Extend the Life of Windows Server 2012/2012 R2 with Azure Arc and SCCM Integration

 Challenge:

  • Maintaining security for Windows Server 2012/2012 R2 after end-of-support by deploying Extended Security Updates (ESUs).
  • Leveraging existing SCCM infrastructure for update deployment while simplifying ESU management.

Solution:

This approach combines the strengths of SCCM and Azure Arc to achieve a streamlined ESU deployment process for on-premises Windows servers.

SCCM:

  • Trusted Patch Management: SCCM remains your familiar tool for deploying updates, including ESUs, to your Windows servers. SCCM integrates well with WSUS for efficient update distribution.

Azure Arc:

Centralized ESU Management:

  1. Onboard eligible Windows servers (2012 & 2012 R2) to Azure Arc.
  2. Important: Update Azure Arc agent to version 1.34 or later for ESU support.
  3. Purchase and manage ESU licenses directly through Azure Arc (optional, simplifies licensing).
  4. Assign ESU licenses to your Azure Arc-enabled servers for simplified tracking.

Workflow:

  1. Azure Arc manages ESU licensing and assignment.
  2. SCCM retrieves updates from WSUS (configured for ESU channels) and deploys them to your servers.

Benefits:

  • Simplified ESU Management: Centralized licensing and assignment in Azure Arc.
  • Familiar Patch Deployment: Leverage existing SCCM expertise for update rollouts.
  • Improved Security: Ensure continued security for your Windows servers with ESUs.

Next Steps:

  • Review prerequisites (SCCM configuration, WSUS synchronization).
  • Onboard eligible servers to Azure Arc and update agents (version 1.34 or later).
  • Consider purchasing and assigning ESU licenses through Azure Arc (optional).
  • Configure SCCM to target relevant Windows versions and include ESU updates in deployments.
  • Thoroughly test the process in a non-production environment before deploying it to production.

Comments

Popular posts from this blog

High Availability vs. Disaster Recovery in Cloud: Key Differences Explained

Understanding App Registration vs. Enterprise Application in Microsoft Entra ID