LANDesk Patch Management Best practices

Slides:



Advertisements
Similar presentations
1. XP 2 * The Web is a collection of files that reside on computers, called Web servers. * Web servers are connected to each other through the Internet.
Advertisements

The Professional Open Source Company JBoss Network Enterprise Manager Introduction and Walkthrough.
Info to Enterprise Migration Implementation Case Study: SBC Corporation Presented to the Crystal Decisions Regional Users Group for the Bay Area on October.
This course is designed for system managers/administrators to better understand the SAAZ Desktop and Server Management components Students will learn.
SOFTWARE Chapter 5.
Getting Started with Microsoft Office 2007
Chapter 1 The Study of Body Function Image PowerPoint
BASIC SKILLS AND TOOLS USING ACCESS
AQute Eclipse Environment By Peter Kriens CEO aQute OSGi Director of Technology and OSGi Fellow.
6 Copyright © 2005, Oracle. All rights reserved. Building Applications with Oracle JDeveloper 10g.
17 Copyright © 2005, Oracle. All rights reserved. Deploying Applications by Using Java Web Start.
XP New Perspectives on Microsoft Office Word 2003 Tutorial 6 1 Microsoft Office Word 2003 Tutorial 6 – Creating Form Letters and Mailing Labels.
DISTRICT AND SCHOOL ASSESSMENT & TECHNOLOGY COORDINATOR ONLINE TESTING WEBINAR FEBRUARY 7 AND 9, 2012 Washington Online Testi ng OSPI Office of Superintendent.
Your Definitive Lockdown Guide
Integrify 5.0 Tutorial : Creating a New Process
0 QuickBooks: Point of Sale 5.0 Ring Up Sales Inventory Management Customer Tracking Credit Card Management Multiple Security Levels Extensive Reporting.
Introduction Lesson 1 Microsoft Office 2010 and the Internet
| Copyright © 2009 Juniper Networks, Inc. | 1 WX Client Rajoo Nagar PLM, WABU.
1 Scanshell.Net CSSN – Card Scanning Solutions THE ULTIMATE, ALL-IN-ONE CARD-SCANNING SOLUTION.
1 2 In a computer system, a file is a collection of information with a single name, such as addresses.doc, or filebackup.ppt, or ftwr.exe, or guidebook.xls.
Configuration management
Software change management
Suite Suite 2 TPF Software – Overview Binary Editor Remote Scripts zTREX Add-Ins & Project Integration with Source Control Manager.
Information Systems Today: Managing in the Digital World
© 2009 VMware Inc. All rights reserved View Pool Image Configuration Considerations for Gold Images around Application virtualization and performance.
ACT User Meeting June Your entitlements window Entitlements, roles and v1 security overview Problems with v1 security Tasks, jobs and v2 security.
1 The phone in the cloud Utilizing resources hosted anywhere Claes Nilsson.
Pharos Uniprint 8.3 Training
SystemCheck for TestNav. Agenda 2 SystemCheck for TestNav – Overview – iPads and Chromebooks – Accessing SystemCheck SystemCheck – Check Your System Proctor.
Campaign Overview Mailers Mailing Lists
Microsoft Office Illustrated Fundamentals Unit K: Working with Data.
Microsoft Access.
1 Contract Inactivation & Replacement Fly-in Action ( Continue to Page Down/Click on each page…) Electronic Document Access (EDA)
In The Name Of Allah, The Most Beneficent, The Most Merciful
XP New Perspectives on Introducing Microsoft Office 2003 Tutorial 1 1 Using Common Features of Microsoft Office 2003 Tutorial 1.
Microsoft Office Illustrated Fundamentals Unit C: Getting Started with Unit C: Getting Started with Microsoft Office 2010 Microsoft Office 2010.
Chapter 11: The X Window System Guide To UNIX Using Linux Third Edition.
VOORBLAD.
HORIZONT TWS/WebAdmin TWS/WebAdmin for Distributed
4 Oracle Data Integrator First Project – Simple Transformations: One source, one target 3-1.
© 2012 National Heart Foundation of Australia. Slide 2.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill Technology Education Introduction to Computer Administration Introduction.
Services Course Windows Live SkyDrive Participant Guide.
HORIZONT 1 XINFO ® The IT Information System HORIZONT Software for Datacenters Garmischer Str. 8 D München Tel ++49(0)89 /
Contents 2 Engagement Overview Migrating to Hyper-V from VMware Consider if time allows.
Virtual Machine Import and Export
Macromedia Dreamweaver MX 2004 – Design Professional Dreamweaver GETTING STARTED WITH.
25 seconds left…...
XP New Perspectives on Browser and Basics Tutorial 1 1 Browser and Basics Tutorial 1.
® Microsoft Office 2010 Browser and Basics.
What’s New in WatchGuard Dimension v1.2
PSSA Preparation.
A Guide to Unix Using Linux Fourth Edition
A lesson approach © 2011 The McGraw-Hill Companies, Inc. All rights reserved. a lesson approach Microsoft® PowerPoint 2010 © 2011 The McGraw-Hill Companies,
© Paradigm Publishing, Inc Access 2010 Level 2 Unit 2Advanced Reports, Access Tools, and Customizing Access Chapter 8Integrating Access Data.
Benchmark Series Microsoft Excel 2013 Level 2
Introduction to ikhlas ikhlas is an affordable and effective Online Accounting Solution that is currently available in Brunei.
Exony Reports User Guide Estimated Timings:
South Dakota Library Network MetaLib User Interface South Dakota Library Network 1200 University, Unit 9672 Spearfish, SD © South Dakota.
What’s new in WebSpace Changes and improvements with Xythos 7.2 Effective June 24,
User Manager Pro Suite Taking Control of Your Systems Joe Vachon Sales Engineer November 8, 2007.
Module 7: Fundamentals of Administering Windows Server 2008.
11 MANAGING AND DISTRIBUTING SOFTWARE BY USING GROUP POLICY Chapter 5.
DIT314 ~ Client Operating System & Administration CHAPTER 5 MANAGING USER ACCOUNTS AND GROUPS Prepared By : Suraya Alias.
1 Chapter Overview Publishing Resources in Active Directory Service Redirecting Folders Using Group Policies Deploying Applications Using Group Policies.
Microsoft Management Seminar Series SMS 2003 Change Management.
Service Pack 2 System Center Configuration Manager 2007.
LANDesk Software Confidential Data Analytics LANDESK Day 5. March 2014 Jan Pisarik Technical Presales Manager.
Presentation transcript:

