Job Management Partner 1/Software Distribution Description and Planning Guide

[Contents][Glossary][Index][Back][Next]

2.7.2 Detecting client patch information

JP1/Software Distribution can detect patches that have been installed at clients or have not been installed at clients and provide it as software information.

To detect clients' patch information, you must distribute a program for detecting patches and a detection database file to the clients and then execute a Get software information from client job.

The following figure shows the general procedure for detecting patch information.

Figure 2-36 General procedure for detecting patch information

[Figure]

JP1/Software Distribution supports two methods for detecting patch information:

You choose one of these detection methods, whichever is more suitable to the environment in which patch information is to be detected.

It is perhaps better to use WUA, because it detects not only OS patches but also software patches (such as for Microsoft Office).

If your system supports both WUA and MBSA 1.2.1, WUA will be used (and MBSA 1.2.1 will not be used).

For details about the methods used to detect patch information, see 7.2 Detecting client patch information in the manual Administrator's Guide Volume 1.

The following subsections describe the patch information that can be acquired and the environment required for each detection method.

Organization of this subsection
(1) Using WUA to detect patch information
(2) Using MBSA 1.2.1 to detect patch information
(3) Changing the detection method from MBSA 1.2.1 to WUA

(1) Using WUA to detect patch information

You can detect patch information by installing WUA at a client, distributing the WUA database file to the client, and then executing a software information collection job.

(a) Detectable patch information

This method detects patch information for security updates provided by Microsoft Update. It can detect not only OS patches but also software patches (such as for Microsoft Office).

(b) JP1/Software Distribution Manager version and target environment required for detection

To detect patch information using WUA, Windows JP1/Software Distribution Manager 08-00 or later is required.

Additionally, the target clients must satisfy all the following conditions:

There are no OS or version restrictions on the relay system that relays the Get software information from client job.

(2) Using MBSA 1.2.1 to detect patch information

You can detect uninstalled patch information by executing a Get software information from client job after distributing the MBSA 1.2.1 command line interface (mbsacli.exe file) and a database file for MBSA 1.2.1 to the clients.

(a) Detectable uninstalled patch information

From the results of the security update scan executed by mbsacli.exe, JP1/Software Distribution detects the latest patches that have not been installed (those that are displayed with NOT Found in the scanning results) as unapplied patch information. Note that unapplied patch information cannot be detected for Microsoft Office products because their security updates are not scanned by mbsacli.exe.

(b) JP1/Software Distribution Manager version and target environment required for detection

To detect uninstalled patch information using MBSA 1.2.1, Windows JP1/Software Distribution Manager 07-50 or later is required.

Additionally, the target computers must satisfy all the following conditions:

There are no OS or version restrictions on the relay system that relays the Get software information from client job.

(3) Changing the detection method from MBSA 1.2.1 to WUA

In an environment in which MBSA 1.2.1 is used to detect uninstalled patches, only uninstalled OS patches (such as for Windows 2000 or Windows XP) can be detected. To detect not only OS patches but also uninstalled software patches (such as for Microsoft Office products and Microsoft SQL Server), you must change the detection method from MBSA 1.2.1 to WUA.

To change the detection method from MBSA 1.2.1 to WUA, the detection requirements for WUA must be satisfied by the JP1/Software Distribution Manager that will be used to execute the detection and by the target clients.

For details about the environment required for detection using WUA, see (1)(b) JP1/Software Distribution Manager version and target environment required for detection.

The mbsacli.exe file and database file for MBSA 1.2.1 can remain at the detection targets. In an environment in which WUA is used to detect uninstalled patches, MBSA 1.2.1 will not be used.