Need some advice setting up Windows Updates Management in Azure to manage updates for servers in our Hybrid environment.
I am looking setup Update Schedules deployments grouped by type.
For example,
Management-Windows-Servers-Monthly: this includes OnPrem and Azure Management Servers - 1st Tuesday of every month, 10PM
Print-Windows-Servers-Monthly: this includes OnPrem and Azure Print Servers - 1st Wednesday of every month, 10PM (These will exclude certain KBs)
App-Windows-Servers-Monthly: this includes OnPrem Application Servers - 1st Tuesday of every month, 10PM (These servers may be migrated to Azure in future)
I have tested managing updates for our OnPrem servers (using a function to query the imported AD group)
All seems OK and will include new servers OnPrem if they are later added to the AD Group
I am trying to setup similar for the Azure VMs.
Is it recommended to add these using group based on Tags/Resource Group or would I need a query to output these servers? Can the Deployment Schedule be updated to include more groups?
Is it best practice to keep Azure and Non-Azure servers in separate Update Deployment Schedules?
Any recommendations?