Summary
You published a new SPS patch through the Software Vulnerability Manager to a Windows Server Update Services server (WSUS), but even when you have clicked to "Approve" the update through the incoming options window, your patches are still being deployed to more systems than what you've approved.
Symptoms
You may have noticed that the Software Vulnerability Manager package is actually set to approve before you did it yourself. This blocks you from executing the planned package distribution because even when you set an approval, it doesn't seem to work or take the expected effect. For example, when you decide to not approve a patch immediately but to do it from the "Available" section under the Patching menu.
Cause
There are a few things to understand here.
- SVM Packages are classified as Security/Critical Update after published to a WSUS (+SCCM) server.
- WSUS (SCCM's SUP ) has been configured to auto-approve Security/Critical updates to all hosts.
- Once any package is approved at WSUS, you cannot override the first with a direct second.
This may happen without you realizing how this happened and when because it is pretty common auto-approvals to be set for e.g. Windows Defender security definition updates.
The Software Vulnerability Manager surrenders the package to the WSUS server after publishing and you 'll have to tweak your WSUS to adjust its configuration to be working for you. Or, you may not have to.
Resolution
You can take one of three options:
- Disable the Automatic approval rule from your WSUS if that is not going to prevent your other security patch management programs. This will allow you granular deployment control.
- Keep the Automatic approval rule and decline the updates at the "Available" menu of the web interface of the Software Vulnerability Manager, as soon as you publish them.
- Modify the existing rule to apply only to specific Microsoft products.
Related Articles
Configure & Deploy Language-Based SPS Patches 5Number of Views SHA1 Checksum Error while Publishing SPS Patches 6Number of Views Delete obsolete patch packages created in WSUS by Software Vulnerability Manager 19Number of Views Integrate SVM with WSUS/SCCM and Deploy a Patch [Logic Flow Map] 7Number of Views SVM Publishing to WSUS: Troubleshooting Guide 18Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Case id: 00001065
Activity: Status change: 2 hours ago