Solved

WSUS creating test group then deploying patche to others later

Posted on 2010-11-11
2
863 Views
Last Modified: 2012-08-14
I have Windows 2003 Servers and a mix of XP and Windows 7 clients.

I've just set up Wsus and want to create teh follwoing set up.
1 server, 1 XP client and 1 Win7 client get all approved updates automatically after patch tuesday. then one week later the remainder of the PCs and servers get the patchs.

as it stands I have a GPO set up as follows:
 Current Sus GPO settings for PCs
I have the following for Servers
 Current SUS GPO for Servers
I have creates an OU within teh Computers OU and placed one XP client and 1 Win7 clinet into it and teh same for teh Member Servers OU in AD.

I've then linked the PC GPO to the Test Pc OU and the Server GPO to the Test Server OU.

My understanding is then Every thursday at 17:00 my test PCs and Server will go to my sus server and download any approved updates approved for that group within SUS.

What I'm looking to do is create two more GPOs one for the remainder of my PCs and one for the remainder of my Servers that runs a week later. is it just a case of setting on up the test group for Wednesday night thus being the first to get the patches after patch tuesday and set a second GPO to schedule a download on say monday so they dont get the patches til almost a week later?

also how do you ensure that users cant keep defering reboots
0
Comment
Question by:faolchu
2 Comments
 
LVL 4

Accepted Solution

by:
Harkins earned 100 total points
ID: 34111426
Hi faolchu,
I can't see any way of achieving what you want automatically. The only way I can see you doing this is by creating groups within WSUS for your test machines and all other machines, then use client side targeting to place the computers into the respective groups.
Once you have done that, you can modify the automatic approval rule in WSUS to only approve for your test group, then, after a week has passed, you will need to manually approve the updates for all the other computers.
HTH,
Harkins
0
 

Author Closing Comment

by:faolchu
ID: 34134257
Cheers, pity there's no other way about it.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Is your Office 365 signature not working the way you want it to? Are signature updates taking up too much of your time? Let's run through the most common problems that an IT administrator can encounter when dealing with Office 365 email signatures.
Last week, our Skyport webinar on “How to secure your Active Directory” (https://www.experts-exchange.com/videos/5810/Webinar-Is-Your-Active-Directory-as-Secure-as-You-Think.html?cid=Gene_Skyport) provided 218 attendees with a step-by-step guide for…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

831 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question