We are in the process of implementing software restrictions policies using group policy on our public computers to curb the amount of software that is installed by our patrons. We are using the "Disallowed" measure, so we must specify the paths of the approved software programs. My fear is that when we implement this, the updates that are pushed down from WSUS will not be included in this list and will not install. Do all the updates that are pushed down from the WSUS server reside in a one or more specific folder on the clients? If so, where are they located? Thanks experts for your help in advance.