Patch using both Bigfix and Build-in Windows Updates

Hi,

I would like to ask around if anyone in this forum at enterprise level ever try updating their machine patches using bigfix in company, while at home uses windows updates to patch? What are the pros and cons?

My company are on certain proxy setting then will only allow communication back to Bigfix.

I’m not sure I get what you are asking, could you re-phrase what you are looking to do?

Are you talking about your personal / work laptop? Using both methods to patch?

This is something I would try to avoid.

You will lose control of which patches are applied where/when.
If a given patch causes issues in your environment, a laptop that goes home and patches there will apply patches that you have explicitly chosen not to install until the issues are ironed out.

You should instead look at the option for direct download. This would allow patching via Bigfix, but enable off-site clients to download direct from source and not your Bigfix infrastructure

Your question is a little confusing but I believe you are asking if a remote user is at home, they use Windows Update but in office they use BigFix?

First, if you are going to use windows update, your control of when patches deploy is more difficult to control.

We patch 30,000 + systems with several thousand remote systems and use Internet Facing Relays to make this work. When a user is in the office, they patch using our internal relays and when they are remote, they use our internet facing relays.

What is the reasoning to use Windows Update vs internet facing DMZ relay?

A relay in a DMZ allows internet connected endpoints to still receive content and new fixlets, actions etc via your Bigfix infra. You can also leverage the direct downloads feature, which has also been enhanced in 10.0.7, to reduce the amount of traffic on the DMZ relay so you the maintain a single patch process but the endpoints on the internet will get content from Micrsooft via the users ISP instead of it hitting your own infra.

Is for work laptop, yes using both methods.