Would like to run my update plan by those that have theirs in place

Hello again,
With the help I've gotten here I think I am finally past testing and need to consider the best way to deploy updates. I've done a lot of reading and understand this facet is different for every workplace so I will skip asking for "best practices"
and tell you what my current plan is. I would appreciate input on if this plan sounds OK or, if not, how I might better deploy.
I've read a number of threads on ADR deployment of updates but because we have a QA environment and many updates are things like service packs that can't be segregated by update type (Updates, Security Updates, etc) without missing other needed updates I'm
thinking the best way would be as follows:
-Select All Software Updates and add creteria to remove expires and superseded updates and add in Product info for our major products (Office 2010, WIndows 7, Wndows Server 2003 and 2008 R2).
-Create Deployment Packages for each of these major product groups and assign to correct Collections.
The above should handle the basic "All Patches" for systems and Office products not up to date from old images, should it not? I understand that if SCCM handles the images they can be updated and that will be something I look for in the
future.
As far as collections I intend to have a QA Workstations, QA Servers, and then the All Desktop and Server Clients setup. In this way I can assign, when timing is right after testing, the deployment packages to the proper collections.
My next question is when it's time for monthly updates. I'd like to have an ADR like I've read about but again with testing and some updates that would not be able to be issued as they came out (like Service Packs) and some non-security patches that need
applying, such that I cannot limit the ADR to having just the "MS" security bulletin patches as a limiting factor, I think I am going to have to run similar deployment packages, adding the criteria "released or revised within the last 1
month" in order to be able to thoroughly review the patches to ensure it isn't somethign in meed of special treatment like Service Packs.
Does this sound valid? Is it too complicated? Am I missing someting? How might I refine this approach? 
Thanks for your help!

It all depends on what you need, you meaning "business".
You actually can include update classification in ADR rules to get exactly what you need (including or excluding service packs).
Take a look at what Microsoft is saying about updates in general.
http://technet.microsoft.com/en-us/library/cc750077.aspx
Once you figure out what you need to deploy, you can configure your ADR rules or do deployments manually each month.
As for the deployment collections, I would stay away from doing all servers, all workstations etc, even after your QA has cleared it.
I know you could have limited downtime window, but if you can, try to apply these updates incrementally (say 5% of all workstations go on Monday, 15% on Tuesday and so on). This way you can avoid an issue, if one arises, that was not spotted during
QA process.
For servers, you can start with less critical systems etc.
How big is your environment (workstations and servers)?

Similar Messages

Maybe you are looking for

  • BDC issue

    Hi All, we have written a bdc for material upload for Tcode MMZ1. all works fine till the Accounting screen where we have to give the valuation type as D. (MBEW-BWTTY). and the Costing Screen we have to manually give enter to cross these screens and

  • IB Links

    Hi there, Does anyone know how to add a hyperlink into an IB window? Cheers, Ricky. http://web.mac.com/rickydamelio

  • How to embed images dynamically?

    HI all , I'm new to flex. Here is what I've already done, I use [Bindable]    [Embed(source="images/xxx.jpg")] private var img:Class; to embed several images in an application. But the source of these images can not be determined until the run time,

  • DIR creation in easyDMS through template

    Hi, Is there anyway to create DIR in easyDMS through template. Thanks. Anirudh,

  • Can you import a player package? I do not have the .odarc file...

    Hey there, My hard drive crashed with my backup odarc file that I did not move to my backup! I do have the latest player package file. This was created in 3.6.1. Is there a way to rebuild the library from a player package? Please say yes...