j***@gmail.com
2009-02-18 14:15:08 UTC
Gentlemen, I thank you for reading.
I have two pairs of Domain Controllers running Windows Server 2003 in
a parent-child forest configuration. My DCs have not had Windows
Updates in some time, and I need to write a procedure for doing so.
Currently, the DCs are virtual machines, and the intent is to keep
them in a snapshotted state until the updates are complete and the DCs
are confirmed functional.
Are there any best practices regarding a procedure for actually
performing the updates? I have some persons in one camp telling me
that I need to shut the other three DCs down while one of them is
updating. This seems counterintuitive, as a workstation on the network
could request an update or change from the DC that's being updated,
and then the structure becomes inconsistent.
Most of my 'best practices' research on the net has lead me to
articles about implementing WSUS or GPOs restricting Windows Updates
on workstations.
There is another option, of course, which is to not run the updates at
all.
Any suggestions, comments, or thoughts are greatly appreciated.
I have two pairs of Domain Controllers running Windows Server 2003 in
a parent-child forest configuration. My DCs have not had Windows
Updates in some time, and I need to write a procedure for doing so.
Currently, the DCs are virtual machines, and the intent is to keep
them in a snapshotted state until the updates are complete and the DCs
are confirmed functional.
Are there any best practices regarding a procedure for actually
performing the updates? I have some persons in one camp telling me
that I need to shut the other three DCs down while one of them is
updating. This seems counterintuitive, as a workstation on the network
could request an update or change from the DC that's being updated,
and then the structure becomes inconsistent.
Most of my 'best practices' research on the net has lead me to
articles about implementing WSUS or GPOs restricting Windows Updates
on workstations.
There is another option, of course, which is to not run the updates at
all.
Any suggestions, comments, or thoughts are greatly appreciated.