Preparing endpoints to accept ESU patches
This topic describes how to prepare endpoints to accept Microsoft ESU patches.
Once your endpoints are subscribed to a BigFix ESU patch site, you can use the content in that site to prepare the endpoints in your deployment to accept Microsoft’s ESU patches.
Verify or Apply Prerequisite Windows Patches for ESU
There are multiple Windows patch Fixlets that are pre-requisites for installing the ESU multiple activation key (MAK). The MAK installation fails if the patches are not installed. The ESU Key Management: Install and Activate MAK Fixlet description contains links to the pre-requisite patch Fixlets for each supported operating system, some of which are available in the Patches for Windows site and some of which are available in the ESU patch site. Follow the links to each Fixlet and verify that it is not relevant; if any Fixlet patch is relevant to the endpoints intended for ESU, you should apply it before installing and activating the ESU key.
Distribute Multiple Activation Key to Enable ESU Patching
Fixlets are provided in each ESU Patching site to automate the activation and deactivation of the ESU multiple activation key (MAK) you received from Microsoft on one or many endpoints at a time. The “ESU Key Management: Install and Activate MAK” task will allow you to input your ESU key securely in the Fixlet description, then take action to install and activate the key on the targeted endpoints. Similarly, the “ESU Key Management: Deactivate and Uninstall MAK” task will help you to remove any ESU key that is already installed on endpoints. You are not required to use BigFix to distribute the MAK and you can use different MAK on different sets of endpoints.
Create ESU Patching Groups in BigFix
By copying the analysis property Relevance into a retrieved property, you can use it to create ESU patching groups in your own deployment.
Test ESU Patch Delivery
Each BigFix ESU Patch Add-on site contains Fixlets to test ESU patching functionality on your endpoints. Take action on one and verify that the result is “Fixed”. If your endpoints are able to apply the ESU test patch successfully, it is a good indicator that they are ready for ESU patching.