• MS-Defcon 2 – Get ready to pause for Dec

    Home » Forums » Newsletter and Homepage topics » MS-Defcon 2 – Get ready to pause for Dec

    Author
    Topic
    #2316314

    It’s time to put the pause (or defer) for your updates.ย  It’s the first Tuesday of the month and non security Office updates are out – PK has them lis
    [See the full post at: MS-Defcon 2 – Get ready to pause for Dec]

    Susan Bradley Patch Lady/Prudent patcher

    2 users thanked author for this post.
    Viewing 4 reply threads
    Author
    Replies
    • #2316408

      I wasn’t able to install the November updates. I had a problem making a backup and then my computer crashed. Is there a way just to just install the November updates?

      • #2316439

        You can download any updates from Microsoft Catalog manually.

        1 user thanked author for this post.
        • #2316449

          Thank you. What do I put in the search box?

          • #2316470

            @Morty

            To find all November 2020 Windows updates in the Microsoft Update Catalog, search for “2020-11” (no quotes). You’ll have to scroll thru several pages and pick only the ones applicable to your Windows version & bitness (x86 or x64).

            For Windows & MSOffice updates, you can still get November’s via Windows Update (WU) up to & even after MS has released the December updates.

            First run WU. After WU finds all outstanding updates, highlight (click on) each found update and verify that it’s release date (in description area on left) is prior to Dec 2020. If any are dated Dec 2020 (or later), first uncheck then hide these updates.

            Once all updates dated Dec 2020 (or later) have been hidden, run WU again. This time WU will find & display the outstanding November 2020 (or prior) updates that were superseded by the hidden Dec 2020 updates.

            After all your Nov 2020 (or prior) updates are successfully installed and system’s been rebooted, if you hid any Dec 2020 updates, run WU again and restore these hidden Dec 2020 updates so they can be found again when it’s time to install these later on (when we’re out of MS-DEFCON 2 for the Dec 2020 updates). You can safely exit out of WU without installing any of the re-found Dec 2020 updates.

            Win7 - PRO & Ultimate, x64 & x86
            Win8.1 - PRO, x64 & x86
            Groups A, B & ABS

            1 user thanked author for this post.
    • #2316451

      Download WUmgr and run it. You can then choose exactly which updates to install.

      cheers, Paul

      1 user thanked author for this post.
    • #2316454

      The Author’s site is: https://github.com/DavidXanatos/wumgr/releases

      cheers, Paul

      1 user thanked author for this post.
      • #2316941

        This is getting a little over my head. How much of a risk am I taking to wait for the next DEFCON 3 or 4?

        • #2316954

          only little risk I guess

          1 user thanked author for this post.
    • #2317025

      I’m confused. I thought Patch Tuesday was the 2nd Tuesday of the month. Since the first Tuesday was Dec. 1, the second Tuesday can’t be before Dec 8. Why DEFCON 2 now? Historically, I’ve waited until just a few days before Patch Tuesday to install Windows updates. What am I missing?

      2 users thanked author for this post.
      • #2317031

        Because of the Office updates. Windows will install anything in the queue unless you prevent it.

        cheers, Paul

        2 users thanked author for this post.
      • #2317034

        “Why DEFCON 2 now?” Exactly!
        What on earth has non-security office patches got to do with the defcon system?
        I’m missing da-real-boss already :)/

        • #2317074

          November patches had the DEFCON-4 rating to go ahead and patch.
          The Office non-Security patches are December updates under the December DEFCON-2 rating, not to be installed yet.
          They are NOT included in the November DEFCON-4 patching (as started in the release announcement post).

          The DEFCON System applies to the updates.
          November updates were classified under DEFCON-4. That means they are now OK to install ANY TIME.
          The DEFCON-2 rating is now aimed at the December patches in order to discourage patching before the Dec patches are vetted.

          It doesn’t mean you can’t install previous patches that have already been vetted and given the DEFCON-4 rating.

          3 users thanked author for this post.
          • #2317108

            This is a subtlety that has not been explained before as far as I am aware, or there has been a policy change. Before Woody retired, he would normally have called time on patching (i.e. set MS-DEFCON 2) around the eve of patch Tuesday, the second Tuesday of the month. And non-security Office patches were around then, weren’t they?

            1 user thanked author for this post.
            • #2317114

              Nothing has changed – it’s always been that way.
              I have explained this quite a few times.
              If a patch has been approved for installing, that approval is not revoked just because the next month’s patches have not been vetted and approved.

              DEFCON is meant to protect you from new, unvetted patches, not limit when you can install patches that have already been through the DEFCON-approval process and OKed for install. DEFCON assumes you install the approved patches during the DEFCON 3-5 window. But if you fall behind and miss the window, it doesn’t prevent you from catching up with the approved updates. Just don’t install the ones that haven’t been approved through the DEFCON System.

              3 users thanked author for this post.
            • #2317254

              @pkcano

              I understand completely what you are stating and, with one exception, I agree with everything. The one exception is your first sentence.

              If, from now on, we can expect MS-DEFCON to be set back to 2 on the eve of the first Tuesday of the month, instead of on the eve of the second Tuesday of the month, that to me is a change in policy.

              I am thankful to @snalmond for raising the issue because I was contemplating doing it. However, at a personal level, it makes no difference to me. My version of Office is CTR and so I don’t get my Office updates through Windows Update. Unless there are exceptional circumstances, I shall continue to wait until nearer Patch Tuesday before applying my system updates.

              • This reply was modified 4 years, 5 months ago by TonyC.
              1 user thanked author for this post.
            • #2317258

              The DEFCON change has never been a set day. It has always been contingent on a condition – that condition being the ability to patch safely.

              When there was enough information on the updates to determine where the problems lay, Woody changed the DEFCON number. He usually waited till the Preview was released to see what MS had fixed. And it was usually preceding a weekend that DEFCON was changed, in order to have the off-time to do the updating. But it was not set to a specific day.

              Woody has retired, and this is Susan’s decision now. The problems that exist with Nov updates are pretty much known and there have not been a bunch of new ones appearing. So it seemed a good time, with the US holiday long weekend off-time, to give the go-ahead. More time for those supporting family and friends to help with the updating.

              But DEFCON has never been a rigid schedule that has to be done on a given day, or not at all. It is meant as a guideline, to indicate that the problems with a particular set of updates are mostly known and, given that knowledge, installing that set of updates is relatively safe.
              (Notice I don’t use the absolute where MS is concerned. ๐Ÿ™‚ )

              3 users thanked author for this post.
    • #2323027

      I did the November patches in December when their Defcon was changed from 2 to 4, and set my December delay for 25 days. That time is about to run out on January 1rst. Any hints as to whether the December patches will be ready by then, and Defcon pushed up to 4 again?

      • #2323035

        The best answer at this time with no hints from Susan yet is “we’ll see”. My guess is that we’ll see the DEFCON go to either 3 or 4 this week or next, so you’ll be OK with your delay if the DEFCON level is changed this week. If not, you can always hit “Pause updates” one more time to give yourself another 7 days’ delay.

        The December patches were released on the 8th, so 25 days gives you, as you say, till the 2nd of January, after which you should be offered the December updates by Windows Update. If you’ve been able to follow the guidance in AKB 2000016, you should be set up so that Windows Update merely informs you that the updates are available but does not install them until you click the “Download” button.

        If you haven’t taken the time to look through the article, perhaps this might be a good time to read through it, keeping your own installation in mind, as AKB 2000016 covers both Windows 10 Home and Windows 10 Pro editions and versions from 2004/20H2 through those from 1909 and earlier.

        We have until January 12th to install the December updates, as that’s when MS will release the January updates.

      • #2323056

        If you used Pause, click the Pause again for another 7 days.
        If you are using Deferrals, change it to 30 days to give you 5 more.

        If you set the maximum Pause and you are running out, read through this thread:
        There is a way to cheat Pause

    Viewing 4 reply threads
    Reply To: MS-Defcon 2 – Get ready to pause for Dec

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: