Microsoft plays its wild card

How-To
Jan 17, 20057 mins

Free patch update server and vulnerability assessment scanner slated to ship this year.

This could be the year Microsoft finally solves its patch management problems. In October 2003, CEO Steve Balmer said the vendor was seven months away from delivering a new corporate patch server, tools to streamline patch installation and one patch download site for all its software.

This set of free tools would replace an oft-criticized, mismatched, grab bag of patching software that more often than not deliver conflicting data that left administrators unsure if they were patched or not.

Microsoft’s ultimate goal is to have these tools form the foundation of one patch infrastructure that includes free tools for smaller companies and fee-based software, Systems Management Server (SMS) and Microsoft Operations Manager (MOM), for larger companies.

Ballmer’s seven-month ship date came and went in early 2004, and today Microsoft has still not shipped those upgrades to its free products.

“Microsoft must get the patch situation under control,” says Ron Sellers, an independent consultant. “Microsoft produces some very good, easy-to-use software with excellent system integration for a very reasonable price. Unfortunately, the cost of patch management may be enough to negate all of the other positives when I have to examine the bottom line.”

Microsoft has heard the complaints, but the solution that it’s proposing has limitations. The free tools will only work with newer versions of the Windows operating system and only with Microsoft applications.

Experts say the free tools will be great for smaller users with mostly Microsoft software, and less appealing to larger companies that still will need something like SMS, which adds features such as inventory and administrative controls the free tools won’t have. Or users will have to turn to third-party tools that handle Microsoft and other platforms, such as Linux, that the software giant ignores.

“Third-party tools have to be considered because users can’t wait for Microsoft to deliver the free tools,” says Trent Henry, an analyst with Burton Group. “And in many cases, customers have non-Microsoft infrastructure, which is another reason the third-party tools play effectively.”

So far, Microsoft’s progress has been marked in small steps. In November 2003, Microsoft introduced a monthly release cycle, issuing patches on the second Tuesday of each month. The move let users schedule their patch efforts. In December 2004, Microsoft added advance notice on how many and how critical the Tuesday patches would be. Microsoft also reduced reboots for patch installation by 10%, reduced patch sizes by up to 75% and offered Webcasts guidance whitepapers on patching.

But in the first half of this year, Microsoft’s patching past is slated to meet the future Ballmer laid out more than a year ago.

First up is Windows Update Services, a free server that corporations deploy internally to download patches from Microsoft and push them out to desktops and servers via the WUS client.

The first WUS beta, released in November, features a reporting engine, restart controls and bandwidth throttling that was missing in the software’s predecessor, System Update Services. But the keys are a client-side scanning engine that details what patches are installed and catalog technology that lists available patches and updates.

The other side of WUS is Microsoft Update, a public Microsoft Web-based patch download site and the replacement for the current Windows Update. Microsoft Update will provide patches for a range of Microsoft software, not just Windows.

Both WUS and Microsoft Update are expected in the first half of 2005.

Microsoft also will reduce the number of patch installers it develops from eight to two, MSI 3.0 for installing patches on any Microsoft software except Windows and Update.exe for the Windows operating system.

But the real milestones start with WUS and Microsoft Update, which will eventually align with licensed tools such as SMS and MOM. Both will incorporate the WUS scanning and cataloging technology.

“WUS and Microsoft Update create an infrastructure for the rest of our patch and vulnerability assessment tools,” says Bill Anderson, group product manager in the Windows and enterprise management division at Microsoft.

Shortly after those two ship, Microsoft will release a new version of Microsoft Baseline Security Analyzer (MBSA), a free vulnerability assessment tool. MBSA 2.0 also will incorporate WUS scanning technology in favor of its current HFNetChk scanning engine. SMS users will be provided with software to add MBSA, the scanning engine and the catalog technology. SMS will collect vulnerability and configuration data using output from MBSA. Today, SMS only consumes MBSA’s patch data.

“Users will be able to do enterprise-wide vulnerability reporting and use SMS or group policy technology to close those vulnerabilities,” Anderson says. “In the next two years, we will have one infrastructure for getting content from Microsoft and delivering that across your enterprise.”

Microsoft users hopeful

“It would be nice if they could fix the scanning issues, it would be nice to have consistency to know which boxes are vulnerable and which are not,” says Mike Miller, director of support services for Media General in Richmond, Va., which publishes the Richmond Times-Dispatch and The Tampa Tribune, among other newspapers. Miller uses SMS, but he says free tools must be available from Microsoft.

“Small to midsized companies that cannot afford enterprise patch software still need to patch their stuff. One small company that says it can’t afford to patch is a big potential risk for everyone else hooked up to the Internet,” Miller says.

Microsoft says it will continue to offer free tools as part of its patch wares, but SMS, MOM and other management tools Microsoft sells will offer the broadest features.

“The main reason Microsoft is doing WUS is that they want something they can provide for free to make sure that no organization has the excuse that they can’t get the funds for patch tools,” says Peter Pawlak, an analyst with independent research firm Directions on Microsoft. “SMS is a fairly substantial project to take on, but WUS can be brought in through the back door and you just do it.”

Dissecting WUS

Microsoft’s Windows Update Services (WUS), a replacement for the current System Update Services 1.0, is a patch server and desktop client that users deploy locally to get updates directly from Microsoft and push them out to servers and desktops.
Versions: One version for all customers. Today, nearly 115,000 users of SUS 1.0.
Server: Runs on Windows 2000 Service Pack 4 or higher; Windows Server 2003; Internet Information Services 5.5 and higher; and SQL Server 2000 SP 3 and higher, SQL Server 2003 or SQL Server Desktop Engine 2000.
Client: Runs on Win 2000 Server and Professional SP4 and higher, Win 2003 and Windows XP.
Operating system patches supported: Win 2000 Server and Professional SP 3 or later, Win 2003 and XP.
Application patches supported: Initially Office 2003, Office XP, Exchange 2003, SQL Server 2000, and MSDE 2000. Support for older versions of those products will be added over time.
Service Pack and update support: Only for Microsoft applications and operating systems.
Migration: Microsoft will provide a tool to move from SUS 1.0 to WUS.
Reporting engine: Includes the ability to see the last-contact date; operating system version; BIOS and machine details; updates installed, needed or failed on a per-machine, per-update basis. Other top features include binary data compression, full catalog of all patches and automatic update roll back.
Other: Can automatically approve and distribute critical updates without manual approval; SUS 1.0 client will not support WUS features; initial release doesn’t support patch distribution to custom applications.