Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

Detection and deployment guidance for Microsoft security updates


View products that this article applies to.

INTRODUCTION

As part of an ongoing commitment to providing detection tools and deployment recommendations for security updates, Microsoft is delivering this detection and deployment guidance for all updates that are released during a Microsoft Security Response Center (MSRC) release cycle.

This guidance contains recommendations that are based on the kinds of scenarios that may exist in various Microsoft operating system environments. This guidance includes how to use tools such as the following:
  • Windows Update
  • Microsoft Update
  • The Microsoft Baseline Security Analyzer (MBSA)
  • Windows Server Update Services (WSUS)
  • Microsoft System Center Configuration Manager 2007 (Configuration Manager 2007)
  • Microsoft Systems Management Server (SMS) 2003
  • The Extended Security Update Inventory Tool
This article details the Microsoft software that may not be supported by some detection and deployment products that are on this list.

Note Microsoft discontinued support for SMS 2.0 on April 12, 2011. For SMS 2003, Microsoft also discontinued support for the Security Update Inventory Tool (SUIT) on April 12, 2011. Customers are encouraged to upgrade to System Center Configuration Manager 2007. For customers who remain on SMS 2003 Service Pack 3, the SMS 2003 Inventory Tool for Microsoft Updates (ITMU) is also an option.




↑ Back to the top


More Information

Detection and deployment

Environments that detect and deploy security updates by using Windows Update, Microsoft Update, and the Office for Mac website

Windows Update
Windows Update supports the following products:
  • Windows XP
  • Windows Server 2003
  • Windows Vista
  • Windows Server 2008
  • Windows 7
  • Windows Server 2008 R2
Microsoft Update
Microsoft Update does not support the following products:
  • Visual Studio 2002
  • Visual Studio 2003
  • Platform SDK: GDI+
  • Any Macintosh products
  • MSN Messenger
  • Windows Live Messenger
Office for Mac website
The Office for Mac website supports the following products:
  • Microsoft Office 2004 for Mac
  • Microsoft Office X for Mac
  • Microsoft Office 2008 for Mac
  • Microsoft Office 2011 for Mac

Environments that detect security updates by using Microsoft Baseline Security Analyzer (MBSA) version 2.2

MBSA 2.2 does not support the following products:
  • Visual Studio 2002 or Visual Studio 2003
  • Platform SDK: GDI+
  • Any Macintosh products
  • MSN Messenger or Windows Live Messenger
Offline and Online scans
  • Online scan
    An online scan occurs when the system that is scanned by MBSA 2.2 has connectivity to Microsoft Update. This is shown in the completed scan report.
  • Offline scan
    An offline scan occurs when the system that is scanned by MBSA 2.2 is managed by WSUS or is in an offline secure environment that forces the system to use the Wsusscn2.cab offline catalog.

Environments that detect and deploy security updates by using Windows Server Update Services (WSUS)

You can detect and deploy security updates if you the following item:
  • WSUS 3.0 SP2
WSUS does not support the following products:
  • Visual Studio 2002
  • Visual Studio 2003
  • Platform SDK: GDI+
  • Any Macintosh products
  • MSN Messenger
  • Windows Live Messenger

Environments that detect and deploy security updates by using SMS 2003 or Configuration Manager 2007

