Home > Enterprise Desktop Tips > > Scripting resources to automate patching
Enterprise Desktop Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


Scripting resources to automate patching


Tony Bradley, Contributor
08.01.2005
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


When most people hear the word "script" they think of the document an actor or actress would use to learn lines for a movie or play. More than just a collection of lines to memorize, though, the script gives step-by-step instructions on how each scene of the performance should go.

In a similar – yet much less dramatic -- fashion, scripts written for your Windows operating system provide step-by-step instructions for the computer to execute. In its simplest form, a script is just a short text file listing out commands to be run. Any command that can be executed from a command line can also be automated by adding it to a script.

Scripts can be assigned on an individual level through the user account properties on a Windows network. However, it is more efficient to use Group Policy in a Windows domain network, where you can assign scripts to be executed automatically when the computer itself boots up or shuts down, or you can assign scripts to run when a user logs on or off the system.

Used in this manner, Windows scripts can automatically install patches and updates on computer systems. By placing security patches on a server, and creating login scripts to automatically execute patch installations each time computers are rebooted or accessed, administrators can ensure that everyone receives the latest updates.

The Script Repository on Microsoft's Script Center contains a variety of scripts that can be used to administer Windows desktop machines. The following scripts are aimed specifically at security:

Install an Update: To script the installation of a Microsoft patch

Modify the Update Schedule: To script the configuration of the Automatic Update setti


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Microsoft Windows patches and critical updates
Troubleshooting Microsoft WSUS connectivity issues
Windows security tools for the busy desktop administrator
Why should Windows shops use Microsoft Baseline Security Analyzer?
Enhancing patch management with NAP
The 10 most common Windows security vulnerabilities
Windows security in the enterprise: Tutorials
Microsoft will release three critical patches in May
Critical patches for IE and Office released
Have my Windows patches actually been installed?
PatchLink Update 6.4

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


ngs on client machines

Deploying patches this way is obviously cheaper than purchasing and implementing a commercial patch management tool. However, it lacks many features of such tools, including the ability to track the successful patch deployments, automatically recall or undo patches that may cause problems on the network, or create reports about the current state or historical view of patching within the environment. There are scripts available to accomplish some of these tasks, but they are much more tedious and time consuming to use than a full patch management solution.

In any event, Windows scripts are valuable resources to have in your administrator toolbox. With all of the bells and whistles of the Windows GUI interface, it is easy to forget just how quick and simple it can be to execute commands from the command line. A good resource for additional Windows scripts is Microsoft's TechNet Script Center or Doc Rice's Security Patch Scripts for Microsoft Windows NT, 4.0, 2000 and XP.

About the author: Tony Bradley is a consultant and writer with a focus on network security, antivirus and incident response. He is the About.com Guide for Internet / Network Security, providing a broad range of information security tips, advice, reviews and information. Tony also contributes frequently to other industry publications. For a complete list of his freelance contributions, visit Essential Computer Security.


More information from SearchWindowsSecurity.com

  • Tip: Manual vs. automated patch tracking
  • Tip: Patching tug-o-war: When to push or pull patches
  • Topics: Get resources for secure scripting in this topic section


  • Rate this Tip
    To rate tips, you must be a member of SearchEnterpriseDesktop.com.
    Register now to start rating these tips. Log in if you are already a member.


    Submit a Tip




    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



    Enterprise Desktop Security - Virus Protection, Malware Protection, Intrusion Detection
    HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogs
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts