-
Notifications
You must be signed in to change notification settings - Fork 32
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Ensure that online 'dual scan' is mitigated #198
Comments
This is a big problem for us. As we use the wsus_client module with the I will look through some other settings applied to the clients and see if I can find another solution but the provided solution below should be ok to implement to the module now without any breaking changes Before disabling Dual Scan
No updates at all are found when searching for new updates. When disabling Dual Scan
Updates are found when searching for updates All settings set by puppet below
SolutionThe soulution for me would be to update the module with a parameter for |
Some more information. Seems like the So the solution would be to either remove the GPCache-key and restart wuauserv ( it gets recreated with the correct values ) - or preferrably set the I will post a pull request for setting that value as a parameter |
Use Case
As per https://cloudblogs.microsoft.com/windowsserver/2017/01/09/why-wsus-and-sccm-managed-clients-are-reaching-out-to-microsoft-online/ (assuming this is still a known issue), Windows has a potential to perform dual-scan for updates even when a WSUS server is defined
Describe the Solution You Would Like
Mitigation in place if this is still an issue
Describe Alternatives You've Considered
As I manage a range of registry keys in a private module (based on CIS), I use the following overrides to mitigate the issue. This may serve as an example with affected registry keys
Additional Context
Not limiting update source purely to a defined WSUS server is probably undesirable
The text was updated successfully, but these errors were encountered: