?
Solved

WSUS on Windows Server 2008 R2

Posted on 2011-03-12
8
Medium Priority
?
611 Views
Last Modified: 2012-05-11
I’m new to WSUS on Windows Server 2008 R2.

Can someone explain how I configure this to automatically approve all updates for client computers but not for Servers?
0
Comment
Question by:DHPBilcare
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
8 Comments
 
LVL 70

Accepted Solution

by:
KCTS earned 668 total points
ID: 35115708
Start by creating two groups - put servers in one group and clients in another http://www.wsuswiki.com/TargetGroups
0
 
LVL 42

Assisted Solution

by:kevinhsieh
kevinhsieh earned 668 total points
ID: 35116313
I don't know that you can. What I do is have target groups for my machines, but also different GPOs that have different automatic update settings for my servers and workstations. Workstations will patch every day, will only patch on weekends, and some server download only so I can control what gets installed and when.

I suppose if you really wanted to you can setup two WSUS servers with different approval policies and point your workstations to one and your servers to another.
0
 
LVL 47

Assisted Solution

by:Donald Stewart
Donald Stewart earned 664 total points
ID: 35119437
0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 

Author Comment

by:DHPBilcare
ID: 35129241
Thanks for all the comments.

One more question.  We have some validated Win2K SP4 clients that must be kept excluded from Windows updates.  What's the best way to do this?
0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 35129335
Place them in a OU that doesnt get the new WSUS gpo's you created applied to them.

Or create another GPO with a client side targeting group for these W2k clients, then in this WSUS group dont approve any win2k updates.
0
 
LVL 42

Expert Comment

by:kevinhsieh
ID: 35131012
First of all, Microsoft will never ever release another update for Windows 2000. To prevent any updates of any kind, I say that it's best to deploy a group policy to the workstations to specifically never check for updates, as opposed to just not configuring it or to use a client side target group and hope that you remember to make sure that every update is not approved for that group. The problem with that plan is that many updates are automatically approved in most deployments, and the default action for approving an update is to approve an update for all groups. It's just too easy for an administrator to approve an update for everything, and setting a setting once in a GPO to make sure that a workstation doesn't download and install updates seems much less prone to error.
0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 35131116
All you would need to do is deselect Windows 2000 from products then wsus wouldn't even synchronize or download win2k updates
0
 
LVL 42

Expert Comment

by:kevinhsieh
ID: 35131177
You could still get Office and other updates.
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Group policies can be applied selectively to specific devices with the help of groups. Utilising this, it is possible to phase-in group policies, over a period of time, by randomly adding non-members user or computers at a set interval, to a group f…
Here's a look at newsworthy articles and community happenings during the last month.
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…

650 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question