We help IT Professionals succeed at work.

WSUS and Elevate non-Admins settings

Is the setting in the WSUS GPO "Allow non-Admins to receive update notifications" setting the same as creating the following Registry Key? :

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\ElevateNonAdmins = 1(on)

Basically I am trying to allow non-Admin users to receive and install updates approved on my WSUS server that might otherwise need Admin permissions. I can't really find an answer to this question on the net.

If the GPO setting is not doing the same thing, then I need to know how to accomplish this. I tried using the GPO to set the registry key, however that key is not available in my GPO. Is there away to update that?
Comment
Watch Question

DonNetwork Administrator

Commented:
Do you have the wuau.adm  template added ?
Top Expert 2005
Commented:
WSUS uses the Automatic Update client on the workstation to run the updates in the context of the machine.  If the workstations are reporting to WSUS properly, then every 22 hours +/- they will check for updates, download them locally and run them at the time you set to be run.There really is no need for the user to be involved in the process at all. They do not see the update shield in the tray like an Admin does but this doesn't affect the fact that they patch.You can set via GPO the ability for non-admins to see the shield if you want, but it's really quite pointless - the machines will patch on schedule.
DonNetwork Administrator

Commented:
DonNetwork Administrator

Commented:

Note that the policy "Allow non-administrators to receive update notifications" is missing from the wuau.adm file that comes with WinXP SP2.  
 
To see that policy, use the wuau.adm file that the WSUS installation places in the folder %windir%\inf\ on the WSUS server.