You can detect and deploy security updates if you use any of the following items:
  • SMS 2003 together with the SUS Feature Pack
  • SMS 2003 together with the Inventory Tool for Microsoft Updates (ITMU)
  • Configuration Manager 2007
Notes
  • SMS 2003 Service Pack 3 (SP3) includes support for, and is required for, Windows Vista and Windows Server 2008 manageability.
  • SMS 2003 with the SUS Feature Pack requires the Extended Security Update Inventory Tool to detect all security updates.
  • SMS 2003 together with the ITMU and Configuration Manager 2007 do not support the following products:
    • Visual Studio 2002
    • Visual Studio 2003
    • Platform SDK: GDI+
    • Any Macintosh products
    • MSN Messenger
    • Windows Live Messenger
  • SMS 2003 together with the SUS Feature Pack does not support the following products:
    • Microsoft Expression Web
    • Microsoft Expression Web 2
    • Microsoft Host Integration Server 2000, 2004, and 2006
    • Report Viewer 2005
    • Report Viewer 2008
    • Windows Media Player 11
    • Microsoft QL Server 2005
    • SQL Server 2008
    • Visual Studio 2008
    • Microsoft Exchange Server 2007 
    • Exchange Server 2010
    • The 2007 Office system
    • Office 2010
    • Windows Internet Explorer 7, Internet Explorer 8, or Internet Explorer 9
    • Windows Vista
    • Windows 7
    • Windows Server 2008
    • Windows Server 2008 R2
    • Search Server 2008
    • Any x64-based versions of Windows or of SQL Server
    • Any Itanium-based versions of Windows or of SQL Server
  • SMS 2003 with the SUS Feature Pack, SMS 2003 ITMU, and Configuration Manager 2007 do not support any Macintosh products.

Acronym table

The following acronyms are provided to help with reading the table in the "Summary of detection and deployment guidance" section.
AcronymProduct
WUWindows Update
MUMicrosoft Update
MBSAMicrosoft Baseline Security Analyzer
WSUSWSUS 3.0
SUSFPSMS 2003 SUS Feature Pack
ITMUSMS 2003 Inventory Tool for Microsoft Updates
Configuration Manager 2007System Center Configuration Manager 2007

Summary of detection and deployment guidance

The following table summarizes the detection and deployment exceptions for each product.


Generally, MU, MBSA, WSUS, SMS ITMU, and Configuration Manager 2007 all support the same products because they are all based on the same metadata.

When a field in a column is blank, this means that no detection and deployment tool applies to that column for that product.

Note This table does not include all Microsoft products. The table includes major products such as Windows and SQL Server. The "Other Products" section includes products for which Microsoft has released a security update and for which there is an exception for one of these products. New products may be added at any time.
ProductDetection and deployment not supportedDetection and deployment supported
Windows
Windows XPWU, MU, MBSA,WSUS, SUSFP, ITMU, Configuration Manager 2007
Windows Server 2003WU, MU, MBSA,WSUS, SUSFP, ITMU, Configuration Manager 2007
Windows Server 2008SUSFPWU, MU, MBSA,WSUS, ITMU, Configuration Manager 2007
Windows Server 2008 R2SUSFPWU, MU, MBSA,WSUS, ITMU, Configuration Manager 2007
Windows VistaSUSFPWU, MU, MBSA,WSUS, ITMU, Configuration Manager 2007
Windows 7SUSFPWU, MU, MBSA,WSUS, ITMU, Configuration Manager 2007
Windows Internet Explorer 7, 8 and 9SUSFPWU, MU, MBSA,WSUS, ITMU, Configuration Manager 2007
Windows Media Player 11SUSFPWU, MU, MBSA,WSUS, ITMU, Configuration Manager 2007
Any Itanium-based versions of WindowsSUSFPWU, MU, MBSA,WSUS, ITMU, Configuration Manager 2007
Any x64-based versions of WindowsSUSFPWU, MU, MBSA,WSUS, ITMU, Configuration Manager 2007
Office
Office 2003MU, MBSA,WSUS, SUSFP, ITMU, Configuration Manager 2007
The 2007 Office systemSUSFPMU, MBSA,WSUS, ITMU, Configuration Manager 2007
Office 2010SUSFPMU, MBSA,WSUS, ITMU, Configuration Manager 2007
SQL Server
SQL Server 2000MU, MBSA,WSUS, SUSFP, ITMU, Configuration Manager 2007
SQL Server 2005SUSFPMU, MBSA,WSUS, ITMU, Configuration Manager 2007
SQL Server 2008SUSFPMU, MBSA,WSUS, ITMU, Configuration Manager 2007
Any Itanium-based versions of SQL ServerSUSFPMU, MBSA,WSUS, ITMU, Configuration Manager 2007
Any x64-based versions of SQL ServerSUSFPMU, MBSA,WSUS, ITMU, Configuration Manager 2007
Exchange Server
Exchange Server 2003MU, MBSA,WSUS, SUSFP, ITMU, Configuration Manager 2007
Exchange Server 2007SUSFPMU, MBSA,WSUS, ITMU, Configuration Manager 2007
Exchange Server 2010SUSFPMU, MBSA,WSUS, ITMU, Configuration Manager 2007
Other Products
Any Macintosh productsMU, MBSA,WSUS, SUSFP, ITMU, Configuration Manager 2007
Microsoft Forefront Client Security 1.0SUSFPMU, MBSA,WSUS, ITMU, Configuration Manager 2007
Host Integration Server 2000, 2004, 2006, 2009, and 2010SUSFPMU, MBSA,WSUS, ITMU, Configuration Manager 2007
Microsoft Expression Media v1 and v2, Microsoft Expression Web 3 and 4SUSFPMU, MBSA,WSUS, ITMU, Configuration Manager 2007
Windows LiveSUSFPMU, MBSA,WSUS, ITMU, Configuration Manager 2007
Platform SDK: GDI+MU, MBSA,WSUS, SUSFP, ITMU, Configuration Manager 2007
Search Server 2008WU, SUSFPMU, MBSA,WSUS, ITMU, Configuration Manager 2007
Visual Studio 2002 or Visual Studio 2003MU, MBSA,WSUS, ITMU, Configuration Manager 2007SUSFP
Visual Studio 2005 and 2008SUSFPMU, MBSA,WSUS, ITMU, Configuration Manager 2007

