Avatar of Jenny Coulthard
Jenny CoulthardFlag for Australia asked on

Can I allow Windows update to run without giving users admin permissions and not using WSUS

Is it possible to allow users who are not members of the power users or administrators group to automatically download and schedule windows updates.  I cannot use SUS or WSUS as very limited file space on server.  These users are prevented via group policy from installing any software.
Windows XPWindows Server 2003Vulnerabilities

Avatar of undefined
Last Comment
Jenny Coulthard

8/22/2022 - Mon
ASKER CERTIFIED SOLUTION
frostsystems

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
See how we're fighting big data
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
ASKER
Jenny Coulthard

THanks forstsystems, I thought this would be the case but wanted confirmation.  Very fast response too!!
Christopher Bruder

Not to reopen the question, but you can use a GPO under the computer configuration to push the updates out and automatically install them at a certain time, then also set the GPO to reset the clients computer as long as a user is not logged in.  That is about as close as you will get.
ASKER
Jenny Coulthard

cmb991 - If I open a new question about your suggestion can we discuss further?
Your help has saved me hundreds of hours of internet surfing.
fblack61
Christopher Bruder

You don't need to open a new question, I don't care about the points.  What do you want to know, how to do it?  Or questions about it?
ASKER
Jenny Coulthard

THanks cmb991, I am intetested in how to do it, as it takes a long time to do manually.   I can get that you can configure windows updates via group policy but how do you run a GPO at a certain time.  One to turn them on and another to trun them off and how do you change a users permissions or dont permissions come into it if no user is logged on?
Christopher Bruder

Do you have a GPO in a domain environment or does each station use its individual GPO?  Like how do you manage the GPO, from a server?
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
ASKER
Jenny Coulthard

We have a GPO in a domain environment managed from a sbs2003 server.
Christopher Bruder

Computer Configuration > Administrative Templates > Windows Components > Windows Update

Select Configure Automatic Updates, and set it to enabled.

Select 'Auto download and schedule the install' if you want to schedule it to install but not reset unless no one is logged in or the user selects to reset (if required)

or

Select 'Auto download and notify for install' if you want them to install them manually and the same thing applies for resetting as above.
-----
Make sure all of your computers are in this policy, enforce the policy also.  
ASKER
Jenny Coulthard

I am confused, I know how to force the automatic udpates via group policy but  the users are logged in and dont have permissions to run the windows udpate so I dont see any benefit in setting this.
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes
Christopher Bruder

It doesn't matter if they do.  In my case, we don't allow users to install updates either, we select the updates by our WSUS and the GPO allows the computers to install the updates at 3am regardless if someone is logged in or not.  Then the GPO resets the computer once the update(s) are finished installed as long as a user isn't logged in.
ASKER
Jenny Coulthard

OK, so let me see if I have this correct.  I can use GPO to install updates at 3am and restart the computer as long as the user isnt logged in but obviously the computer has to be turned on.
ASKER
Jenny Coulthard

and this is without WSUS simply using the windows update on each pc to download critical updates.
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.