ConfigMgr Feature update issue

%3CLINGO-SUB%20id%3D%22lingo-sub-1781119%22%20slang%3D%22en-US%22%3EConfigMgr%20Feature%20update%20issue%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1781119%22%20slang%3D%22en-US%22%3E%3CP%3EWith%20this%20month%20new%20versions%20of%20FU%3A%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fportal.msrc.microsoft.com%2Fen-US%2Fsecurity-guidance%2Fadvisory%2FCVE-2020-16908%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fportal.msrc.microsoft.com%2Fen-US%2Fsecurity-guidance%2Fadvisory%2FCVE-2020-16908%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EIt's%20the%20second%20time%20that%20we%20need%20to%20download%20all%20of%20the%20feature%20updates%20that%20we%20currently%20use%20to%20fix%20issue%20that%20this%20does.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWould%20it%20be%20possible%26nbsp%3B%3CSPAN%3Eto%26nbsp%3B%20improve%20how%20this%20is%20done%20and%2For%20provide%20some%20guidance%20and%20more%20importantly%20improve%20the%20communication.%20Was%20only%20aware%20because%20I%20saw%20this%20post%20on%20Twitter%20with%20this%20post%3A%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Ftwitter.com%2Fjandreacola%2Fstatus%2F1316089842388938752%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Ftwitter.com%2Fjandreacola%2Fstatus%2F1316089842388938752%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EThis%20is%20a%20bad%20admin%20experience%20and%20it%20seems%20that%20it%20will%20happen%20more%20often.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3EI%20get%20why%20they%20need%20to%20be%20updated%2C%20but%20I%20think%20the%20how%20can%20be%20improved.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20insight%20on%20this%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1784515%22%20slang%3D%22en-US%22%3ERe%3A%20ConfigMgr%20Feature%20update%20issue%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1784515%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F99115%22%20target%3D%22_blank%22%3E%40Stephane%20Lalancette%3C%2FA%3E%26nbsp%3B%20-%20Hi%20Stephane%20-%20Thank%20you%20for%20your%20question.%26nbsp%3B%20You%20will%20see%20a%20formal%20answer%20to%20this%20posted%20on%20our%20blogs%20shortly.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThis%20year%20we%20have%20had%20two%20security%20updates%20(CVE's)%20which%20have%20required%20that%20we%20update%20Windows%20SetUp%20files.%26nbsp%3B%20As%20we%20update%20these%20files%2C%20the%20consequence%20is%20the%20need%20to%20have%20new%20media%2Ffeature%20update.%26nbsp%3B%20This%2C%20in%20turn%2C%20will%20end%20up%20timing-out%20any%20feature%20update%20that%20would%20be%20pre-cached%20to%20the%20endpoint%20-%20and%20the%20need%20to%20bring%20down%20the%20new%20media.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EPlease%20stay%20tuned%20in%20the%20next%20day%20or%20so%20for%20a%20blog%20on%20this.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1790915%22%20slang%3D%22en-US%22%3ERe%3A%20ConfigMgr%20Feature%20update%20issue%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1790915%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F458525%22%20target%3D%22_blank%22%3E%40Karen_Simpson%3C%2FA%3E%26nbsp%3BThanks%20for%20the%20update%20Karen.%26nbsp%3B%20Looking%20forward%20to%20the%20blog%20post%20and%20communication%20plans%20moving%20forward.%26nbsp%3B%20I%20think%20the%20biggest%20issue%20is%20the%20%22deleted%20deployments%22%20if%20they%20were%20active.%26nbsp%3B%20Also%20having%20to%20redistribute%20content%20in%20MECM%20(esd%20file)%20when%20only%20a%20relatively%20minor%20set%20of%20files%20(WindowsUpdateBox.exe)%20changed.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

With this month new versions of FU:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16908

It's the second time that we need to download all of the feature updates that we currently use to fix issue that this does. 

 

Would it be possible to  improve how this is done and/or provide some guidance and more importantly improve the communication. Was only aware because I saw this post on Twitter with this post:
https://twitter.com/jandreacola/status/1316089842388938752

This is a bad admin experience and it seems that it will happen more often.

I get why they need to be updated, but I think the how can be improved.

 

Any insight on this?

 

Thks

2 Replies

@Stephane Lalancette  - Hi Stephane - Thank you for your question.  You will see a formal answer to this posted on our blogs shortly.

 

This year we have had two security updates (CVE's) which have required that we update Windows SetUp files.  As we update these files, the consequence is the need to have new media/feature update.  This, in turn, will end up timing-out any feature update that would be pre-cached to the endpoint - and the need to bring down the new media.

 

Please stay tuned in the next day or so for a blog on this.

 

AND - yes - we understand the feedback and are looking at how we can improve this experience between our MEM, Fundamentals and Windows Servicing&Delivery teams.

@Karen_Simpson Thanks for the update Karen.  Looking forward to the blog post and communication plans moving forward.  I think the biggest issue is the "deleted deployments" if they were active.  Also having to redistribute content in MECM (esd file) when only a relatively minor set of files (WindowsUpdateBox.exe) changed.