upgrades out in the field as long as possible.

The following new features are being introduced as part of this update.

  • This update will be published to WSUS so that customers can deploy and manage Insider Preview builds alongside their standard ConfigMan/WSUS approach. See this blog post for details.
  • We are offering pre-release support for 19H2 offered to Windows Insider Program for Business (WIP4Biz) customers who face blocking issues that prevent them from feature evaluation or device use. See this article for details.
  • Windows containers require matched host and container version. This restricts customers and limits Windows containers from supporting mixed-version container pod scenarios This update includes 5 fixes to address this and allow the host to run down-level containers on up-level for process (Argon) isolation.
  • A fix to allow OEMs to reduce the inking latency based on the hardware capabilities of their devices rather than being stuck with latency selected on typical hardware configuration by the OS.
  • Key-rolling or Key-rotation feature enables secure rolling of Recovery passwords on MDM managed AAD devices upon on demand request from Microsoft Intune/MDM tools or upon every time recovery password is used to unlock the BitLocker protected drive. This feature will help prevent accidental recovery password disclosure as part of manual BitLocker drive unlock by users.
  • A change to enable third-party digital assistants to voice activate above the Lock screen.
  • You can now quickly create an event straight from the Calendar flyout on the Taskbar. Just select the date and time at the lower right corner of the Taskbar to open the Calendar flyout and pick your desired date and start typing in the text box–you’ll now see inline options to set a time and location.
  • The navigation pane on the Start menu now expands when you hover over it with your mouse to better inform where clicking goes.
  • We have added friendly images to show what is meant by “banner” and “Action Center” when adjusting the notifications on apps in order to make these settings more approachable and understandable.
  • Notifications settings under Settings > System > Notifications will now default to sorting notification senders by most recently shown notification, rather than sender name. This makes it easier to find and configure frequent and recent senders. We have also added a setting to turn off playing sound when notifications appear.
  • We now show the options to configure and turn off notifications from an app/website right on the notification, both as a banner and in Action Center.
  • We have added a “Manage notifications” button to the top of Action Center that launches the main “Notifications & actions” Settings page.
  • We have added additional debugging capabilities for newer Intel processors. This is only relevant for hardware manufacturers.
  • We have made general battery life and power efficiency improvements for PCs with certain processors.
  • A CPU may have multiple “favored” cores (logical processors of the highest available scheduling class). To provide better performance and reliability, we have implemented a rotation policy that distributes work more fairly among these favored cores.
  • We have enabled Windows Defender Credential Guard for ARM64 devices for additional protection against credential theft for enterprises deploying ARM64 devices in their organizations.
  • We have enabled the ability for enterprises to supplement the Windows 10 in S Mode policy to allow traditional Win32 (desktop) apps from Microsoft Intune.
  • We’re updating the search box in File Explorer to now be powered by Windows Search. This change will help integrate your OneDrive content online with the traditional indexed results. More details here.
  • We have added the ability for Narrator and other assistive technologies to read and learn where the FN key is located on keyboards and what state it is in (locked versus unlocked).



And here you will find the bugfixing and stabilization done sofar for this release:
  • Some older devices may experience loss of Wi-Fi connectivity due to an outdated Qualcomm driver. An updated Wi-Fi driver should be available from your device manufacturer (OEM).
    To safeguard your upgrade experience, we have applied a hold on devices with affected Qualcomm driver from being offered Windows 10, version 1903 or Windows 10, version 1909, until the updated driver is installed.
  • Microsoft has identified compatibility issues with some driver versions for Bluetooth radios made by Realtek. To safeguard your update experience, we have applied a compatibility hold on devices with affected driver versions for Realtek Bluetooth radios from being offered Windows 10, version 1903 or Windows Server, version 1903 until the driver has been updated.Resolution: This issue was resolved with an updated driver for the affected Realtek Bluetooth radio and the safeguard hold has been removed. Please note, it can take up to 48 hours before you can update to offered Windows 10, version 1909 or Windows 10, version 1903.
And here are some known issues:
  • Issues with some older versions of Avast and AVG anti-virus products:
    Microsoft and Avast has identified compatibility issues with some older versions of Avast Antivirus and AVG Antivirus that might still be installed by a small number of users. Any application from Avast or AVG that contains Antivirus version 19.5.4444.567 or earlier is affected.

