Microsoft Knowledge Base Email Alertz

Detection and Deployment Guidance for Microsoft Security Updates

Search KbAlertz

Advanced Search

Receive Microsoft Knowledge Base articles by E-Mail?

Every night we scan the Microsoft Knowledge Base. If technologies you're interested in are updated, we'll send you an e-mail. You only get one e-mail a day, and only when new articles are added.

Click here to create a
FREE account
Already have an account?
[Click here to Login]











Microsoft Knowledge Base Article

This article contents is Microsoft Copyrighted material.
©2005-©2007 Microsoft Corporation. All rights reserved. Terms of Use | Trademarks

Article ID: 961747 - Last Review: July 19, 2011 - Revision: 4.0

Detection and deployment guidance for Microsoft security updates

On This Page

INTRODUCTION

As part of an ongoing commitment to provide detection tools and deployment recommendations for security updates, Microsoft is delivering this detection and deployment guidance for all updates that are released during a Microsoft Security Response Center (MSRC) release cycle.

This guidance contains recommendations that are based on the kinds of scenarios that may exist in various Microsoft operating system environments. This guidance includes how to use tools such as the following: 
  • Windows Update
  • Microsoft Update
  • The Microsoft Baseline Security Analyzer (MBSA)
  • Windows Server Update Services (WSUS)
  • Microsoft System Center Configuration Manager 2007 (Configuration Manager 2007)
  • Microsoft Systems Management Server (SMS)
  • The Extended Security Update Inventory Tool
This article details the Microsoft software that may not be supported by one or some of the detection and deployment products that are in this list.

MORE INFORMATION

Detection and deployment

Environments that detect and deploy security updates by using Windows Update, Microsoft Update, and Mactopia

Windows Update
http://update.microsoft.com/windowsupdate (http://update.microsoft.com/windowsupdate)
The products that are supported by this website are as follows: 
  • Windows XP
  • Windows Server 2003
  • Windows Vista
  • Windows Server 2008
Microsoft Update
http://update.microsoft.com/microsoftupdate (http://update.microsoft.com/microsoftupdate)
Microsoft Update does not support the following:
  • Visual Studio 2002 or Visual Studio 2003
  • Report Viewer 2005 or Report Viewer 2008
  • Platform SDK: GDI+
  • Office 2003, Office 2007, and Office 2010 components
  • Any Macintosh products
  • MSN Messenger or Windows Live Messenger
Mactopia
http://www.microsoft.com/mac/ (http://www.microsoft.com/mac/)
The products that are supported by this website are as follows:
  • Microsoft Office 2004 for Mac
  • Microsoft Office X for Mac
  • Microsoft Office 2008 for Mac
  • Microsoft Office 2011 for Mac

Environments that detect security updates by using Microsoft Baseline Security Analyzer (MBSA) version 2.2

MBSA does not support the following:
  • Visual Studio 2002 or Visual Studio 2003
  • Report Viewer 2005 or Report Viewer 2008
  • Platform SDK: GDI+
  • Office 2003, Office 2007, or Office 2010 components
  • Any Macintosh products
  • MSN Messenger or Windows Live Messenger
Offline and Online scans
  • Online scan
    This is when the system that is scanned by MBSA 2.2 has connectivity to Microsoft Update. This is shown in the completed scan report.
  • Offline scan
    This is when the system that is scanned by MBSA 2.2 is managed by WSUS or is in an offline secure environment that forces the system to use the Wsusscn2.cab offline catalog. 

Environments that detect and deploy security updates by using Windows Server Update Services (WSUS)

You can detect and deploy security updates if you use any of the following items:
  • WSUS 3.0 SP2
  • WSUS 3.0 SP1
WSUS does not support the following:
  • Visual Studio 2002 or Visual Studio 2003
  • Report Viewer 2005 or Report Viewer 2008
  • Platform SDK: GDI+
  • Office 2003, Office 2007, and Office 2010 components
  • Any Macintosh products
  • MSN Messenger or Windows Live Messenger

Environments that detect and deploy security updates by using SMS 2.0, SMS 2003, or Configuration Manager 2007

You can detect and deploy security updates if you use any of the following items:
  • Systems Management Server (SMS) 2.0 together with the SUS Feature Pack
  • SMS 2003 together with the SUS Feature Pack
  • SMS 2003 together with Inventory Tool for Microsoft Updates (ITMU)
  • Configuration Manager 2007
Notes
  • Microsoft SMS 2003 Service Pack 3 (SP3) includes support for, and is required for, Windows Vista and Windows Server 2008 manageability.
  • The SMS SUS Feature Pack requires the Extended Security Update Inventory Tool to detect all the security updates.

