Windows Update Group Policy for DC and SBS Servers

Posted on 2008-10-02
Last Modified: 2012-05-05

I am trying to confirm that what I am doing is correct and if not to ask for some direction.

The default domain policy says that all systems are to update windows and install automatically. This includes the DC and servers. I don't want this for obvious reasons. I want to be able to download but wait for manual installation on the DC and Servers.

To set this up, I did a Block Inheritance at the Domain Controllers and SBSServers OU's and configured their respective poilicies accordingly.
Is this correct?

Thanks in advance.
Question by:cepolly
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
LVL 70

Assisted Solution

KCTS earned 100 total points
ID: 22626056
If you do this it will Block ALL policies except those applied directly to the OUs in question - if that what you want then its fine.

Author Comment

ID: 22626080
Yes it is. We don't have too many policies that we have implemented.

However, you bring up a good point.
Are there policies inherent to SBS 2003 that I may be blocking inadvertantly?

LVL 18

Assisted Solution

sk_raja_raja earned 400 total points
ID: 22626173
when i have this same issue,

1.Block inheritance on the DC and server OU and this will block all the policies
2.Create a new policy for updates and link to the DC ans erver OU's
3.Then again link the other policies you need to apply to these ou's

I would suggest linking the GP's is the best way to do this.

Migrating Your Company's PCs

To keep pace with competitors, businesses must keep employees productive, and that means providing them with the latest technology. This document provides the tips and tricks you need to help you migrate an outdated PC fleet to new desktops, laptops, and tablets.

LVL 18

Assisted Solution

sk_raja_raja earned 400 total points
ID: 22626199
in simple you can link the GP's anywhere in the OU...even if you specify block inheritance and say for example it is going to block GP1 and GP2.... then still you can link the GP2 on the same ou and this policy will be applied.

Other workaround you can try is,create a new update policy with settings and link it to the dc and server ou and the enforce the newly create policy....this will work only if your parent policy from top is not enforced.....

Author Comment

ID: 22626346
Looks like the linking was the problem. As soon as I removed the linkage, the policies took.

Now if I relink, will I lose the settings that I want? Will the newly link GPO take precedence?
LVL 18

Accepted Solution

sk_raja_raja earned 400 total points
ID: 22626407
i dont understand your query..can you be more clear.

just relink the policy and dont enforce
link the newly link gpo and enforce it

hence the settings on the new gp will take precedence....

Author Comment

ID: 22626441
You didn't understand what I said exactly but you answered it. :-)

I understand. Thanks for the help.


Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Windows Server Backup - behind the scenes management algorithm 8 124
Multiple Open Excel Spreadsheets 12 66
ticket bloat 3 82
AD account Auto logoff 1 58
I've often see, or have been asked, the question about the difference between the Exchange 2010 SP1 version, available as part of Small Business Server (SBS) 2011, and the “normal” Exchange 2010 SP1 Standard. The answer to the question is relativ…
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question