Azure Update Management

Sdílet
Vložit
  • čas přidán 26. 07. 2024
  • A look at the two main Azure-native solutions for patching of Windows and Linux OS instances (in Azure and beyond).
    00:00 Introduction
    00:40 Patch responsibility for Azure services
    03:05 Azure Update Management
    04:42 Supported OS and patch sources
    09:22 Primary steps of patching
    10:05 Demo of Azure Update Management and configuration
    18:37 Pain points today
    19:14 Automatic VM-guest patching
    23:10 Going forward
    24:35 Summary
  • Věda a technologie

Komentáře • 54

  • @CameronFullerTX
    @CameronFullerTX Před 3 lety +3

    Great stuff John, especially the details on automatic management and the concepts behind update center

  • @sudeepmanandhar1971
    @sudeepmanandhar1971 Před 2 lety +1

    Truly appreciated what you do John. It so amazing information delivery on various Azure topics. Thank you for keeping it up. Really a fan of yours. Cheers

  • @gopeisho
    @gopeisho Před 3 lety +1

    A very good video, which gives me a good contrast to the quarterly maintenance we do with all our servers on-premises and in Azure.

  • @nathm8366
    @nathm8366 Před 3 lety +1

    Excellent thorough overview as always John - many thanks!

  • @konstantinpopov529
    @konstantinpopov529 Před 3 lety +1

    I always like your videos, your explanations are clear and right to the point

  • @bestplaylists1208
    @bestplaylists1208 Před rokem

    Thanks, John for making it so simple.

  • @jimyoung1971
    @jimyoung1971 Před 3 lety

    Great to see what is planned. Update Center sounds very useful and I can definitely see customers wanting to use this going forward.

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety

      Update Manager is here today and has the functionality. You just need log analytics and azure automation.

  • @iankelly49
    @iankelly49 Před 2 lety

    excellent video John. thank you.
    A couple of quirks I've found using update manager in the past.
    If you're doing one time patching. you have to specify more than about 7 minutes in the future, you can't do immediately.
    the details you get in the history tab, can be misleading. it may say "success" however, looking at the machine tab, it says "not compliant"
    The Machine tab is the source of truth.
    the "success" simply means, it ran successfully, not it installed updates successfully. FYI for anyone else who comes across this.

  • @jeremywallacemusic
    @jeremywallacemusic Před 3 lety

    Hey John this is great, thanks for putting this together, was very helpful!

  • @iamdedlok
    @iamdedlok Před 3 lety +1

    Fantastic as always John, Thank you!

  • @TiteufMela
    @TiteufMela Před rokem

    the way you explain... it's amazing.
    thank you

  • @vt1454
    @vt1454 Před 3 lety +4

    Thank you for making your videos freely available. The content is so much better than most of the paid courses. Appreciate your spirit of giving back..

  • @pacmanh22
    @pacmanh22 Před 2 lety

    Great video! Very detailed explanation and with examples

  • @yulaw3289
    @yulaw3289 Před měsícem

    enjoying this video for today learning, thanks a lot!

  • @prasadchowdary4701
    @prasadchowdary4701 Před 3 lety +1

    Thanks for the explanation 🔥

  • @aditya-garg
    @aditya-garg Před 2 lety

    Thanks for an amazing explanation!!

  • @patrickboucher892
    @patrickboucher892 Před 3 lety +1

    merci John. Great stuff.

  • @marcelohg
    @marcelohg Před 3 lety

    Very clear as allways. Thank you!

  • @craigwaterhouse8009
    @craigwaterhouse8009 Před 3 lety

    wrong place for this comment but wanted to thank you for the overview in cloud security podcast.. great breakdown and interview

  • @gabrielalicea4803
    @gabrielalicea4803 Před 2 lety

    Outstanding video

  • @zzzzz-jx2qi
    @zzzzz-jx2qi Před 2 lety

    Thanks again John!

