Hey Guys,
Here is my setup - Last year, I switched the servers my team manages over to BigFix for Windows updates. I decided to use Patch Policies instead of baselines because they are automated and will continue to work automatically if I am out of town, etc. I have the servers downloading the policies prior to update time, but I only had a 2 hour “patch duration” specifically because of some other issues with HA and monitoring. I switched to a 3 hour window next month to hopefully assist with the reporting that leaves the VM at “running”: or “pending restart”. I do have a pre-patch script that only reboots the servers prior to patching if it detects that is needed, and I have checked the box to “force restart: immediately after” for all servers. The patch policies are setup to continue on error and retry twice on failure. This seems to be working at 90%, but I still have a few outlier issues each month.
I had a bigger issue this month. Server 2016 only is having an issue running both Service Stack and Cumulative patch policies. We had several dozen 2016 servers only that installed only the Service Stack, and skipped the January cumulative update. I can fix this with a baseline, but trying to figure out what I can possibly do to keep this from happening again? I will pull some logs and attach, but let me know if anyone has any ideas.