Solved

Windows server update service and workstations

Posted on 2006-06-18
19
249 Views
Last Modified: 2010-04-18
I'm wondering how one configures workstations for the Windows update service when the windows update service is located on the local aera network?

I.e. I'm using wsus to download the patches, and want to configure certain workstations to have the updates downloaded from the wsus server.

Do I have to go to each workstation and make a change or is there a global policy that can be done. (I only want workstations updated, not the servers as I want to do the servers manually)

Thanks
0
Comment
Question by:john_s99
  • 7
  • 6
  • 4
19 Comments
 
LVL 51

Accepted Solution

by:
Netman66 earned 125 total points
ID: 16930342
You can create a new OU and move all the computers into it that you want to use your WSUS server (this assumes you haven't done this already).
Create a new GPO linked to this OU.
Set these settings in the GPO:

Computer Config>Admin Templates>Windows Components>Windows Update ::

> Specify intranet Microsoft update service location
> Configure Automatic updates


These are the 2 important ones.  The rest of the elements in Windows Update are to fine tune things.

0
 
LVL 51

Expert Comment

by:Netman66
ID: 16930356
Anything else you might want to know can be found here (great reference):

http://www.wsuswiki.com/

0
 
LVL 104

Assisted Solution

by:Sembee
Sembee earned 125 total points
ID: 16930809
The way that I do it is to have three group policy settings covering two OUs.

The first GP template is the base. This specifies the intranet location, detection time etc.
The second GP template is for the workstations. This sets the behaviour of automatic updates and includes a tag to sort them in to the correct group.
The third GP template is for the servers. This is linked to the domain controllers OU and a separate OU for the member servers. You have to be really careful with moving the servers around in the domain. You don't move the domain controllers unless you are really sure as that can screw things up. Similarly Exchange servers can get upset if things are moved around wrongly.

On the WSUS server, create two groups, one called Servers, one called Workstations. Set the WSUS to use group policy for sorting the machines.

What that means is you can set the workstations to install, the server to detect. Or a mix, or set the workstations to force installation, with the servers download and prompt - or a combination. You have control over what is happening, what the machines need and how it is installed, while still having the advantages of a local download point.

Simon.
0
 

Author Comment

by:john_s99
ID: 17064945

  Is there a way to force the computers to reboot after an update is done. (i.e. have the systems reboot at 3am after the update when no one is using them?)

Thanks
0
 
LVL 104

Expert Comment

by:Sembee
ID: 17064994
The group policy does that.

Simon.
0
 

Author Comment

by:john_s99
ID: 17065016
But where in GPO, as I didn't see where to set the time for reboot...
0
 
LVL 104

Expert Comment

by:Sembee
ID: 17065172
You don't set the time for the reboot, but the time for the installation. So you would set the machines to install at 3am and then reboot.

There is a setting "No Auto Restart for scheduled Automatic Update Installations". If you disable that, then the machine will restart automatically 5 minutes after the installation is complete.

Simon.
0
 

Author Comment

by:john_s99
ID: 17072300
What is strange now, is I setup the auto update at 3am but there is no status report for that time.

The only time the last status was is when I logged in as administrator and not as the user.

The updates were flagged as detect only and not install, so I changed the updates to install.

But what rights does the user need to install the updates? (power user, standard user, administrator?)

Thanks
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 
LVL 51

Expert Comment

by:Netman66
ID: 17073070
The user doesn't need any further rights.  At 3am, the updates will install and the computer will reboot - but only if the user is logged off.

A normal user will not see any update shield in the tray and should not be aware of anything that happens.

0
 
LVL 104

Expert Comment

by:Sembee
ID: 17073177
There is a setting to allow a non-administrator to install updates. If you don't enable that, then they will not see anything.

Simon.
0
 
LVL 51

Expert Comment

by:Netman66
ID: 17073200
The danger to enabling this is that if they don't choose to do the update via the shield it doesn't happen.

I would leave the default behiour as it is.

0
 

Author Comment

by:john_s99
ID: 17074849
So if a user is logged in, the updates will happen but the system won't reboot?

Also on the wsus admin page on the server, it says detect only... Do I have to change every update from detect to install? (as there are over 600+ that say detect only)

Thanks
0
 
LVL 104

Expert Comment

by:Sembee
ID: 17075463
You need to change them to install to install.
You can select them in bulk and choose Install. It will take a while to tag them all, so leave it to get one with it.

With the correct group policy settings, the updates can install automatically no matter who is logged in. If it is a normal user they will get nagged at intervals. I usually set this to every 45 minutes, although if I need the update to be applied immediately I have set it to every 5 minutes and slowly turn it down to every minute - usually with associates email messages telling the users to reboot.

Simon.
0
 

Author Comment

by:john_s99
ID: 17087305
Will WSUS do Office updates too?

Thanks
0
 
LVL 104

Expert Comment

by:Sembee
ID: 17089707
It will. It does Office 2002 and Office 2003. It has just done some updates overnight for Excel.

Simon.
0
 

Author Comment

by:john_s99
ID: 17098693
Ok, there were some updates that were done and when I went into the WSUS admin screen some said a reboot is required. (I thought the PC's rebooted automatically after the updates were done?)

These systems are Windows 2000 Professional

Thanks
0
 
LVL 104

Expert Comment

by:Sembee
ID: 17100532
The WSUS admin information is not live. It is the status when the machine last called in.
Therefore if was waiting to be rebooted last time the machine called in, that is what is would be recorded.

You can force the machine to call home with the latest update information by dropping in to a command prompt and typing

wuauclt /detectnow

You could also cut down the time between detections in the group policy. The default is 22 hours. I usually run between 3 and 6 hours.

Simon.
0

Featured Post

Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I have never ceased to be amazed how many problems you can encounter on a fresh install of a Windows operating system.  This is certainly case in point& Unable to complete ANY MSI installation.  This means Windows Updates are failing and I can't …
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.

929 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now