    To safeguard your upgrade experience, we have applied a hold on devices with affected Avast and AVG Antivirus from being offered or installing Windows 10, version 1903 or Windows 10, version 1909, until the application is updated.

    Workaround
    Before updating to Windows 10, version 1903 or Windows 10, version 1909, you will need to download and install an updated version of your Avast or AVG application.
  • Unable to create local users in Chinese, Japanese and Korean during device setup
    When setting up a new Windows device using the Out of Box Experience (OOBE), you might be unable to create a local user when using Input Method Editor (IME). This issue might affect you if you are using the IME for Chinese, Japanese, or Korean languages.

    Note This issue does not affect using a Microsoft Account during OOBE.

    Workaround
    : To mitigate this issue, set the keyboard language to English during user creation or use a Microsoft Account to complete OOBE. You can set the keyboard language back to your preferred language after user creation. Once the OOBE is done and you are at the desktop, you can rename the current user using these instructions. If you prefer to create a new local user, see KB4026923.

Friday, April 6, 2018

Windows 10 Pro Licensing Logic (OEM to VL)

From time to time the Windows 10 Pro vs. Enterprise discussion comes back. Just to clarify from a security point of view and also in relation's of limitations the Enterprise edition is still the best and recommended way to go. It offers a tremendous value in terms of security and manageability.

But we still have customers were the financial pain is so huge that we need to cut very important features as well just to fulfill their serious budget limits. 




Caution!  Just one word as advice. DO NOT TRY TO MAP WINDOWS7 TO WINDOWS 10 !!!

Its the same as you want to use a Ferrari in the same way as you did with your VW Golf before. Please rethink your potential modern workplace even only with PRO instead of Enterprise. It does not make sense to do the stuff the old way as you fear the new way or you are not willing to ask what could be the new way for you to simplify things.

If you had to go with Windows 10 Pro (knowing all current and future potential limitations) then you can go with the PRO license coming on your OEM device. There is still the rule that having 1 Windows 10 Pro VL license bought through commercial licensing brings you the right to use the VLSC and download your Windows 10 Pro Image ISO you can use for further deployment.

Please checkout here:
https://download.microsoft.com/download/3/d/4/3d42bdc2-6725-4b29-b75a-a5b04179958b/reimaging.pdf

You find here the sentence:

Using Commercial Licensing media to reimage.
Commercial Licensing Windows Desktop operating system media may be used to reimage devices if all devices being reimaged are licensed for the edition and version of Windows being reimaged onto them. (Note: Each device being reimaged does not need to be licensed under Commercial Licensing if they are properly licensed for the edition and version being reimaged onto them.)

(Which is given when you have an OEM Windows 10 Pro you can reimage with Windows 10 Pro but only in the given edition and version. So Windows 10 version and Pro edition.) I asked a few years ago MS license Q and that's what they explained to me as well.

Another Reference
https://blogs.technet.microsoft.com/uktechnet/2015/07/13/windows-10-licensing-logic/

And please be aware. You can not stop the update train! Which is from security point of view the only valid way. From a management point of view rethink things. Windows 10 is not a project. Its a continuous process!



