INTRODUCTION
As part of an ongoing commitment to providing detection tools and deployment recommendations for security updates, Microsoft is delivering this detection and deployment guidance for all updates that are released during a Microsoft Security Response Center (MSRC) release cycle.
This guidance contains recommendations that are based on the kinds of scenarios that may exist in various Microsoft operating system environments. This guidance includes how to use tools such as the following:-
Windows Update
-
Microsoft Update
-
The Microsoft Baseline Security Analyzer (MBSA)
-
Windows Server Update Services (WSUS)
-
Microsoft System Center Configuration Manager 2007 (Configuration Manager 2007)
-
Microsoft Systems Management Server (SMS) 2003
-
The Extended Security Update Inventory Tool
This article details the Microsoft software that may not be supported by some detection and deployment products that are on this list. System Center Configuration Manager 2007. For customers who remain on SMS 2003 Service Pack 3, the SMS 2003 Inventory Tool for Microsoft Updates (ITMU) is also an option.
Note Microsoft discontinued support for SMS 2.0 on April 12, 2011. For SMS 2003, Microsoft also discontinued support for the Security Update Inventory Tool (SUIT) on April 12, 2011. Customers are encouraged to upgrade toMore Information
Detection and deployment
Environments that detect and deploy security updates by using Windows Update, Microsoft Update, and the Office for Mac website
Windows Update
http://update.microsoft.com/windowsupdateWindows Update supports the following products:
-
Windows XP
-
Windows Server 2003
-
Windows Vista
-
Windows Server 2008
-
Windows 7
-
Windows Server 2008 R2
Microsoft Update
http://update.microsoft.com/microsoftupdateMicrosoft Update does not support the following products:
-
Visual Studio 2002
-
Visual Studio 2003
-
Platform SDK: GDI+
-
Any Macintosh products
-
MSN Messenger
-
Windows Live Messenger
Office for Mac website
http://www.microsoft.com/mac/The Office for Mac website supports the following products:
-
Microsoft Office 2004 for Mac
-
Microsoft Office X for Mac
-
Microsoft Office 2008 for Mac
-
Microsoft Office 2011 for Mac
Environments that detect security updates by using Microsoft Baseline Security Analyzer (MBSA) version 2.2
MBSA 2.2 does not support the following products:
-
Visual Studio 2002 or Visual Studio 2003
-
Platform SDK: GDI+
-
Any Macintosh products
-
MSN Messenger or Windows Live Messenger
Offline and Online scans
-
Online scan
An online scan occurs when the system that is scanned by MBSA 2.2 has connectivity to Microsoft Update. This is shown in the completed scan report. -
Offline scan
An offline scan occurs when the system that is scanned by MBSA 2.2 is managed by WSUS or is in an offline secure environment that forces the system to use the Wsusscn2.cab offline catalog.
Environments that detect and deploy security updates by using Windows Server Update Services (WSUS)
You can detect and deploy security updates if you the following item:
-
WSUS 3.0 SP2
WSUS does not support the following products:
-
Visual Studio 2002
-
Visual Studio 2003
-
Platform SDK: GDI+
-
Any Macintosh products
-
MSN Messenger
-
Windows Live Messenger
Environments that detect and deploy security updates by using SMS 2003 or Configuration Manager 2007
You can detect and deploy security updates if you use any of the following items:
-
SMS 2003 together with the SUS Feature Pack
-
SMS 2003 together with the Inventory Tool for Microsoft Updates (ITMU)
-
Configuration Manager 2007
Notes
-
SMS 2003 Service Pack 3 (SP3) includes support for, and is required for, Windows Vista and Windows Server 2008 manageability.
-
SMS 2003 with the SUS Feature Pack requires the Extended Security Update Inventory Tool to detect all security updates.
