set windows update date after applying K1000 Windows patches
Good Friday all!
Our security team is going to implement a rule on the VPN servers that connection is only possible if the last installed date for windows updates is lower then 30 days.
We are using Kace for Windows updates, and this date is not adjusted and can be still set to 2 years ago.
Although, when I use the manual windows update to check, it shows the same updates to install as what my smartlabels show for pending updates.
So I know it's up to date
Is there an option in Kace to adjust the date shown in the Windows Update screen when new updates have been installed by Kace?
thanks!
0 Comments
[ + ] Show comments
Answers (2)
Please log in to answer
Posted by:
Channeler
8 years ago
KACE does not touch Windows Update feature at all, and there are even some companies that block/disable that feature via GPO.
In the event of a chance to edit that Date... let's say via script by modifying the windows registry, it will cause a gap in the security system... 'cause if at some point the K1´s patching schedule fails for whatever reason, and you are running the script after KACE finishes patching... well...
And that also adds a whole to your VPN security team... I don´t know if there is a way to modify the Windows Updates´ date... but if there is, your VPN is totally vulnerable (I mean everything is, but come on, too easy)...
Your Security Team should look for Installed KB Updates (KACE agent does this via Windows Registry), and confirm if the PCs are behind or still with very old updates installed.
And that also adds a whole to your VPN security team... I don´t know if there is a way to modify the Windows Updates´ date... but if there is, your VPN is totally vulnerable (I mean everything is, but come on, too easy)...
Your Security Team should look for Installed KB Updates (KACE agent does this via Windows Registry), and confirm if the PCs are behind or still with very old updates installed.
Posted by:
Ericenri
8 years ago