-
Group B and Patch blocklists
Good question from L:
I’m in Group B and I’d like to ask a question about something I’ve been confused about ever since you posted it about a year ago. Back on March 11, 2016, you posted an article titled “Bad Patch Lists”, and in that article, you said “In the future, only install security patches for Win7 and 8.1. Don’t install optional patches.” My question is this: what about patches that Microsoft lists as “important” (but are not described as security patches)? These “Important” patches don’t fit into either the “optional” category nor the “security” category. For the past year since you published that, I’ve been unchecking the boxes for those “important” ones, so as to err on the safe side and not install them. Every month there’s about 4 or 5 of them that I uncheck in this fashion, but I always scratch my head and wonder whether I should have installed them. And again this month, I don’t see them listed in the Step B5 of your article, which is titled “Step B5: Get rid of problematic updates”. So can you tell me, should I install those ones that are described by Microsoft as “important” (but not described as “security” nor as “optional”)?
Recall that March 11, 2016 was before the patchocalypse – there was no Group A or Group B at that time.
The best approach is to follow the exact instructions that I give every month. For example, at the end of March I posted these directions.
In broad terms, I have folks in Group A – the ones who don’t mind the snooping – install Recommended updates; while I have those in Group B skip the Recommended updates.
The most important part: If you see something that’s checked, don’t uncheck it unless the instructions specifically tell you to uncheck. If you see something that’s unchecked, don’t check it, unless there are specific instructions to the contrary.
If you see an “Important” update that isn’t checked, don’t check it – regardless of whether you find reference to it somewhere in the documentation as security or optional.