{"id":12938,"date":"2018-07-30T06:30:04","date_gmt":"2018-07-30T14:30:04","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2018\/07\/30\/news-6705\/"},"modified":"2018-07-30T06:30:04","modified_gmt":"2018-07-30T14:30:04","slug":"news-6705","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2018\/07\/30\/news-6705\/","title":{"rendered":"An open letter to Microsoft management re: Windows updating"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2017\/09\/windows_patch_security2-100734733-large.3x2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Woody Leonhard| Date: Mon, 30 Jul 2018 06:34:00 -0700<\/strong><\/p>\n<p><strong>From<\/strong><span style=\"font-weight: 400;\">: Susan Bradley<\/span><\/p>\n<p><strong>To<\/strong><span style=\"font-weight: 400;\">: <\/span><span style=\"font-weight: 400;\">Mr. Satya Nadella, Mr. Carlos Picoto and Mr. Scott Guthrie<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Dear Sirs:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Today, as Windows 10 turns three years old, I am writing to you to ensure that you are aware of the dissatisfaction your customers have with the updates released for Windows desktops and servers in recent months. The quality of updates released in the <\/span><strong><i>month of July, in particular,<\/i><\/strong><span style=\"font-weight: 400;\"> has placed customers in a quandary: install updates and face issues with applications, or don&#8217;t install updates and leave machines subject to attack.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In the month of July 2018 alone there are <\/span><a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/releasenotedetail\/1c26eff2-573f-e811-a96f-000d3a33c573\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">47 knowledge base bulletins<\/span><\/a><span style=\"font-weight: 400;\"> with known issues. Some of these were stop issues, but most concerning were the .Net side effects with <\/span><a href=\"https:\/\/blogs.msdn.microsoft.com\/dotnet\/2018\/07\/20\/advisory-on-july-2018-net-framework-updates\/\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">your own software<\/span><\/a><span style=\"font-weight: 400;\">: \u00a0SharePoint, BizTalk and even <\/span><a href=\"https:\/\/blogs.technet.microsoft.com\/exchange\/2018\/07\/16\/issue-with-july-updates-for-windows-on-an-exchange-server\/\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">Exchange<\/span><\/a><span style=\"font-weight: 400;\"> servers were impacted by these July 10<\/span><span style=\"font-weight: 400;\">\u00a0updates.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">I am a moderator on a community listserve that focuses on the topic of patch management, <\/span><a href=\"http:\/\/www.patchmanagement.org\/\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">patchmanagement.org<\/span><\/a><span style=\"font-weight: 400;\">. Recently many of the participants on the listserve have expressed their concerns and dissatisfaction with the quality of updates as well as the timing of updates.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">I recently asked the list members to answer several questions about patching on Windows 7 to Windows 10. The full results of this unscientific survey can be <\/span><a href=\"https:\/\/1drv.ms\/x\/s!Aq2UzWJDxFbHi7EulTFNCCJdjjYEng\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">read here<\/span><\/a><span style=\"font-weight: 400;\">. I urge you to take the time to read the responses. It showcases that your customers who are in charge of patching and maintaining systems are not happy with the quality of updates and the cadence of feature releases, and feel that it cannot go on as is.<\/span><\/p>\n<p><strong>Question 1<\/strong><span style=\"font-weight: 400;\"> I asked on a scale of 1 to 5, 5 being the highest, how satisfied respondents are with the quality of Windows updates in general.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Many respondents were not satisfied with Windows updating in general.<\/span><\/p>\n<p><strong>Question 2<\/strong><span style=\"font-weight: 400;\"> I asked about satisfaction with patching of Windows 10 specifically:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Many respondents were not happy with the quality of Windows 10 updates.<\/span><\/p>\n<p><strong>Question 3<\/strong><span style=\"font-weight: 400;\"> I asked if Windows 10 feature updates were useful to the respondents\u2019 business needs.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Many respondents indicated that the feature updates were either not useful at all or rarely useful to their business needs.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In <\/span><strong>Question 4<\/strong><span style=\"font-weight: 400;\">, I asked about the cadence of feature releases.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Most of the survey respondents did not want feature releases as often as they are being released now.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In <\/span><strong>Question 5<\/strong><span style=\"font-weight: 400;\"> I asked if Windows 10 is meeting respondents&#8217; business needs.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Most of the survey respondents answered that it was meeting their needs. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Finally, I asked an open-ended question as to what could be changed in Windows 10 to make it better for respondents&#8217; business. You can read the response to Question 6 <\/span><a href=\"https:\/\/1drv.ms\/x\/s!Aq2UzWJDxFbHi7EjiF2XURO7mU4KfQ\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">here<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">I also did a similar survey for consumers. The results of the survey targeted to consumers were similar to the results from the consultants and patching administrators. The majority thought that the feature updates occurred too many times during the year, and the said that they were overall not happy with the quality of updates from Microsoft. The full survey results from Microsoft consumer customers can be found <\/span><a href=\"https:\/\/1drv.ms\/x\/s!Aq2UzWJDxFbHi7Emy9VxX-Rp3B3VFg\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">here<\/span><\/a><span style=\"font-weight: 400;\">. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">I urge you to take the time to look at both the <\/span><a href=\"https:\/\/1drv.ms\/x\/s!Aq2UzWJDxFbHi7EulTFNCCJdjjYEng\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">results from patching administrators<\/span><\/a><span style=\"font-weight: 400;\">, and also <\/span><a href=\"https:\/\/1drv.ms\/x\/s!Aq2UzWJDxFbHi7Emy9VxX-Rp3B3VFg\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">consumers and home users<\/span><\/a><span style=\"font-weight: 400;\"> in detail. You will see similar trends in both surveys.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">It appears that there is a breakdown in the testing process. The Windows 10 insider process is not able to identify issues on released products. When your own products break with these releases<\/span><i><span style=\"font-weight: 400;\">, it is clear that current testing processes are not good enough<\/span><\/i><span style=\"font-weight: 400;\">. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">It is concerning when issues with Microsoft\u2019s own software releases have detrimental side effects with other Microsoft software. Case in point: the recent .<\/span><a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4346822\/high-cpu-issue-in-azure-active-directory-connect-health-for-sync\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">Net 4.7.2 and Azure AD connect that causes side effects and issues with high CPU<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">At one time you had a program called the <\/span><a href=\"https:\/\/cloudblogs.microsoft.com\/microsoftsecure\/2012\/03\/28\/software-update-validation-program-and-microsoft-malware-protection-center-establishment-twc-interactive-timeline-part-4\/\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">Security Update Validation Program<\/span><\/a><span style=\"font-weight: 400;\"> that allowed firms with special nondisclosure agreements to test security updates ahead of their release. I urge you to increase this program and include a broader testing process. While your MSRC communication says that for best practice one needs to install updates immediately, the reality is that the prudent patcher is waiting at least a week, if not more, before installing updates. I hope you find this trend as concerning and disturbing as I do.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">I am disturbed when I see users and consultants talk about taking drastic measures to take back control of updating and rebooting. Some are disabling Windows Update as a drastic measure to ensure that updates do not reboot systems when they are not wanted. It\u2019s clear that <\/span><a href=\"https:\/\/www.thurrott.com\/windows\/windows-10\/164214\/windows-10-wont-waste-time-unexpected-updates-anymore\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">your team also acknowledge<\/span><\/a><span style=\"font-weight: 400;\"> that unexpected updates are problematic. But your customers deserve better than \u201cpromising\u201d results. They deserve a stable platform that reboots only when they want it to. The operating system needs to do a better job of communicating to the end user and especially to the patching administrator when a machine will receive an update. The addition of the Windows Update for Business settings that often conflict with other group policy settings cause confusion, not clarity. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">While it\u2019s commendable that you\u2019ve listened to feedback and made changes to Windows update during these three years, the fact is that these changes in each version release have caused confusion, and in some cases behavior that was not expected at all. <\/span><a href=\"https:\/\/blogs.technet.microsoft.com\/wsus\/2017\/05\/05\/demystifying-dual-scan\/\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">Dual scan<\/span><\/a><span style=\"font-weight: 400;\"> is one such change that caused confusion, and as a side effect caused administrators to have updates installed when they did not want them. The lack of clear communication regarding update changes leads to this confusion. Administrators are having to follow various <\/span><a href=\"https:\/\/techcommunity.microsoft.com\/t5\/Windows-IT-Pro-Blog\/bg-p\/Windows10Blog\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">blogs<\/span><\/a><span style=\"font-weight: 400;\"> and <\/span><a href=\"https:\/\/blogs.windows.com\/windowsexperience\/tag\/windows-insider-program\/#2zdhKEe1O8ZWZYId.97\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">sites<\/span><\/a><span style=\"font-weight: 400;\"> and even Twitter channels to be able to understand the changes. The lack of basic documentation of Windows update error codes, the fact that it took several feature releases to make <\/span><a href=\"https:\/\/blogs.technet.microsoft.com\/charlesa_us\/2015\/08\/06\/windows-10-windowsupdate-log-and-how-to-view-it-with-powershell-or-tracefmt-exe\/\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">changes to the unreadable Windows update log<\/span><\/a><span style=\"font-weight: 400;\">, the fact that it took several feature releases before <\/span><a href=\"https:\/\/docs.microsoft.com\/en-us\/windows-hardware\/drivers\/debugger\/debugger-download-symbols\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">acknowledging the problem of symbol publishing<\/span><\/a><span style=\"font-weight: 400;\"> showcases that the changes in Windows updating have had a major impact in the servicing and handling of Windows 10. I personally know of several large enterprises that are not on the current Semi Annual channel release of 1803 and are in fact several feature releases behind. The constant change and churn is not helping firms in their deployment strategies.