Question
How do we automatically update all of our Microsoft* Windows* XP x86 machines to Service Pack 3?
Answer
A Managed Software Delivery policy can be created to automatically determine whether a machine needs to be upgraded to Service Pack 3. These steps describe how to create a Managed Software Delivery policy for the English version of Windows XP.
Open your Symantec Management web console
Open the menu Manage > Software
Expand the tree to Software > Software Catalog > Deliverable Software
Click the Add button and select Service Pack from the drop down menu
On the Package tab there are two components that need to be configured. The Package definition and the command line to execute.
To configure the Package Definition:
To configure the command line:
On the rules tab select the appropriate Detection and Applicability rules*
Configure the following associations on the associations tab.
Pull down the Association Type drop down menu and select Supersedes
Click on the Manage > Policies menu
Expand the tree to Policies > Software > All Managed Software Delivery
Under the Software tab click the Add > Software Resource option
Within this section we need to add the Software Package and specify how the package will be displayed and executed.
Use the Deliverable Software option from the Group drop down menu and the Search dialogue to the list Service Pack package created in Part 1.
Select the "Windows XP Service Pack 3" and click the OK button.
Ensure that the Compliance Settings > Perform software compliance check using: is enabled.
The rule will be automatically selected based upon the Software Package dependency rules.
The Automatically upgrade software that has been superseded by this software can be selected if required.
Click the Advance options button.
Select the Run tab. Configure the execution environment to ensure that the program can execute successfully.
Setting the Run As option is set to use the Altiris Agent credential will function within most environments.
Configure the Prompt user before running option if required.
Select the Results-based actions tab.
Configure the correct action to take after a successful installation. Because this is installing a service pack it is recommended to select Upon Success: Restart Computer
Configure a target filter set consisting of:
All computer Resources;
Excluding all computers not in filter "All Windows XP Computers"
Excluding all computers in filter "Windows x64"
Configure a schedule that runs against the Agent time. This would usually be similar to your Maintenance Windows.
Set "During window, check every:" = 4 hours**
Set Remediation as per your requirement. This will be either Immediately OR At next maintenance window.
* The detection and applicability rules referenced within this article are only available within your browser after running a Patch Management Import.
** The repeat interval should NOT be less than the minimum amount of time it takes to install the service pack on the slowest machine in the environment.