Hey Joshua,
Thanks for responding, as always. I'm sure this is all obvious to you, but the new Win10 terms, tracks, and flowcharts are new to me and anything but clear compared to how easy it was to manage win7 patching. The confusing part for me is exactly what updates are considered cumulative vs feature and what exactly needs to be installed to stay current with the CBB branch and continue to receive security updates.
It seems like going from original win10 release to win10 1511 is a feature update and thus not supported by patch, correct? If that's true, it seems unfortunate as WSUS and Shavlik protect are supporting this feature update/upgrade.
"Unlike previous versions of Windows, the servicing lifetime of Current Branch or Current Branch for Business is finite. You must install new feature upgrades on machines running these branches in order to continue receiving monthly security updates." https://technet.microsoft.com/en-us/library/mt574263(v=vs.85).aspx
I have a test Win10 VM I set up (original release) with GPO set to defer updates. Via patch, I installed the latest cumulative update, CSWU-022, and remain at original windows 10 release (winver reports build 10240). So if I'm understanding you and how Microsoft CBB works, I will only continue to receive security updates on this original release win10 VM until the next 'feature' release after 1511 (they only support current release and one back for security updates, right?).
If all that is correct, the only way I will continue to receive security updates (with Symantec) is to push out 'feature' updates via software management solution. To me - that makes those feature updates actually very much 'security' updates.
We push Java via symantec's software management because we use custom deployment files not easily supported by patch - and it's very much less than ideal compared to the other apps we update via patch. I can't imagine trying to realistically use it for these very large feature updates and would likely look for another solution instead.
I hope I'm misunderstanding and you'll tell me where I'm wrong because I've been so happy with Patch thus far, I don't really want to think about moving elsewhere.
Thanks!