-
SMS 2003 together with the ITMU and Configuration Manager 2007 do not support the following products:
-
Visual Studio 2002
-
Visual Studio 2003
-
Platform SDK: GDI+
-
Any Macintosh products
-
MSN Messenger
-
Windows Live Messenger
-
-
SMS 2003 together with the SUS Feature Pack does not support the following products:
-
Microsoft Expression Web
-
Microsoft Expression Web 2
-
Microsoft Host Integration Server 2000, 2004, and 2006
-
Report Viewer 2005
-
Report Viewer 2008
-
Windows Media Player 11
-
Microsoft QL Server 2005
-
SQL Server 2008
-
Visual Studio 2008
-
Microsoft Exchange Server 2007
-
Exchange Server 2010
-
The 2007 Office system
-
Office 2010
-
Windows Internet Explorer 7, Internet Explorer 8, or Internet Explorer 9
-
Windows Vista
-
Windows 7
-
Windows Server 2008
-
Windows Server 2008 R2
-
Search Server 2008
-
Any x64-based versions of Windows or of SQL Server
-
Any Itanium-based versions of Windows or of SQL Server
-
-
SMS 2003 with the SUS Feature Pack, SMS 2003 ITMU, and Configuration Manager 2007 do not support any Macintosh products.
Acronym table
The following acronyms are provided to help with reading the table in the "Summary of detection and deployment guidance" section.
Acronym |
Product |
---|---|
WU |
Windows Update |
MU |
Microsoft Update |
MBSA |
Microsoft Baseline Security Analyzer |
WSUS |
WSUS 3.0 |
SUSFP |
SMS 2003 SUS Feature Pack |
ITMU |
SMS 2003 Inventory Tool for Microsoft Updates |
Configuration Manager 2007 |
System Center Configuration Manager 2007 |
Summary of detection and deployment guidance
The following table summarizes the detection and deployment exceptions for each product.
Generally, MU, MBSA, WSUS, SMS ITMU, and Configuration Manager 2007 all support the same products because they are all based on the same metadata. When a field in a column is blank, this means that no detection and deployment tool applies to that column for that product. Note This table does not include all Microsoft products. The table includes major products such as Windows and SQL Server. The "Other Products" section includes products for which Microsoft has released a security update and for which there is an exception for one of these products. New products may be added at any time.
Product |
Detection and deployment not supported |
Detection and deployment supported |
Windows |
Office |
SQL Server |
Exchange Server |
Other Products |
---|---|---|---|---|---|---|---|
Windows XP |
WU, MU, MBSA,WSUS, SUSFP, ITMU, Configuration Manager 2007 |
||||||
Windows Server 2003 |
WU, MU, MBSA,WSUS, SUSFP, ITMU, Configuration Manager 2007 |
||||||
Windows Server 2008 |
SUSFP |
WU, MU, MBSA,WSUS, ITMU, Configuration Manager 2007 |
|||||
Windows Server 2008 R2 |
SUSFP |
WU, MU, MBSA,WSUS, ITMU, Configuration Manager 2007 |
|||||
Windows Vista |
SUSFP |
WU, MU, MBSA,WSUS, ITMU, Configuration Manager 2007 |
|||||
Windows 7 |
SUSFP |
WU, MU, MBSA,WSUS, ITMU, Configuration Manager 2007 |
|||||
Windows Internet Explorer 7, 8 and 9 |
SUSFP |
WU, MU, MBSA,WSUS, ITMU, Configuration Manager 2007 |
|||||
Windows Media Player 11 |
SUSFP |
WU, MU, MBSA,WSUS, ITMU, Configuration Manager 2007 |
|||||
Any Itanium-based versions of Windows |
SUSFP |
WU, MU, MBSA,WSUS, ITMU, Configuration Manager 2007 |
|||||
Any x64-based versions of Windows |
SUSFP |
WU, MU, MBSA,WSUS, ITMU, Configuration Manager 2007 |
|||||
Office 2003 |
MU, MBSA,WSUS, SUSFP, ITMU, Configuration Manager 2007 |
||||||
The 2007 Office system |
SUSFP |
MU, MBSA,WSUS, ITMU, Configuration Manager 2007 |
|||||
Office 2010 |
SUSFP |
MU, MBSA,WSUS, ITMU, Configuration Manager 2007 |
|||||
SQL Server 2000 |
MU, MBSA,WSUS, SUSFP, ITMU, Configuration Manager 2007 |
||||||
SQL Server 2005 |
SUSFP |
MU, MBSA,WSUS, ITMU, Configuration Manager 2007 |