LANDesk Patch Management Best practices Chris Rawlings LANDesk Sales Engineer

LANDesk 9.5 SP1 Updates Mobility OS X Inventory Patch HP Integration Printer Management Security Suite Intel Auditing FIPS 140-2 Remote Control Flexera Cloud Service Appliance Data Analytics Agent SmartVue Provisioning Linux/Unix SWD

Patch Management Best Practices

Clean Up The Patch Management Disable Replaced Rules Wizard Adobe Flash Sun Java Itunes

Clean Up The Patch Management Purge Distribution and Patch Definitions Eliminates unnecessary Operating Systems Eliminates unnecessary languages

Clean Up The Patch Management Delete Unnecessary Patches Delete patches in Do Not Scan and unassigned groups Delete undetected patches

Patching – Application EOL Detection Application End Of Life Detection Publish by Content Leverage LANDesk Patch Manager Already support MS Office 2000/XP Adobe Acrobat Pro/Sta 6.x, 7.x, 8.x Adobe Reader 6.x, 7.x, 8.x Java SE 1.3, 1.4, 5.0

Prepare Patch Reports Gather Historical Information Schedule to run on a daily basis

Avoid Impacting Users Configure CPU Utilization during scan for low impact

New Feature Do Not Disturb if… Maximize end-user productivity Reduce unwanted disruptions Detect full screen apps Dynamically hide scan dialog

Configure Reboot options Change Defaults Allow user to defer Reboot if no one is logged After Time out snooze Increase Timeout

Patching – Application Interference Increased first pass success rate Java Browser plugins Custom applications Close applications prior to patching Prevent / block applications from running during the patch process

What you see on the client… Configured to Prompt Don’t allow defer or cancel Shows apps that must close. Dynamically updates list as apps are closed by user.

Process to Kill are Definition Based Clone Vulnerability Edit Detection Rule Add Process to stop

Autofix by Scope Supports Targeted Repairs Fewer Scheduled Tasks to manage

Create query for affected computers Scenario: Administrator wants to quickly and easily create a vulnerability query to represent affected computers. New right-click option The “IN” clause is not editable in the DAL query editor.

