Windows 10 Feature Updates Remotely

%3CLINGO-SUB%20id%3D%22lingo-sub-1329031%22%20slang%3D%22en-US%22%3EWindows%2010%20Feature%20Updates%20Remotely%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1329031%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20are%20currently%20using%20SCCM%20using%20Windows%2010%20upgrade%20task%20sequences%20to%20mange%20our%20Microsoft%20Windows%2010%20feature%20updates.%20With%20300%20of%20staff%20going%20remote%20and%20SCCM%20upgrade%20task%20sequences%20not%20being%20an%20option.%20What%20free%20ways%20does%20Microsoft%20recommend%20for%20managing%20these%20updates%3F%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E-Zachary%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1329081%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20Feature%20Updates%20Remotely%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1329081%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F632799%22%20target%3D%22_blank%22%3E%40zaclaramay%3C%2FA%3E%26nbsp%3B%20Can%20you%20explain%20why%20you'd%20say%20%22%3CSPAN%3ESCCM%20upgrade%20task%20sequences%20not%20being%20an%20option.%22%3CBR%20%2F%3E%3CBR%20%2F%3EIs%20it%20because%20they%20don't%20have%20VPN%20to%20connect%20back%20to%20the%20ConfigMgr%20MP%20%26amp%3B%20DPs%3F%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1329090%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20Feature%20Updates%20Remotely%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1329090%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F632799%22%20target%3D%22_blank%22%3E%40zaclaramay%3C%2FA%3E%20there%20are%20a%20few%20different%20ways%20that%20you%20can%20manage%20updates%20for%20your%20remote%20workers.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22font-size%3A%2016px%3B%22%3E1.%20You%20can%20deploy%20feature%20updates%20as%20a%20software%20update%20from%20Configuration%20Manager%20and%20allow%20clients%20to%20acquire%20the%20content%20for%20those%20directly%20from%20Windows%20Updates%20rather%20than%20from%20on%20premise%20DPs%20while%20still%20maintaining%20management%20of%20the%20updates%20from%20Configuration%20Manager%20so%20long%20as%20you%20configure%20correctly%20(see%20these%20blogs%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fconfiguration-manager-blog%2Fmanaging-remote-machines-with-cloud-management-gateway-in%2Fba-p%2F1233895%22%20target%3D%22_self%22%3E1%3C%2FA%3E%2C%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fconfiguration-manager-blog%2Fmanaging-patch-tuesday-with-configuration-manager-in-a-remote%2Fba-p%2F1269444%22%20target%3D%22_self%22%3E2%3C%2FA%3E).%3C%2FP%3E%0A%3CP%20style%3D%22font-size%3A%2016px%3B%22%3E2.%20To%20further%20reduce%20VPN%20traffic%2C%20you%20can%20utilize%20Windows%20Update%20for%20Business%20which%20is%20free%20whether%20through%20Group%20Policy%20or%20through%20moving%20your%20Windows%20update%20workload%20to%20co-management%20with%20Intune.%20Please%20see%20the%20docs%20on%20how%20to%20%3CU%3E%3CA%20title%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fdeployment%2Fupdate%2Fwaas-manage-updates-wufb%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fdeployment%2Fupdate%2Fwaas-manage-updates-wufb%22%20target%3D%22_blank%22%20rel%3D%22noreferrer%20noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%20data-cke-saved-href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fdeployment%2Fupdate%2Fwaas-manage-updates-wufb%22%3Eset%20this%20up%20here%3C%2FA%3E%3C%2FU%3E.%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22font-size%3A%2016px%3B%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22font-size%3A%2016px%3B%22%3EPlease%20let%20me%20know%20if%20you%20want%20any%20more%20information%20on%20either%20of%20these%20approaches.%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1329109%22%20slang%3D%22en-US%22%3ERE%3A%20Windows%2010%20Feature%20Updates%20Remotely%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1329109%22%20slang%3D%22en-US%22%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F350114%22%20target%3D%22_blank%22%3E%40gwblok%3C%2FA%3E%20Lack%20of%20VPN%20is%20likely%20the%20case.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1329100%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20Feature%20Updates%20Remotely%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1329100%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F632799%22%20target%3D%22_blank%22%3E%40zaclaramay%3C%2FA%3E%26nbsp%3BWe%20use%20the%20upgrade%20task%20sequence%20remotely%20on%20computers%20connected%20to%20the%20VPN%20and%20to%20the%20CMG.%26nbsp%3B%20it%20is%20only%20OS%20deployments%20that%20cannot%20go%20over%20the%20CMG.%26nbsp%3B%20For%20Upgrades%2C%20you%20use%20to%20have%20to%20select%20to%20pre-download%20all%20the%20content%20first%2C%20but%20i%20think%20in%201806%2C%20that%20requirement%20was%20removed.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

We are currently using SCCM using Windows 10 upgrade task sequences to mange our Microsoft Windows 10 feature updates. With 300 of staff going remote and SCCM upgrade task sequences not being an option. What free ways does Microsoft recommend for managing these updates? 

