Sorry - changed depts at work and have been swamped with new stuff - haven't been to visit in a while. However, the WSUS library is working great. I use it in the environment I'm responsible for and it works great.

We used to have the WSUS admins release some patches on the first week, then the second week, and finally the third week, so we could roll out to our Secondary QA, Primary QA, and then production servers. Sometimes they would forget to release patches to a machine, or would not releast them in time.. we'd lose our patch window. Sometimes, too, when the patches were downloaded during the day, we'd have short periods where our app would hang, even though BITS is supposed to be low overhead.

We changed the settings on the target systems to report only - D/L & install only when initiated by an admin - we've had no hang problems, unexpected installs, or missed patch windows. Every patch for our servers is now approved for every server on the first of the month. The servers still report their needs every 4 hours or so, but don't download or install anything until either an admin logs in and initiates it, or the WUS script (using this library, and included in the zip file) is executed. This is done by a windows task scheduler event on the first, second, or third weekend of the month.

So far, I've encountered only one issue - if the patches are downloaded but not installed by some mechanism outside the library (still haven't figured out how that happened) the script sees there are no patches to download and exits. It needs to be recoded to continue processing, installing previously downloaded patches. This is a minor issue and can be changed by eliminating the EXIT statement that is invoked when no patches are available for download.

Glenn
_________________________
Actually I am a Rocket Scientist! \:D