    To obtain the Extended Security Update Inventory Tool, visit the following Microsoft website:
    http://www.microsoft.com/downloads/details.aspx?FamilyId=2C93DA1D-48A0-4E5C-991F-87E08954F61B&displaylang=en (http://www.microsoft.com/downloads/details.aspx?FamilyId=2C93DA1D-48A0-4E5C-991F-87E08954F61B&displaylang=en)
  • SMS 2003 together with the ITMU and Configuration Manager 2007 do not support the following products:
    • Visual Studio 2002 or Visual Studio 2003
    • Report Viewer 2005 or Report Viewer 2008
    • Platform SDK: GDI+
    • Office 2003, Office 2007, or Office 2010 components
    • Any Macintosh products
    • MSN Messenger or Windows Live Messenger
  • SMS together with the SUS Feature Pack does not support the following products:
    • Microsoft Expression Web and Microsoft Expression Web 2
    • Host Integration Server 2000, 2004, and 2006
    • Report Viewer 2005 or Report Viewer 2008
    • Windows Media Player 11
    • SQL Server 2005
    • SQL Server 2008
    • Visual Studio 2008
    • Exchange 2007
    • Exchange 2010
    • The 2007 Office system
    • Office 2010
    • Windows Internet Explorer 7, Internet Explorer 8, or Internet Explorer 9
    • Windows Vista
    • Windows 7
    • Windows Server 2008
    • Windows Server 2008 R2
    • Search Server 2008
    • Any x64-based versions of Windows or of SQL Server
    • Any Itanium-based versions of Windows or of SQL Server
  • The SMS SUS Feature Pack, SMS ITMU, and Configuration Manager 2007 do not support any Macintosh products.

Acronym table

The following acronyms are provided to help with reading the table in the "Summary of detection and deployment guidance" section.
Collapse this tableExpand this table
ProductAcronym
Office UpdateOU
Windows UpdateWU
Microsoft UpdateMU
Microsoft Baseline Security AnalyzerMBSA
WSUS 3.0WSUS
SMS SUS Feature PackSUSFP
SMS Inventory Tool for Microsoft UpdatesITMU
System Center Configuration Manager 2007Configuration Manager 2007

Summary of detection and deployment guidance

The following table summarizes the detection and deployment exceptions for each product.

Generally, MU, MBSA, WSUS, SMS ITMU, and Configuration Manager 2007 all support the same products because they are all based on the same metadata. 

When a field in a column is blank, it means that no detection and deployment tool applies to that column for that product. 

Note This table does not include all Microsoft products. The table includes major products such as Windows and SQL. The "Other Products" section includes products for which Microsoft has released a security update, and there is an exception for one of these products. New products may be added at any time.
Collapse this tableExpand this table
ProductDetection and Deployment not supportedDetection and Deployment supported
Windows
Windows XPWU, MU, MBSA,WSUS, SUSFP, ITMU, Configuration Manager 2007
Windows Server 2003WU, MU, MBSA,WSUS, SUSFP, ITMU, Configuration Manager 2007
Windows Server 2008SUSFPWU, MU, MBSA,WSUS, ITMU, Configuration Manager 2007
Windows Server 2008 R2SUSFPWU, MU, MBSA,WSUS, ITMU, Configuration Manager 2007
Windows VistaSUSFPWU, MU, MBSA,WSUS, ITMU, Configuration Manager 2007
Windows 7SUSFPWU, MU, MBSA,WSUS, ITMU, Configuration Manager 2007
Windows Internet Explorer 7SUSFPWU, MU, MBSA,WSUS, ITMU, Configuration Manager 2007
Windows Media Player 11SUSFPWU, MU, MBSA,WSUS, ITMU, Configuration Manager 2007
Any Itanium-based versions of WindowsSUSFPWU, MU, MBSA,WSUS, ITMU, Configuration Manager 2007
Any x64-based versions of WindowsSUSFPWU, MU, MBSA,WSUS, ITMU, Configuration Manager 2007
Office
Office 2003, 2007, 2010 ComponentsMU, MBSA,WSUS, ITMU, Configuration Manager 2007OU, SUSFP
Office 2003MU, MBSA,WSUS, SUSFP, ITMU, Configuration Manager 2007
The 2007 Office systemSUSFPMU, MBSA,WSUS, ITMU, Configuration Manager 2007
Office 2010SUSFPMU, MBSA,WSUS, ITMU, Configuration Manager 2007
SQL
SQL Server 2000MU, MBSA,WSUS, SUSFP, ITMU, Configuration Manager 2007
SQL Server 2005SUSFPMU, MBSA,WSUS, ITMU, Configuration Manager 2007
SQL Server 2008SUSFPMU, MBSA,WSUS, ITMU, Configuration Manager 2007
Any Itanium-based versions of SQL ServerSUSFPMU, MBSA,WSUS, ITMU, Configuration Manager 2007
Any x64-based versions of SQL ServerSUSFPMU, MBSA,WSUS, ITMU, Configuration Manager 2007
Exchange
Exchange 2003MU, MBSA,WSUS, SUSFP, ITMU, Configuration Manager 2007
Exchange 2007SUSFPMU, MBSA,WSUS, ITMU, Configuration Manager 2007
Exchange 2010SUSFPMU, MBSA,WSUS, ITMU, Configuration Manager 2007
Other Products
Any Macintosh productsMU, MBSA,WSUS, SUSFP, ITMU, Configuration Manager 2007
Forefront Client Security 1.0SUSFPMU, MBSA,WSUS, ITMU, Configuration Manager 2007
Host Integration Server 2000, 2004 and 2006SUSFPMU, MBSA,WSUS, ITMU, Configuration Manager 2007
Microsoft Expression Web and Microsoft Expression Web 2SUSFPMU, MBSA,WSUS, ITMU, Configuration Manager 2007
MSN Messenger or Windows Live MessengerMU, MBSA,WSUS, SUSFP, ITMU, Configuration Manager 2007
Platform SDK: GDI+MU, MBSA,WSUS, SUSFP, ITMU, Configuration Manager 2007
Search Server 2008OU, WU, SUSFPMU, MBSA,WSUS, ITMU, Configuration Manager 2007
Visual Studio 2002 or Visual Studio 2003MU, MBSA,WSUS, ITMU, Configuration Manager 2007SUSFP
Visual Studio 2005 and 2008SUSFPMU, MBSA,WSUS, ITMU, Configuration Manager 2007
Report Viewer 2005 or Report Viewer 2008MU, MBSA,WSUS, SUSFP, ITMU, Configuration Manager 2007

