No, they are not needed if you have the hotfix installed.
I have installed the "F-Secure Server Security Premium 12.x FSAV Hotfix"
- The new: "2019-02 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4487006)" still takes hours.
It's not fixing our problem.
Do the exclusions mentioned earlier fix it?
The new hotfix released by F-Secure on 19 February for Server Security (FSAV952-10) says it fixes the slowness during the Microsoft Patch installation.
Well it does!
On Windows 2016 servers the difference it makes is remarkable.
On some initial testing I did an install of the latest Cumulative update on two identical servers.
One server had the new patch FSAV952-10 installed.
Still to test on Window 2012 servers, but to be honest we did not experience any issues with extended patching times. All our issues were with Windows 2016 servers.
Just to add to our experience of the new 19 February patch to fix the slowness during the Microsoft Patching:-
The greatly improves installation + reboot times for Windows 2016 servers were achieved WITHOUT the needs for any special directory, file or process exclusions that have been mentioned by other contributors to this post.
I'd like to inform that same hotfix works also PSB Server Security product as there is same kind of problems with MS patches.
@Vadwhen will the hotfix be pushed to SS12 and PSB via updates?
I would like to know as well. How can we push the hotfix to hundreds of servers?
Looks like the Hotfix can be pushed out in bulk using "Policy Based Installations".
Instances created from Windows Server 2016 and later Amazon Machine Images (AMIs) use the EC2Launch service for a variety of startup tasks, including initializing EBS volumes. By default, EC2Launch does not initialize secondary volumes. You can configure EC2Launch to initialize these disks automatically. https://onlineitguru.com/aws-training.html