none
SCCM SUP use for patching image build in MDT 2013 RRS feed

  • Question

  • Hi , 

    I have SCCM 2012 R2 SUP (WSUS) and then i have MDT 2013 for build and capture Images. I am trying to use windows update method in MDT 2013 but my reference  VM failes to get any updates. How do i get the patches that are approved inside SCCM (since now sccm is controlling WSUS now through SUP)? Any pointers will be appreciated

    Regards,

    Monday, January 27, 2014 7:22 PM

All replies

  • Would love an answer to this...
    Friday, September 19, 2014 3:50 PM
  • In my experience, you cannot use a ConfigMgr 2012 R2 SUP to patch builds in MDT. Specifically, if you attempt to use the WSUSServer property in CS.ini, it will not work with the SUP. In my environment, I have standalone WSUS server specifically for servicing MDT.

    Remember, the ConfigMgr SUP is only using WSUS metadata. It is not a "true" WSUS server; updates are downloaded to packages within ConfigMgr. MDT would have no insight to those packages.


    -Nick O.

    • Proposed as answer by DonPick Saturday, September 20, 2014 4:14 AM
    Friday, September 19, 2014 4:39 PM
  • I've never actually done this myself, but CHris Nackers did some research on this a while back:

    http://myitforum.com/cs2/blogs/cnackers/archive/2011/04/28/using-ztiwindowsupdate-wsf-to-install-updates-in-a-system-center-configuration-manager-task-sequence.aspx

    Please let us know if it works out.


    Keith Garner - Principal Consultant [owner] - http://DeploymentLive.com

    Saturday, September 20, 2014 1:05 AM
    Moderator
  • I've never actually done this myself, but CHris Nackers did some research on this a while back:

    http://myitforum.com/cs2/blogs/cnackers/archive/2011/04/28/using-ztiwindowsupdate-wsf-to-install-updates-in-a-system-center-configuration-manager-task-sequence.aspx

    Hmm, actually, Chris is showing how to use WSUS (via ztiWindowsUpdate.wsf) *instead of ConfigMgr SUM* from within a TS - his example shows no ConfigMgr SUP in use...

    Don
    (Please take a moment to "Vote as Helpful" and/or "Mark as Answer", where applicable.
    This helps the community, keeps the forums tidy, and recognises useful contributions. Thanks!)

    Saturday, September 20, 2014 4:16 AM
  • In my experience, you cannot use a ConfigMgr 2012 R2 SUP to patch builds in MDT. Specifically, if you attempt to use the WSUSServer property in CS.ini, it will not work with the SUP. In my environment, I have standalone WSUS server specifically for servicing MDT.

    Remember, the ConfigMgr SUP is only using WSUS metadata. It is not a "true" WSUS server; updates are downloaded to packages within ConfigMgr. MDT would have no insight to those packages.


    -Nick O.

    I agree with Nick - you can't effectively use a SUP-controlled WSUS for any other non-ConfigMgr purposes.
    There are no approvals in the susdb (which WSUS clients would require), and you shouldn't approve anything in the WSUS console (because that will confuse the WUAgent in a peculiar way), but most importantly as Nick says - there is no update package content sitting on the WSUS, because ConfigMgr hosts the downloaded contently directly, without WSUS even knowing where the content is.

    It's generally recommended to either use a separate WSUS, or, you could use ConfigMgr SUM.
    But plenty of people theorise that the simplest/purest reference image comes from MDT and where ConfigMgr client has never been installed....


    Don
    (Please take a moment to "Vote as Helpful" and/or "Mark as Answer", where applicable.
    This helps the community, keeps the forums tidy, and recognises useful contributions. Thanks!)

    Saturday, September 20, 2014 4:20 AM