Frequently asked questions

What is Microsoft doing to provide guidance about how to deploy these updates?


We encourage system administrators to join the monthly technical webcast to learn more about security updates. The webcast occurs every month. To register, visit the following Microsoft website:
Search for "Security Bulletins (Level 200)" and then sort by date. These webcasts are scheduled several months in advance. Therefore, make sure that you look for the specific month and year of the webcast that you want to view. 

What other information should I know about MBSA?


For more information about the programs that MBSA currently supports, visit the following Microsoft TechNet website:
Can I use SMS or System Center Configuration Manager to determine whether the updates are required? 

Yes. SMS helps detect and deploy these security updates. SMS 2003 together with SUSFP uses MBSA version 1.2.1 technology for detection. Therefore, SMS 2003 together with the SUS Feature Pack has limitations that resemble the limitations of MBSA version 1.2.1.

For more information about SMS, visit the following Microsoft TechNet website: The SUS Feature Pack together with the Extended Security Update Inventory Tool is required to detect all the security updates on Windows and on other affected Microsoft products.

For more information about the limitations of the SUS Feature Pack, visit the following Microsoft website: SMS 2.0 together with the SUS Feature Pack and SMS 2003 together with the SUS Feature Pack also uses the Microsoft Office Inventory Tool to detect the required security updates for Microsoft Office programs such as Microsoft Word.

SMS 2003 customers can also use ITMU to detect and to deploy security updates. ITMU uses technology from Microsoft Update. For more information about ITMU, visit the following Microsoft website: Configuration Manager 2007 uses WSUS 3.0 for detection and deployment of these security updates. Therefore, anything that is supported by WSUS 3.0 is also supported by Configuration Manager 2007.

↑ Back to the top


Applies to:

↑ Back to the top

Keywords: kb, kbsccm, kbentirenet, kbsecreview, kbhowto, kbsecurity, kbsecbulletin, kbmustloc, kblangall, kbinfo

↑ Back to the top

Article Info
Article ID : 961747
Revision : 1
Created on : 1/7/2017
Published on : 3/18/2012
Exists online : False
Views : 281