Saturday, March 19, 2016

Repair Windows 10 with DISM command in command prompt


Windows 10 while it is running you can check and fix components and the component store. (this goes far beyond of the capabilities of SFC.exe)

Instructions:
a. Start cmd.exe from start menu with right click as Admin (very important!)
b. Or Win + X Command Prompt (Admin)



You see now in the command prompt: C:\Windows\system32\
1. Check if errors are in the registry:

Dism /Online /Cleanup-Image /CheckHealth

2. Check if errors are in Windows Components Store

Dism /Online /Cleanup-Image /ScanHealth

3. Repair the registry and component store (you need online connection to Windows Update!)

Dism /Online /Cleanup-Image /RestoreHealth


If the repair is done you can double check with no2. again (/ScanHealth option)







If there are still errors you can use the components from the ISO media or the installation DVD:

DISM /Online /Cleanup-Image /RestoreHealth /source:wim:C:\install.wim:1 /limitaccess

ATTENTION you may need to adjust /source:wim:C:\install.wim:1
Probably the C: is  not the drive to the install.wim. It might be e.g. D:\sources\install.wim

Also make sure that you use the same ISO as you have as OS installed.
Simply open winver.exe to check the version of the OS.

If you need the media as you have no media. You may download it here. This also allows you to upgrade to a newer version if you are running an older one.


 

Biometric Windows Hello also with Surface PRO3 (workaround)

Users of Surface Pro 3 may be very disappointed as they have no chance to use their face for logon simplification. As there is no Windows Hello camera integrated.


But recently MS released the new TypeCover for Surface Pro4 with Fingerprint Reader which gives you a great Chance still to use Windows Hello.






Just to clarify in "Windows Hello ready" devices mostly the Intel Realsense camera is used for 3D face recognition. A normal camera does not work for this feature as you need the 3rd dimension information just cameras like these create.

This is also the reason why "just a picture" does not work.
Also cut off the head does not work either. Just to make clear we did not tried that! :-)


But the Realsense technology take advantage of infrared light processing as well.


When you have a Surface Pro4 then Microsoft uses it's own camera sensor which is comparable with the Intel Realsense camera. There you Can use for Windows Hello logon your face.

But Windows Hello is not limited to this.

You can use also other biometric informations for Windows Hello as well. Here Comes the new keyboard into Play. The Keyboard is compatible for Surface PRO 3 and PRO4.

When you connect this great new keyboard with Fingerprint Reader with your Surface Pro3 (at least the typing experience alone is worth the money compared to the old one!) then you have all you need to run also Windows Hello.
And now you just need your finger to logon. :-)





Just to clarify. I was not sponsored from MS to write this blog. Nor I get an typecover upfront for writing this article. :-)





Wednesday, January 13, 2016

FIX: Startmenu and Cortana not working

Last weekend one of my friends had trouble with Startmenu and Cortana. Both were not working. He tried all the different fixes he found in the internet. None of them where working. There was one of them with a powershell command to re-register the Startmenu but even this was not working after a reboot either.

But we found the ultimate solution which is also very easy to implement.

Its important to know the root cause for this issue. For some reason the user profile got corrupted during a wrong situation (e.g. through powerloss in the wrong moment, AV scanner issues, etc.)


(If it reappears after this fix here the chance is high you have issues with your AV scanner. Remove it and use another one. If you did not use any other AF than Windows defender will kick in after 3 days to make sure that your machine is at least protected with him. And Windows Defender is now better than its reputation).

The good message its easy to recover without data loss. (This here worked at least in V1511 (Build 10.10586))


#### UPDATE 1 from March 19th 2016 ####

There are a couple other considerations arround I found:

1. Also 3rd Party add ons may corrupt Start Menu (check taskbar)
    Some found e.g. that dropbox application ("which officially was stated as Win10 compatible") caused this and they had to remove it!

2. Also other antivirus solutions may cause this (as referred above)

3. Let run in admin cmd: sfc.exe /SCANNOW to check for OS integrity

4. Also just try a regular reboot through: shutdown.exe /f /r /t:0
    (This was once the key on my wifes Dell Venue pro 8. My 2nd Account solution here did not worked with her. The 2nd Account also did not Show up the start menu right away. Simply the reboot fixed it. It seems there was some os config pending in the Background waiting for a regular reboot.)