Frequently asked questions

What is Microsoft doing to provide guidance about how to deploy these updates?

We encourage system administrators to join the monthly technical webcast to learn more about security updates. The webcast occurs every month. To register, visit the following Microsoft website:
http://msevents.microsoft.com (http://msevents.microsoft.com)
Search for "Security Bulletins (Level 200)" and then sort by date. These webcasts are scheduled several months in advance, so make sure that you look for the specific month and year that you want to view. 

What other information should I know about MBSA?

For more information about the programs that MBSA currently supports, visit the following Microsoft TechNet website:
http://technet.microsoft.com/en-us/security/cc184923.aspx (http://technet.microsoft.com/en-us/security/cc184923.aspx)
Can I use SMS or System Center Configuration Manager to determine whether the updates are required?

Yes. SMS helps detect and deploy these security updates. SMS 2.0 together with the SUS Feature Pack and SMS 2003 together with SUSFP use MBSA version 1.2.1 technology for detection. Therefore, SMS 2.0 together with the SUS Feature Pack and SMS 2003 together with the SUS Feature Pack have limitations that resemble the limitations of MBSA version 1.2.1.

For more information about SMS, visit the following Microsoft website:
http://go.microsoft.com/fwlink/?LinkId=21158 (http://go.microsoft.com/fwlink/?LinkId=21158)
The SUS Feature Pack together with the Extended Security Update Inventory Tool is required to detect all the security updates on Microsoft Windows and on other affected Microsoft products.

For more information about the limitations of the SUS Feature Pack, click the following article number to view the article in the Microsoft Knowledge Base:
306460  (http://kbalertz.com/Feedback.aspx?kbNumber=306460/ ) Microsoft Baseline Security Analyzer (MBSA) returns note messages for some updates
SMS 2.0 together with the SUS Feature Pack and SMS 2003 together with the SUS Feature Pack also use the Microsoft Office Inventory Tool to detect the required security updates for Microsoft Office programs such as Microsoft Word.

SMS 2003 customers can also use ITMU to detect and deploy security updates. ITMU uses technology from Microsoft Updates. For more information about ITMU, visit the following Microsoft website:
http://technet.microsoft.com/en-us/sms/bb676783.aspx (http://technet.microsoft.com/en-us/sms/bb676783.aspx)
Configuration Manager 2007 uses WSUS 3.0 for detection and deployment of these security updates. Therefore, anything that is supported by WSUS 3.0 is also supported by Configuration Manager 2007.
Note This is a "FAST PUBLISH" article created directly from within the Microsoft support organization. The information contained herein is provided as-is in response to emerging issues. As a result of the speed in making it available, the materials may include typographical errors and may be revised at any time without notice. See Terms of Use (http://go.microsoft.com/fwlink/?LinkId=151500) for other considerations.