 

-Zachary

11 Replies
Highlighted

@zaclaramay  Can you explain why you'd say "SCCM upgrade task sequences not being an option."

Is it because they don't have VPN to connect back to the ConfigMgr MP & DPs?

Highlighted

@zaclaramay there are a few different ways that you can manage updates for your remote workers. 

 

1. You can deploy feature updates as a software update from Configuration Manager and allow clients to acquire the content for those directly from Windows Updates rather than from on premise DPs while still maintaining management of the updates from Configuration Manager so long as you configure correctly (see these blogs 1, 2).

2. To further reduce VPN traffic, you can utilize Windows Update for Business which is free whether through Group Policy or through moving your Windows update workload to co-management with Intune. Please see the docs on how to set this up here

 

Please let me know if you want any more information on either of these approaches. :)

Highlighted

@zaclaramay We use the upgrade task sequence remotely on computers connected to the VPN and to the CMG.  it is only OS deployments that cannot go over the CMG.  For Upgrades, you use to have to select to pre-download all the content first, but i think in 1806, that requirement was removed.  

 

 

Highlighted
@gwblok Lack of VPN is likely the case.
Highlighted

@Aria Carley thank you for your reply. I will look into the managing the updates via Windows Updates rather than from on premise DP. We will just have to do some testing as we deploy several scripts in our Upgrade Task Sequence to resolve bugs in the Windows feature upgrade process. 

 

-Zachary

Highlighted

@zaclaramay 

For the scripts you run in your IPU process currently via a Task Sequence, you might be able to leverage the Custom Action Scripts that run at various times during the Windows 10 Setup Engine process:
https://garytown.com/windows-10-upgrade-custom-action-scripts

 

You might also be able to leverage scheduled tasks, and have the scripts look for specific conditions to know when to run.

Highlighted

@Harjit Dhaliwal 

Yeah, if you don't have VPN back to connect to your internal CM infrastructure, TS's become very difficult.

If you do have VPN, then it's completely possible, even with slow links thanks to LEDBAT++ and BranchCache Technology.  

Highlighted

@gwblok @Harjit Dhaliwal  we have a VPN but unfortunately its not set as always on and users tend to only be connected for a short window at a time. That is why we are looking for other options to manage windows 10 feature updates.

Highlighted

@zaclaramay 
I hear you on that, we too had a handful of users who rarely would connect to VPN.  At at point it became a management issue.  They were instructed to turn on their computer at 6PM, connect to VPN and leave it on overnight so it could upgrade over VPN.  Failure to comply was failing to complete job duties.

Highlighted

@gwblok @zaclaramay I had IBCM configured for my ConfigMgr but soon after the sudden WFH mandate, I discovered IBCM was not working properly. After getting it fixed, it required the clients to VPN at least once for a duration of time to pick up new policies and changes. Catch-22 is that some remote systems don't have the VPN client installed and they are unable to install due to lack of local admin creds for UAC elevation. Sigh! 

Highlighted

@zaclaramay We have been upgrading these users with the CMG.  We set the content location to download all content prior to start.

 

Snag_1a8b4ea.png

 

We also mark the task sequence allow to run on Internet.  The only issue we see is the status messages for the deployment status are not returned after the new OS is deployed.

 

here is a snip-it from the documentation:

Allow task sequence to run for client on the Internet: Specify whether the task sequence is allowed to run on an internet-based client. Operations that require a boot media, such as the installation of an OS, aren't supported with this setting. Use this option only for generic software installations or script-based task sequences that perform operations in the standard OS.

  • This setting is supported for deployments of a Windows 10 in-place upgrade task sequence to internet-based clients through the cloud management gateway. For more information, see Deploy Windows 10 in-place upgrade via CMG.

https://docs.microsoft.com/en-us/mem/configmgr/osd/deploy-use/deploy-a-task-sequence