How to verify a WSUS GPO is being applied to Computers?

Hello, how can i make sure my WSUS is being applied to the computeres and not to the users?
Thanks in advanced.
ComptxAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Toni UranjekConsultant/TrainerCommented:
Hi Comptx,

WSUS GPO should be linked to an OU which contains computer accounts. Because WSUS settings are part of computer configuration they can not be applied to users. You cen use gpresult on clinet computer to check if policy is applies. You can use gpupdate /force to apply new settings immediately.

HTH

Toni
0
LateNiteRCommented:
For one.  You can not assign WSUS to Users, ONLY computers.  There are a few settings under the Users Windows Components but they only pertain to how users can interact with the Service's effects.  Not the Service itself.
0
DonNetwork AdministratorCommented:
reg query "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /s
is the fastest way
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
10 Tips to Protect Your Business from Ransomware

Did you know that ransomware is the most widespread, destructive malware in the world today? It accounts for 39% of all security breaches, with ransomware gangsters projected to make $11.5B in profits from online extortion by 2019.

DonNetwork AdministratorCommented:
Go over this guide and compare to yours
Configuring the WSUS Client by Group Policy
0
ComptxAuthor Commented:
Well, my settigs are correct according to the guide, but for some reason half my computers are not showing up on the wsus console, thats why i wanted to know if maybe i was applying the policy incorrectly.
0
DonNetwork AdministratorCommented:
You most likely have a problem with duplicate sids, which is caused by imaging.
run the .bat below on computers not showing up

%Windir%\system32\net.exe stop bits 
%Windir%\system32\net.exe stop wuauserv  
 
 
 
reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v AccountDomainSid /f
reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v PingID /f
reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v SusClientId /f
 
 
rd /s /q %windir%\softwareDistribution
 
%Windir%\system32\net.exe start bits 
%Windir%\system32\net.exe start wuauserv 
 
 
sc sdset wuauserv D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;PU)
 
 
sc sdset bits D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;PU)
 
wuauclt /resetauthorization /detectnow
 
exit /B 0 

Open in new window

0
ComptxAuthor Commented:
I have tried that command already and it didnt work, also i havent used images for my systems.
0
ComptxAuthor Commented:
Actually, the server which runs the wsus is from an image. Does that have anything to do with it?  I havent ran that command on the server itself..
0
DonNetwork AdministratorCommented:
no, that wont have any bearing. Could you post your windowsupdate.log from any client not showing up?
0
ComptxAuthor Commented:
attached is a Windowsupdate.log of a brand new PC added to the domain. Not showing up on the WSUS server like they used to before. And below is the results of the client diag program.


WSUS Client Diagnostics Tool

Checking Machine State
        Checking for admin rights to run tool . . . . . . . . . PASS
        Automatic Updates Service is running. . . . . . . . . . PASS
        Background Intelligent Transfer Service is running. . . PASS
        Wuaueng.dll version 7.2.6001.788. . . . . . . . . . . . PASS
                This version is WSUS 2.0

Checking AU Settings
        AU Option is 4: Scheduled Install . . . . . . . . . . . PASS
                Option is from Control Panel

Checking Proxy Configuration
        Checking for winhttp local machine Proxy settings . . . PASS
                Winhttp local machine access type
                        <Direct Connection>
                Winhttp local machine Proxy. . . . . . . . . .  NONE
                Winhttp local machine ProxyBypass. . . . . . .  NONE
        Checking User IE Proxy settings . . . . . . . . . . . . PASS
                User IE Proxy. . . . . . . . . . . . . . . . .  NONE
                User IE ProxyByPass. . . . . . . . . . . . . .  NONE
                User IE AutoConfig URL Proxy . . . . . . . . .  NONE
                User IE AutoDetect
                AutoDetect not in use

Checking Connection to WSUS/SUS Server
AU does not have Policy Set
AU does not have Policy Set
        UseWuServer is disabled . . . . . . . . . . . . . . . . FAIL

Press Enter to Complete
Windowsupdate.log
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2003

From novice to tech pro — start learning today.