まっちゃだいふくの日記

セキュリティのこと、ITの気になった記事をリンクしています。

Changes to improve security for Windows devices scanning WSUS - Microsoft Tech Community - 1645547@ HTTPなWSUSを組織内で使っている場合でユーザー設定のプロキシ経由で接続している場合は要注意

Changes to improve security for Windows devices scanning WSUS:Changes to improve security for Windows devices scanning WSUS - Microsoft Tech Community - 1645547

First, beginning with the September 2020 cumulative update, HTTP-based intranet servers will be secure by default. To ensure that your devices remain inherently secure, we are no longer allowing HTTP-based intranet servers to leverage user proxy by default to detect updates. If you have a WSUS environment not secured with TLS protocol/HTTPS and a device requires a proxy in order to successfully connect to intranet WSUS Servers—and that proxy is only configured for users (not devices)—then your software update scans against WSUS will start to fail after your device successfully takes the September 2020 cumulative update.

Changes to improve security for Windows devices scanning WSUS - Microsoft Tech Community - 1645547

f:id:ripjyr:20200909160753j:plain

Options to ensure that devices in your environment can continue to successfully scan for updates:

  • Secure your WSUS environment with TLS/SSL protocol (configure servers with HTTPS).
  • Set up system-based proxy for detecting updates if needed.
  • Enable the “Allow user proxy to be used as a fallback if detection using system proxy fails” policy.