Skip to main content
Question

Best practice for OS patches on Mac OS

  • July 25, 2017
  • 3 replies
  • 14 views

flamingo
Forum|alt.badge.img+4

Hey All,

Would it be best to create a smart group to find versions of Mac OS lower than what our company wants to allow. Then push the OS patch/update out to that smart group?

Just trying to take the best possible course of action.

Cheers!

3 replies

Forum|alt.badge.img+5
  • Contributor
  • July 30, 2017

Unless you want to individually manage each update (using something like Reposado), go the simple route and enable the software update policy w/ reboot if needed enabled and a restart message. Alternatively, deploy Munki in software-update only mode. There is a section on the Munki wiki called "Using the Munki tools only to install Apple Software Updates".


Forum|alt.badge.img+13
  • Honored Contributor
  • July 30, 2017

As mentioned by @mrben , I use Reposado with ReposadoAutopromote and Munki to automate things. You might also want to keep an eye on Caching Server, once it gets sorted


Forum|alt.badge.img+16
  • Valued Contributor
  • July 31, 2017

We have:
Internal Software Update Server to allow you to control release, machines set to auto update after hours from that server.
Smart groups for machines more than 1 spot update out of date that manually applies combo update to the bring up to the latest version.