New Feature 9.5 SP1 Patching – Maintenance Windows Controlled and Predictable maintenance Autofix policies are queued Machine state detection More aggressive reboot controls become possible

Patching – Application Interference Increased first pass success rate Java Browser plugins Custom applications Close applications prior to patching Prevent / block applications from running during the patch process

Patching – Application EOL Detection Application End Of Life Detection Publish by Content Leverage LANDesk Patch Manager Already support MS Office 2000/XP Adobe Acrobat Pro/Sta 6.x, 7.x, 8.x Adobe Reader 6.x, 7.x, 8.x Java SE 1.3, 1.4, 5.0

Vulnerability severity override Scenario: Administrator disagrees with the predefined severity of a vulnerability definition and/or wants to “lock down” reviewed severities. Right-click multi-selected definitions is allowed. The “focused” definition’s current settings are displayed. For backward compatibility in the database, “Severity” still contains the current value. “OrigSeverity” is null if no override has been specified. Otherwise, it stores the LANDesk-supplied severity.

9.5.1 Software Distribution LANDesk Software

Desktop Manager New interface Customizable branding Deliver Links, Docs & Apps Packages and links can be placed in categories “Chrome-less” app launching WPF and EXE Launchpad integrated Task history of client changes

Software Distribution Package Bundles Leverages groups in distribution packages Set the installation order (one level) Allows for packages to be grouped and ordered (one level) Categories are supported Group multiple packages or bundles Bundle within a bundle within a bundle. Schedule the bundle like you would custom groups. Internally what we do is the “My Packages” and “All”, are just bundles. Allows you to schedule one level deep. No circular bundles.

Software Distribution New Streamed Document package type Link for any file type (.txt, .pdf, .docx, .msi, etc.) Associated application Streamed from the portal (new portal only), not downloaded to the client Uses the current associated shell application (by file extension) defined for the client operating system Have to have an associated application with the extension. New portal only. You can point to any file you want. When it shows in the portal it streams to the source file. You need to have an associate application with the extension. You could point to an MSI as a stream share. Use case, say you want to deploy office with a text file for Outlook settings or instructions for your end users. Streaming from UNC, no cached copy from the client, uses all security settings within UNC. Credentials are not specified anywhere as we inherently get access based on the UNC Security.

Software Distribution Default Delivery Method New shared control to select the delivery method Global value Only enabled for Administrators One global default. Not a default within the sub categories, push, policy, etc..

Software Distribution New package pre-cache feature Only downloads package files to client machines, will not perform package installation Mac – 30 days PC – 7 days It just downloads files. Keep it simple image. Initially built for the MAC application installs but made available to all platforms.

Software Distribution Task History Task history is automatically gathered and stored in the client database Task History Maintenance Enable automatic cleanup of task history in the client database Configured in Agent settings and must be associated with each client (Agent configuration / Agent settings) Configurable by days to keep, a value of 0 will delete all task history from the client database If not set, all task history will continue to be stored Settings stored in each client machine registry under LANDesk/ManagementSuite/WinClient/SoftwareDistribution/InventorySettings ClientDatabaseHistoryDays: Specifies days to keep history, -1 or 0xffffffff if not set (all task history will be kept) See the history, what’s been installed, when, when attempted, failed, etc… Once it completes a package task it will then update it’s history agenda. Checked means it will maintain and keep for x days. Unchecked it does not maintain and everything is kept.

Software Distribution Task History/Maintenance continued Inventory scanner automatically sends client task history to the core database Located in inventory under LANDesk Management / SWD / History If you have a bundle it will show you the bundle and the suplemental packages. It’s gives task ID and package ID.

Software Distribution Automatically run inventory scanner after package installation Inventory settings located in Agent settings UI Requires an Inventory setting to be associated with each client (Agent configuration / Agent Settings) Creates a local scheduler task from the current time plus a delay If multiple packages are installed, the local scheduled task is added/updated with the new time. Always uses the same task id (779) Two delay settings Initial delay, minimum of 5 minutes, maximum of 60 minutes, default 5 minutes Additional random delay to help stagger scans (reduce the load on the core), minimum of 0 minutes and maximum of 60 minutes, default 15 minutes (will randomize between 0 and the value set) Settings stored in each client machine registry under LANDesk/ManagementSuite/WinClient/SoftwareDistribution/InventorySettings InventoryScanDelayAfterPackageInstall: High word is the initial delay, low word is the additional random delay, -1 or 0xffffffff if not set (inventory scanner will not run after package install) This was the #1 feature asked for at interchange. 3 packages chained, it will update the already created local scheduler task to update the time. You can’t hard code it past 60. It will just exit High Word: First 4 hex digits, Low Word: Last 4 hex digits, 0xffff / ffff

Questions