  • @michaelpietrzak2067
    @michaelpietrzak2067 Před 3 lety +1

    I hope Update Center can be leveraged for on-prem services. I would love to see 3rd party patches baked into it as well

  • @amcadam26
    @amcadam26 Před 3 lety

    Excellent video as always John. Quick question on updates for ScaleSet VMs if I can? I just need to know how I can monitor missing updates for ScaleSets VMs (as they don't' seem to have the MMS agent by default), is there anyway to query missing updates from each VMScaleSet VM or is this not possible?

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety

      If its AKS then right it won't have the regular VMSS log agent because it is managed by AKS. It is AKS job to update the images and there are various AKS options to auto update when there are new AKS image versions. You don't patch the scaleset, you can see it, but its AKS>

  • @SombreSyr
    @SombreSyr Před 3 lety +1

    Thank you very much for this very interesting video. I have so much questions ;-)
    Is it possible to use Update Management with an on-prem disconnected environment (physical and virtual machines) to avoid each machine having Internet access ?
    If I understand well the doc, the Log Analytics Gateway can be used for both the Log Analytics Agent and the Hybrid Runbook Workers. So it should be possible, am I correct ?
    In the Update Management, when you configure an Update Deployment schedule, is there a way to configure the deployment to allow only one machine reboot at a time and also defining an order for the machines ?
    Like MECM allows you with Orchestration group with 'Allow a number of the machines to be updated at the same time' and 'Specify the maintenance sequence'.

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety +2

      Glad you like the video. it needs to get to log analytics and to azure automation. there are certain private link services you could look at to remove Internet then use on-premises stores like WSUS etc. You could create groups based on tag and tag machines based on maintenance window etc to avoid too many running etc. There are those pre scripts as well so you could do clever things.

    • @SombreSyr
      @SombreSyr Před 3 lety

      @@NTFAQGuy Thanks for your answer, I will try to do a poc at work.

  • @richardwaldron1684
    @richardwaldron1684 Před 2 lety

    Hi John, great video as always, thanks. Out of curiosity any idea why Windows client OS VMs aren't supported please?

    • @NTFAQGuy
      @NTFAQGuy  Před 2 lety +1

      Clients would normally be part of a VDI solution so would have its own method to update or use a client update technology like MEM.

  • @Gmankach
    @Gmankach Před 3 lety

    Hey John, I've implemented this quite recently and run into an interesting one... ARC joined machines count as Azure machines and can be added as workstations. You can however not add them as group using Tag as criteria. Guessing this is due to the actual resources not technically being part of the subscription. Weird one.

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety +2

      For Update Management purposes you need to follow the non-Azure machine path for Arc. There is no Arc & Log Analytics integration directly. docs.microsoft.com/en-us/azure/automation/update-management/enable-from-automation-account#enable-non-azure-vms

  • @shift2sw
    @shift2sw Před 3 lety +1

    if i have 2012 X1,2016X1, Redhat X1, CentOS x1, how many update deployment should I create? 1 windows + 1 Linux?

  • @deepakranjan3030
    @deepakranjan3030 Před 3 lety

    Hi John, How do I get patch report through update management

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety

      Docs cover compliance scans and log analytics data

  • @macho271
    @macho271 Před 2 lety

    Do you have carry license for those guns?

    • @NTFAQGuy
      @NTFAQGuy  Před 2 lety +2

      Concealed carry 😉💪🤙

  • @RoukeBroersma
    @RoukeBroersma Před 3 lety

    How does all of this relate to azure automanage?

    • @NTFAQGuy
      @NTFAQGuy  Před 3 lety

      automanage does far more than just patching and i'll cover it in detail once its further down the path.

    • @RoukeBroersma
      @RoukeBroersma Před 3 lety

      @@NTFAQGuy Awesome looking forward to it!

  • @rajatat5431
    @rajatat5431 Před 10 měsíci

    I'm gonna get fired the day this guy deletes his youtube account