The hairline shows how long I've been in IT
Have you ever had users complain that their computer rebooted unexpectedly about the time you deployed patches? Maybe it gave them a brief warning, but no chance to postpone? We ran into that, and it took a fair bit of digging to get the answer.
We found out that one of the first things that the patch update program does, even before looking at the options you selected, is to check the PendingFileRenameOperations registry key. If there are any operations pending, it performs a reboot right away. It doesn't matter if these affect the patches or not. It doesn't matter if they have anything to do with patching. If there are any operations pending, you get a reboot. I think it gave a five-minute warning, with no option to postpone or cancel. That's not even long enough to call the Help Desk and get to someone that might know what processes to cancel. This applies to servers as well as workstations, of course.
I found, from looking at BindView reports that showed the pending operations, that there were many machines with pending operations from all sorts of things. Most seemed to be from the printers, others were from AntiVirus or other application updates. Some were from patches applied through baseline updates. Our results won't be the same as yours, but the results are definitely not what I had expected. I never there would be so many!
This was even worse when we were using MBSA for patching. We often had two or three separate updates for each machine, one for each scanner (MBSA, Office and Extended MBSA) with updates that month. At first we made two of the three silent, to minimize hassle for the users. That was fine until an Office update turned out to set pending operations for nearly every computer! In fact, that's what led to learning the real cause of this. Until then there were so few complaints that it never got a whole lot of attention.
What do you do about this?
The main thing is being aware that these reports represent a real problem, and what's causing it. If you understand what is setting the pending operations you're well on the way to preventing the problem.
Do you concentrate just on applying the latest updates? Do you figure that once last month's patches
We've all experienced users that blame absolutely everything on patching. My personal favorite is