|||||
SQL Server 2008 |
SUSFP |
MU, MBSA,WSUS, ITMU, Configuration Manager 2007 |
|||||
Any Itanium-based versions of SQL Server |
SUSFP |
MU, MBSA,WSUS, ITMU, Configuration Manager 2007 |
|||||
Any x64-based versions of SQL Server |
SUSFP |
MU, MBSA,WSUS, ITMU, Configuration Manager 2007 |
|||||
Exchange Server 2003 |
MU, MBSA,WSUS, SUSFP, ITMU, Configuration Manager 2007 |
||||||
Exchange Server 2007 |
SUSFP |
MU, MBSA,WSUS, ITMU, Configuration Manager 2007 |
|||||
Exchange Server 2010 |
SUSFP |
MU, MBSA,WSUS, ITMU, Configuration Manager 2007 |
|||||
Any Macintosh products |
MU, MBSA,WSUS, SUSFP, ITMU, Configuration Manager 2007 |
||||||
Microsoft Forefront Client Security 1.0 |
SUSFP |
MU, MBSA,WSUS, ITMU, Configuration Manager 2007 |
|||||
Host Integration Server 2000, 2004, 2006, 2009, and 2010 |
SUSFP |
MU, MBSA,WSUS, ITMU, Configuration Manager 2007 |
|||||
Microsoft Expression Media v1 and v2, Microsoft Expression Web 3 and 4 |
SUSFP |
MU, MBSA,WSUS, ITMU, Configuration Manager 2007 |
|||||
Windows Live |
SUSFP |
MU, MBSA,WSUS, ITMU, Configuration Manager 2007 |
|||||
Platform SDK: GDI+ |
MU, MBSA,WSUS, SUSFP, ITMU, Configuration Manager 2007 |
||||||
Search Server 2008 |
WU, SUSFP |
MU, MBSA,WSUS, ITMU, Configuration Manager 2007 |
|||||
Visual Studio 2002 or Visual Studio 2003 |
MU, MBSA,WSUS, ITMU, Configuration Manager 2007 |
SUSFP |
|||||
Visual Studio 2005 and 2008 |
SUSFP |
MU, MBSA,WSUS, ITMU, Configuration Manager 2007 |
Frequently asked questions
What is Microsoft doing to provide guidance about how to deploy these updates?
We encourage system administrators to join the monthly technical webcast to learn more about security updates. The webcast occurs every month. To register, visit the following Microsoft website:http://msevents.microsoft.comSearch for "Security Bulletins (Level 200)" and then sort by date. These webcasts are scheduled several months in advance. Therefore, make sure that you look for the specific month and year of the webcast that you want to view. What other information should I know about MBSA? For more information about the programs that MBSA currently supports, visit the following Microsoft TechNet website:
http://technet.microsoft.com/en-us/security/cc184923.aspxCan I use SMS or System Center Configuration Manager to determine whether the updates are required? Yes. SMS helps detect and deploy these security updates. SMS 2003 together with SUSFP uses MBSA version 1.2.1 technology for detection. Therefore, SMS 2003 together with the SUS Feature Pack has limitations that resemble the limitations of MBSA version 1.2.1. For more information about SMS, visit the following Microsoft TechNet website:
http://technet.microsoft.com/en-us/library/cc181833.aspxThe SUS Feature Pack together with the Extended Security Update Inventory Tool is required to detect all the security updates on Windows and on other affected Microsoft products. For more information about the limitations of the SUS Feature Pack, visit the following Microsoft website:
Software Update Services Feature PackSMS 2.0 together with the SUS Feature Pack and SMS 2003 together with the SUS Feature Pack also uses the Microsoft Office Inventory Tool to detect the required security updates for Microsoft Office programs such as Microsoft Word. SMS 2003 customers can also use ITMU to detect and to deploy security updates. ITMU uses technology from Microsoft Update. For more information about ITMU, visit the following Microsoft website:
http://technet.microsoft.com/en-us/systemcenter/bb676783Configuration Manager 2007 uses WSUS 3.0 for detection and deployment of these security updates. Therefore, anything that is supported by WSUS 3.0 is also supported by Configuration Manager 2007.