Here I show how to use Group Policy to set Windows Update settings.
This is using Windows 2008 Active Directory.
1) Create a security group for the to place computers to be updated -
2) I've chosen to create a GPO for the settings -
3) Navigate to -
Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Updates
Configure the settings as follows -
4) Configure Automatic Updates -
I've chosen to download and install every day at 20:00.
NB : If the download source is Windows Update then this would be a daft setting as it is uncontrollable.
I'm using an internal WSUS server to control updates so this setting will only apply updates at 20:00 on the day they have been authorized for the computer.
5) Specify intranet Microsoft update service location -
The address of the WSUS instance.
6) Automatic Updates detection frequency -
Fairly self explanatory, how often to check update source.
7) Allow Automatic Updates immediate installation -
Again, self explanatory - install straight after updates?
8) Enable client-side targeting -
Specify the group created in step 1.
Showing posts with label wsus. Show all posts
Showing posts with label wsus. Show all posts
Friday, 11 June 2010
Tuesday, 23 March 2010
WSUS : Force Updates
Use this command to get all updates from the WSUS server.
Then go to Control Panel > Windows Update
wuauclt.exe /resetauthorization /detectnow
Then go to Control Panel > Windows Update
Wednesday, 16 December 2009
Bookmark : How to build and maintain a tiered WSUS infrastructure
Could have done with this a couple of months back...
How to build and maintain a tiered WSUS infrastructure
How to build and maintain a tiered WSUS infrastructure
Subscribe to:
Posts (Atom)







