Tech Community Live: Endpoint Manager edition
Jul 21 2022, 08:00 AM - 12:00 PM (PDT)

Latest CU for server 2008 are not seen as missing.

%3CLINGO-SUB%20id%3D%22lingo-sub-2752514%22%20slang%3D%22en-US%22%3ELatest%20CU%20for%20server%202008%20are%20not%20seen%20as%20missing.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2752514%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all%2C%20I%20am%20getting%20a%20strange%20issue%20where%20cumulative%20updates%20for%20server%202008%20SP2%20(both%20x86%20and%20x64)%20and%202008%20R2%20are%20not%20seen%20as%20missing%20by%20Endpoint%20Manager.%3C%2FP%3E%3CP%3EI%20have%20followed%20all%20the%20ESU%20requirements%2C%20tried%20to%20install%20every%20single%20updates%20to%20be%20compliant%20for%20the%20ESU%20and%20all%20updates%20where%20not%20applicable%20(already%20installed).%3C%2FP%3E%3CP%3EWhen%20I%20am%20installing%20updates%20by%20hand%2C%20they%20are%20installing%20without%20any%20complaint.%3C%2FP%3E%3CP%3EI%20do%20not%20know%20where%20to%20look%20at%20and%20the%20problem%20is%20that%20they%20are%20showing%20compliant%20in%20report%20because%20the%20updates%20are%20not%20seen%2C%20but%20when%20a%20scan%20from%20Nessus%20is%20done%2C%20the%20result%20is%20that%20all%20my%20server%202008%20and%202008%20R2%20are%20missing%20tones%20of%20patches.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAll%20ideas%20on%20where%20to%20start%20investigating%20are%20welcome.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMathieu%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2752514%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ESoftware%20update%20management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2769085%22%20slang%3D%22en-US%22%3ERe%3A%20Latest%20CU%20for%20server%202008%20are%20not%20seen%20as%20missing.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2769085%22%20slang%3D%22en-US%22%3EHi%2C%3CBR%20%2F%3EHave%20you%20install%20the%202107%20update%20for%20ConfigMgr%20%3F%3CBR%20%2F%3EOnly%20the%20latest%20version%20of%20ConfigMgr%20can%20deploy%20ESU.%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fconfiguration-manager-blog%2Fextended-security-updates-and-configuration-manager%2Fba-p%2F825618%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fconfiguration-manager-blog%2Fextended-security-updates-and-configuration-manager%2Fba-p%2F825618%3C%2FA%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hi all, I am getting a strange issue where cumulative updates for server 2008 SP2 (both x86 and x64) and 2008 R2 are not seen as missing by Endpoint Manager.

I have followed all the ESU requirements, tried to install every single updates to be compliant for the ESU and all updates where not applicable (already installed).

When I am installing updates by hand, they are installing without any complaint.

I do not know where to look at and the problem is that they are showing compliant in report because the updates are not seen, but when a scan from Nessus is done, the result is that all my server 2008 and 2008 R2 are missing tones of patches.

 

All ideas on where to start investigating are welcome. 

 

Thank you!

 

Mathieu

2 Replies
Hi,
Have you install the 2107 update for ConfigMgr ?
Only the latest version of ConfigMgr can deploy ESU.

https://techcommunity.microsoft.com/t5/configuration-manager-blog/extended-security-updates-and-conf...
Sorry for the delay, had to make the update to MECM. Now we are at 2107. As I understand, the latest version is required but does that mean that the server need to have the latest client installed?
If yes, here is the situation.
The latest version of MECM client does require .Net 4.8 installed which cannot be installed on server 2008 because it is no longer supported.
If I am correct, this is now the end of software update deployment on Windows Server 2008, which is great because I will have more leverage to tell others to work their butt to migrate to another OS.
Can anyone confirm that the latest client is required to deploy the latest SU under ESU?

Thank you!

Mathieu