APPLIES TO
  • Windows 7 Service Pack 1, when used with:
    • Windows 7 Enterprise
    • Windows 7 Professional
    • Windows 7 Ultimate
    • Windows 7 Home Premium
    • Windows 7 Home Basic
  • Windows 7 Enterprise
  • Windows 7 Professional
  • Windows 7 Ultimate
  • Windows 7 Home Premium
  • Windows 7 Home Basic
  • Windows Server 2008 R2 Service Pack 1, when used with:
    • Windows Server 2008 R2 Standard
    • Windows Server 2008 R2 Enterprise
    • Windows Server 2008 R2 Datacenter
  • Windows Server 2008 R2 Standard
  • Windows Server 2008 R2 Enterprise
  • Windows Server 2008 R2 Datacenter
  • Windows Server 2008 Service Pack 2, when used with:
    • Windows Server 2008 for Itanium-Based Systems
    • Windows Server 2008 Datacenter
    • Windows Server 2008 Enterprise
    • Windows Server 2008 Standard
    • Windows Web Server 2008
  • Windows Server 2008 for Itanium-Based Systems
  • Windows Server 2008 Datacenter
  • Windows Server 2008 Enterprise
  • Windows Server 2008 Standard
  • Windows Web Server 2008
  • Windows Vista Service Pack 2, when used with:
    • Windows Vista Business
    • Windows Vista Enterprise
    • Windows Vista Home Basic
    • Windows Vista Home Premium
    • Windows Vista Starter
    • Windows Vista Ultimate
    • Windows Vista Enterprise 64-bit Edition
    • Windows Vista Home Basic 64-bit Edition
    • Windows Vista Home Premium 64-bit Edition
    • Windows Vista Ultimate 64-bit Edition
    • Windows Vista Business 64-bit Edition
  • Windows Vista Service Pack 1, when used with:
    • Windows Vista Business
    • Windows Vista Enterprise
    • Windows Vista Home Basic
    • Windows Vista Home Premium
    • Windows Vista Starter
    • Windows Vista Ultimate
    • Windows Vista Enterprise 64-bit Edition
    • Windows Vista Home Basic 64-bit Edition
    • Windows Vista Home Premium 64-bit Edition
    • Windows Vista Ultimate 64-bit Edition
    • Windows Vista Business 64-bit Edition
  • Microsoft Windows Server 2003 Service Pack 2, when used with:
    • Microsoft Windows Server 2003, Standard Edition (32-bit x86)
    • Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
    • Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
    • Microsoft Windows Server 2003, Web Edition
    • Microsoft Windows Server 2003, Datacenter x64 Edition
    • Microsoft Windows Server 2003, Enterprise x64 Edition
    • Microsoft Windows Server 2003, Standard x64 Edition
    • Microsoft Windows XP Professional x64 Edition
    • Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
    • Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
  • Microsoft Windows XP Service Pack 3, when used with:
    • Microsoft Windows XP Home Edition
    • Microsoft Windows XP Professional
  • Microsoft Office Professional 2010
  • Microsoft Office Professional Plus 2010
  • Microsoft Office Standard 2010
  • Microsoft Office Professional 2007
  • Microsoft Office Professional Plus 2007
  • Microsoft Office Standard 2007
  • Microsoft Office Ultimate 2007
  • Microsoft Office 2004 for Mac Professional Edition
  • Microsoft Office 2004 for Mac Standard Edition
  • Microsoft Office 2004 for Mac Student and Teacher Edition
  • Microsoft Office X for Mac Standard Edition
  • Microsoft Office 2008 for Mac
  • Microsoft Office 2008 for Mac Home and Student Edition
  • Microsoft Office 2008 for Mac Special Media Edition
  • Microsoft Office for Mac Academic 2011
  • Microsoft Office for Mac Home and Business 2011
  • Microsoft Office for Mac Home and Business 2011 Home Use Program
  • Microsoft Office for Mac Home and Student 2011
  • Microsoft Office for Mac Standard 2011
Keywords: 
kbsccm kbhowto kbsecurity kbsecbulletin kbinfo KB961747
       

Community Feedback System

Very often, it takes hours to solve a problem. Very often, you've looked high and low, and have tried a lot of solutions. When you finally found it, chances are, it was because someone else helped you. Here's your chance to give back. Use our community feedback tool to let others know what worked for you and what didn't.

Please also understand that the community feedback system is not warranted to be correct, it's simply a system that we've built to let people try and help each other. If something in a feedback response doesn't make sense to you, or you're not comfortable making changes that the feedback talks about (like registry edits), please consult a professional.

Thank you for using kbAlertz.com Feedback System.

-- Scott Cate