The Recycle Bin is an organizer where records and folders that one have deleted are put away. They have not been for all time expelled from your hard drive(s), they were just moved to this unique folder called Recycle Bin. In a similar manner, any firm would definitely show interest in having a recycle bin enabled for the Active Directory for various reasons.
Start > server manager > Tools > Active Directory Administrative Center > Open the Domain > In the Tasks click on Enable the Recycle bin...> OK as shown in the figure.
Active Directory server Backup
Start > Server Manager > Tools > Windows Server Backup > Local Backup > In the Actions menu select Backup once.. > Follow the onscreen commands > Select Full server backup (Recommended) / Custom backup > Local Drives are the preferred storage type > Select the supported hard drive for the backup destination.
A system hard drive is an unsupported volume for the server backup
It is a best practice to create a separate non sys-drive for in particular with the server backup.
After confirming with the desired language continue to select the products and the updates that are required for the servers to which the process of patch management should be done.
Option of synchronization is up to individual.
Begin with the initial synchronization as shown below.
Which results in a pop-up of the WSUS Console.
All the updates that are obtained once after the server gets in contact with the Microsoft cop. can be seen in this console.
Console > Updates > All Updates // Make sure the option (Unapproved and any) to be turned on as shown below.
As it is shown that these updates needed to be approved, select all the updates that are visible in the console and right click to approve them which will lead to a confirmation pop-up window as shown.
Right click on the group or the computers to which the patch management need to be done and approve for the installation.
Group policy management
Once the updates were approved by the PMS server, to push the desired updates to the client servers one need to update their group policy. This can be done in the Group Policy Management.
Windows Start > Server Manager > Tools > Group policy management // In the PMS server.
Create a GPO in this domain and Link it here.. by right clicking on the domain to which the patches need to be pushed.
Right click on the created group policy to edit which results in Group policy management editor.
Expand Computer configurations > Policies > Administrative Templates > Windows Components > Windows Updates.
Double click Configure Automatic Updates and set it to Enabled.
One has a freedom of selecting an option of how to configure the updates as shown below.
Click on Apply and then OK.
Double click Specify Intranet Microsoft Update Service Location and set it to Enabled.
Specify the intranet statistics server below in the format [http:Servername:8530] as shown.
Click on Apply and OK.
Proceed to the client server’s command prompt and force the server to update the group policy as shown below and wait for the servers to get appeared in the WSUS console under unassigned computers.
There are various kinds of updates that are provided by Microsoft corporation. Few of them were listed below.
Critical Updates
Security Updates
Definition Updates
Update Rollup
Service pack
Tool
Feature pack
Update
Critical Updates are updates which fixes specific, non-security related, critical bug. That bug can cause for example serious execution degradation, interoperability malfunction or disturb application compatibility.
Security Updates are one of the important type of updates which makes the the complete corporation to be safe against the world of hackers.
WSUS (Windows Server Update Services)
The concept of patch management is one of the significant service that a firm need to run periodically to update themselves and be strong in every single viewpoint. WSUS is a service developed by the Microsoft, which helps in managing and distribution of the patches to multiple servers from the main server. In the point of practicality a server (Windows 2019) is launched as an instance in AWS and connected remotely
A new role Windows server update services and its features were added to the server accordingly and installed.
Windows start > Server manager > Add roles and features //follow the default options on the screen to add a role windows server update service and install the corresponding role.
Before configuring the role, Launch the post installation tasks (from the notification bar as shown below).
Server manager > Tools > Windows server update service > Create a folder name WSUS in the drive and mention the desired file location and click Run. \\ A dialogue box for the file confirmation appears on the screen as shown.
Click close to launch WSUS console.
Follow the on screen commands to configure the WSUS.
As it is the main server to which the the updates needed to be synchronized from the Microsoft, select the option of synchronize from Microsoft Update as shown.
Use the proxy details if needed or else continue further to start connecting with the Microsoft for updating with the details of our server.
Select the desired language and click Finish.
Patience is the key for success
Patience is the other important role and feature that needed to be added for success to be followed in this configuration.