Force update of Advanced Threat Analytics (ATA) on Windows Server 2016

When there is an update available for ATA you will get a blue arrow notification in the portal. Hovering with the mouse pointer over the icon will show what’s new in the available update:

clip_image002

The update notification tells you to go to Windows Update on the machine running the ATA Center. But when you check for updates, there are none available:

clip_image003

What is going on here?

It is because ATA updates are technically not classified as Recommended updates. There are a lot of extra hoops and requirements to get this classification (since everyone will get them). Using Optional is more flexible.

On Windows Server 2016 there is no obvious way to look for Optional updates, like there is on Windows Server 2012 R2 and earlier:

clip_image005

But you can use a tool that normally is used to configure Core installations called sconfig.

On the ATA Center, running on Windows Server 2016, run sconfig:

clip_image006

Select option 6 (Download and Install Updates):

clip_image007

You will be asked if you want to search for All or Recommended updates only:

clip_image008

Note that if you chose Recommended here, you will get the same result as in the normal settings interface:

clip_image010

If you instead chose All updates, you will find the ATA update (and any other Optional Updates):

clip_image012

I do not want to install Silverlight, so I chose to Select a single update and chose the number of the ATA update:

clip_image014

After a while, the installation wizard of the ATA update will start:

clip_image015

After you finish the installation you will see the installation result:

clip_image017

When you now go to the ATA Portal you will see that the update notification is gone:

clip_image018

The ATA gateways might be automatically updated now, depending on how you have configured updates in ATA:

clip_image020

You will have health alerts as long as the gateways are not updated:

clip_image022

I hope this blog post helped someone.

About Tom Aafloen

IT Security Advisor @ Onevinn
This entry was posted in ATA, Updates and tagged , , , . Bookmark the permalink.

1 Response to Force update of Advanced Threat Analytics (ATA) on Windows Server 2016

  1. Alex says:

    You Are Great. Thanks

Leave a comment