#### UPDATE 1 END ####


1. Do a backup of your profile documents you want to keep.
(e.g. C:\Users\USERNAME\documents, videos, music, favorites, etc.) 
VERY IMPORTANT as we will delete your whole profile !!!
WIN key + E opens the explorer

If your current user is setup with the Microsoft account and you let the express settings then all your profile setup is synced to OneDrive. This helps a lot! Your settings get automatically reapplied when logging in first time when your account get recreated. You still need to backup your personal files!

2. Create a second user which has admin rights (now it becomes a little bit tricky, how to access the settings when Start, Cortana and Action center wont work)

  A. Right click taskbar on an empty space --> Click on "TASKMANAGER" to open it.
  B. In Taskmanager --> Click File --> Click "RUN NEW TASK"
  C. In Run new task type in: lusrmgr.msc and press ENTER
  D. Click on "Users"
  E. Right click in the middle pane to add a "New User ..."





4. Then add to this new local user the administrators group.

  A. Double click on the new created user
  B. Click on "Member of" tab.
  C. Click on "Add"
  D. Type in "Administrators"
  E. Click on "Check names"





Now you should logout and login with the new user.

5. Now we need to delete the old user.

  A: Open elevated Command Prompt.
  B: Type the following Command and hit enter key:
  net user username /delete
  wait until the command finished successfully
(replace “username” with the user account name which you would like to delete)
6. Reboot the system and login again with the new local user
7. Recreate the original user

  A. Right click taskbar --> Click on "TASKMANAGER" to open it.
      (Alternate shortcut CTRL + SHIFT + ESC)
  B. In Taskmanager --> Click File --> Click "RUN NEW TASK"
  C. In Run new task type in: ms-settings:otherusers and press ENTER
  D. Click in "Other users" on "Add someone else to this PC"
       Here add your original Microsoft account you used before.
       If you used "express settings" initially on the system setup
       then your settings would sync back from OneDrive :-)





8. Reboot and enjoy your recreated profile.
9. OPTIONALLY: Copy back your backup files from step 1 if you made a backup of your documents, videos etc.

And actually that's it!

Enjoy your recreated profile.

Monday, January 4, 2016

Move on to EDGE: How to import IE favorites in Edge

As time goes by Edge gets better and better. Soon the additional addons arrive.
And from speed perspective I really love Edge. He is much faster and smoother then IE.

I know not yet everything works. But from build to build I see more improvements.

That drove me to the descision to move on with EDGE first and only switch back to IE when needed.

You can simply control the default URL handler behaviour with the IE Enterprise Mode that let even control which URL is opened with which browser. But this will be another blog post.

This blog is really about the way to import IE favorites into Edge.
And now it is really simple to do that.

See here the simple steps:

Click on HUB and then on FAVORITES SETTINGS
 
 
Then Click on IMPORT

 
finally you see all the imported favorites.
 
Sometimes it is necessary to close and reopen the browser to see the full list of imported favorites.


Checkout soon for the next Edge related blog

Thursday, December 31, 2015

Windows enterprise ready deployment on SURFACE Pro4

The great Surface Pro4 device is out and due to its outstanding capabilities many companies consider to use it as a enterprise device. But therefore you want to deploy it also in an enterprise manner.


Lets see how this works.

Rule 1 for Surface is as with any other device.
USE THE LATEST FIRMWARE AND DRIVERS!  You get them here.
Checkout recent history of firmware and drivers here.

Rule 2 you need something that allows you to boot from PXE over network

Option A: Use the Surface Pro3 dockingstation or Surface Dock. That allows you to boot via network cable from PXE with Gbit speed. Benefit of the Surface Dock is: You can update the firmware on the dock itself. Also it allows the user to choose their own viewangle (regarding the kickstand) on the Surface Pro 3/4 device.


Option B: Use the Surface Ethernet Adapter. This here supports PXE. This here is my favour. As in reality sometimes a user want to user a wired connection as well. So the user has at least one option to use the dock or the USB adapter to get a wired connection.


The Ethernet adapters in both solutions use the same chipset and provide identical functionality. Both adapters support gigabit connectivity for optimal performance during deployment, and both support the ability to boot from the network (PXE boot) without additional hardware.

Option C: You may use a 3rd party USB ethernet adapter. I dont recommend this as you have to add the adapter specific drivers first to an USB stick with an PE image you boot from stick. Then the PE integrated setup (e.g. MDT) can access the network. I would avoid this. 

Then there is another pitfall you have to keep in mind.
But this is not related to Surface in general. It is more related to the fact that slim tablets do not have wired PXE builtin.



Most PXE related deployment solutions check the MAC address to identify a machine. Then you have two options.

Option 1. Simply disable identification and allow deployment to all machines (known and unknown. Therefore I would protect your deployment e.g. through MDT with a password. Also make sure that the naming convention does not use MAC).

Option 2. Make use of MDT in general as MDT doet not use the MAC address to identify an individual computer. But you have to make sure that WDS where MDT is relying on allows unknown and known devices as well (Option in WDS server properties).

When you plan to use SCCM instead then there is even a higher dependency on this.
Please check out this BLOG.

The last question is how to tell the Surface to boot into the PXE boot.

To boot a Surface device from an alternative boot device, follow these steps:

  1. Ensure the Surface device is powered off.
  2. Press and hold the Volume Down button.
  3. Press and release the Power button.
  4. After the system begins to boot from the USB stick or Ethernet adapter, release the Volume Down button.

Note:  In addition to an Ethernet adapter, a keyboard must also be connected to the Surface device to enter the pre-installation environment and navigate the deployment wizard.
 
There would could be even more to share.
To get the full MS story you can also checkout this BLOG here.

Monday, November 30, 2015

Windows Update for Business - how it works?

 
With Threshold 2 (v1511) Microsoft introduces Windows Update for Business (often also shortened as WUB). This is a new option to keep your infrastructure up-to-date. Just to avoid confusion. This is a new option. All old methods like WSUS/SUS or Windows Update still working!
 

This brings two benefits.

1. You get more granular control
2. You can use Windows Update without the need to use WSUS server on premise.

But keep in mind you need either: Windows Pro or Windows Enterprise. As Homeuser you do not have this option. There is an unsupported registry hack available as GPOs are using registry values.

When you use the Windows Insider program these settings are fully ignored (by purpose!)
 

How does it work.

 
 
Its very simple. Use this GPO
 
 
You find this GPO (since v1511 checkout the versioning blog entry here):
 
Computer Configuration\Administrative Templates\Windows Components\Windows Updates

You can control the upgrades (newer branches) and updates (e.g. Patch Tuesday Updates) differently. Upgrades you can defer by months. Updates you can defer by weeks.

Updates for Windows Defender are out of scope. Signature updates were installed as soon as they are available.

When you link this GPO with different settings on different OUs (Organizational Units) you can control how long a specific update/upgrade is defered.

If you find that a specific update/upgrade will cause an issue and you need additional time to fix it you can pause this until the next update/upgrade cycle. The checkbox is removed automatically after the next upgrade/update version appears.

This illustrates the different waves you can implement. You can also define more rings if you want. Typically you would also decide to test first with Insider branch or with current branch. Take advantage of your key users (e.g. SAP key user) to do the business process testing. The process owners are typically the guys they can tell you if the business process still works (e.g. SAP order, order printing etc.)


 
 
 
Here you find additional informations:
https://technet.microsoft.com/en-us/library/mt598226

My video about Windows Update and Rollout (sorry it was my session at German Technical Summit. Therfore the slides and video is in German only!) If you hear bad noise just re-adjust and lower the audio volume level. Somehow the recording get mixed badly.
 
Have fun and enjoy WUB ;-)