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Starting in January of this year with the release of Spectre\/Meltdown patches, there have been numerous instances where patching communication has been wrong, registry entries detailed in Knowledge Base articles regarding registry key application was initially incorrect and later updated, or vendor updates had to be <\/span><a href=\"https:\/\/www.theverge.com\/2018\/1\/29\/16944326\/microsoft-spectre-processor-bug-emergency-windows-update-reboot-fix\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">stopped<\/span><\/a><span style=\"font-weight: 400;\"> and in general patching communication has been lacking. We in the patching community understand that the coordination with other vendors means that this communication process was not easy, but needless to say, communication and follow-up in regards to side effects and known issues need to be faster and more communicative. On a regular basis, it is difficult to identify if there are known issues with an update and if our firms will be directly impacted. Often the patching known issues refer to <\/span><a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4338818\/windows-7-update-kb4338818\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">undefined \u201cthird-party software\u201d<\/span><\/a><span style=\"font-weight: 400;\"> and we often must ask each other in the patching community If we were impacted and what vendors we were using. Clarity in documenting known issues would be greatly appreciated.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">When one downloads a Windows 10 virtual machine in Azure and deploys it, is often built from a release from several months ago. These patching side effects we see in the traditional operating system channels, impact patching on Azure as well. Recently a RDP patch that was released in March and ultimately implemented fully in June impacted Azure virtual machines. The fact that you had to release a <\/span><a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4295591\/credssp-encryption-oracle-remediation-error-when-to-rdp-to-azure-vm\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">Knowledge Base article<\/span><\/a><span style=\"font-weight: 400;\"> to instruct customers to go around this issue showcases that delays in patching Azure, and the lack of clear patching communication causes ripple effects to your cloud platforms. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">I ask you to take time out of your very busy schedule to review these survey results and see the customer dissatisfaction. Many of your customers are not happy. We need action to fix these issues with patch quality.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">As both a user of Microsoft software and a shareholder of Microsoft, I ask that you please take this feedback as it\u2019s intended: We want Microsoft software to be such that we can indeed install all updates and patches immediately without reservation. As it stands right now, we do not trust the software and the patching quality enough to do so.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">I thank you in advance for the opportunity to share with you your customers\u2019 views. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Susan Bradley<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Moderator at Patchmanagement.org<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Writer on the topic of patches for <a href=\"https:\/\/www.askwoody.com\/2018\/an-open-letter-to-microsoft-management-re-windows-updating\/\" rel=\"noopener nofollow\" target=\"_blank\">Askwoody.com<\/a><\/span><\/p>\n<p><span style=\"font-weight: 400;\">July 29, 2018<\/span><\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3293440\/microsoft-windows\/an-open-letter-to-microsoft-management-re-windows-updating.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2017\/09\/windows_patch_security2-100734733-large.3x2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Woody Leonhard| Date: Mon, 30 Jul 2018 06:34:00 -0700<\/strong><\/p>\n<article>\n<section class=\"page\">\n<p><strong>From<\/strong><span style=\"font-weight: 400;\">: Susan Bradley<\/span><\/p>\n<p><strong>To<\/strong><span style=\"font-weight: 400;\">: <\/span><span style=\"font-weight: 400;\">Mr. Satya Nadella, Mr. Carlos Picoto and Mr. Scott Guthrie<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Dear Sirs:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Today, as Windows 10 turns three years old, I am writing to you to ensure that you are aware of the dissatisfaction your customers have with the updates released for Windows desktops and servers in recent months. The quality of updates released in the <\/span><strong><i>month of July, in particular,<\/i><\/strong><span style=\"font-weight: 400;\"> has placed customers in a quandary: install updates and face issues with applications, or don&#8217;t install updates and leave machines subject to attack.<\/span><\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3293440\/microsoft-windows\/an-open-letter-to-microsoft-management-re-windows-updating.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[714,10525],"class_list":["post-12938","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-security","tag-windows"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/12938","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=12938"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/12938\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=12938"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=12938"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=12938"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}