Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 221
  • Last Modified:

Group Policy and SUS

Why is it that when I specify in my Intranet  Microsoft Update service location GPO on my server that it does not show up in my local computer policy but it does in my REGISTRY?

on the server I have done the...

secedit /refreshpolicy user_policy /enforce
as well as the
secedit /refreshpolicy machine_policy /enforce

on the client I have done gpupdate and restarted.

the corect information is reflected in the REGISTRY under HKLM\software\policies\microsoft\windows\windowsupdate

I am ready to run my SUS server on my network but am unsure if this is a problem?

Please Help!!!
1 Solution
All you need to ensure is that the SUS server appears under the registry key.  After that,  the computers that will receive the updates from the SUS server, they will check in with the SUS server every 17-22 hours to see if there are any approved updates.  Check here for registry keys and settings:


A great resource for SUSserver is:  www.susserver.com

Hope this helps :)
Yeah!  On a client, go to your C:\winnt\Windows Update.log and that will tell you where your clients are pulling updates from.
zyanjAuthor Commented:
so why is this not reflected in the local computer policy i.e. NOT grayed out.

if this is the case then isn't it possible for someone to change this setting @ the client level?
Upgrade your Question Security!

Your question, your audience. Choose who sees your identity—and your question—with question security.

It should be.  Have you added the machine accounts into the OU?
zyanjAuthor Commented:

So you created an OU, moved the computer accounts into it, created a GP and installed the WUAU.adm template, and enabled 'Configure Automatic Updates' within that?
Just curious, what OS is the client?
zyanjAuthor Commented:

the clients are XP pro

buddy... it won't show in your "Local Policy"... its a separate config....

if you want to verify whether you received your Group Policy settings or not go to...

Start > Help and Support > Tools > Advanced system information > View Group Policy settings applied

Also.. if you want to see.. whether your clients are getting update from SUS server or not..

check %systemroot%\Windows Update.log

it should mention your SUS Servers entry there...


Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now