Deploy Windows 10 feature update to remote users - SCCM - Deployment size

n4 41 Reputation points
2021-03-02T22:32:19.277+00:00

Good Afternoon,

I have roughly 5000 remote clients due to Covid, and we need to move off Windows 10 1809 fairly soon.

I have a working deployment, but I am very concerned about how to release this to users on VPN (not always-on).

I have BITS throttling pretty aggressively, but I'm still worrying about overloading our 3 VPN pipes. We are not able to use cloud services or split tunnel VPN.

For now I'm looking at required, silent deployments to small numbers. The deployments would be time-randomized per the client setting, and install would be allowed outside the nightly maintenance window. The machine would be rebooted (the longest part) during the window.

I guess the biggest question is roughly how many clients I can deploy per day. 10? 100? 500?

Has anyone dealt with this situation? I'm looking for advice, guidelines, etc. I'm just not finding much info on how to deal with this volume.

Microsoft Security Intune Configuration Manager Updates
Microsoft Security Intune Configuration Manager Other
{count} votes

1 answer

Sort by: Most helpful
  1. n4 41 Reputation points
    2021-03-03T15:14:21.93+00:00

    Thanks for the reply!

    Getting content from MS is possible to set in the deployment, but users would have to disconnect their VPN beforehand or they would pull it through our network anyway. I might also have to change some GPO settings such as enabling Windows Update on the client. In this scenario it would have to be a user-initiated install or I would have to use a task sequence to ensure they drop their VPN. All probably possible, but I'm not super-comfortable here.

    We have 2 local WAN-connected locations (30GB pipe IIRC) where VPN's terminate and I built 2 DPs at each location. I'm in the process of setting the VPN boundaries to only talk to the DPs at their location. So maybe the DPs can take it, if we're careful? I suspect we may have to find out.

    Also MS says a 'required' deployment will use BITS to start caching the package right away. I'm not finding this to be true at all. Deployment is set to required after 7 days currently for testing. I have another test under way and will check again to make sure.

    3GB? That's not much bigger than a monthly patch load. From observation it looks closer to 7GB. If it matters we're going 1809/1909 to 20H2.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.