Block Windows Updates from the Internet in a Domain

Posted on 2011-04-21
Last Modified: 2012-08-14
Inside my domain I have a WSUS/SCE server that is used to deploy the updates to around 150 stations. At the same time, when I go to a station, I can see that the "Check online for updates from Microsoft Update" option is still enabled.

I know that it should be grayed as I only want to deploy the updates I want, and I dont want any user to be able to update the PC on his own.

I understand that this option is somewhere in Group Policy Options but I am having hard time finding it...

Any help is appreciated!
Question by:WINBRO
    LVL 8

    Expert Comment

    Computer configuration >Administrative Templates> Windows Components> Windows Update> Configure Automatic Updates

    LVL 47

    Accepted Solution

    This is the setting you are looking for

    Remove access to use all Windows Update features (Not related directly to WSUS)
    This setting allows you to remove access to Windows Update.

    If you enable this setting, all Windows Update features are removed. This includes blocking access to the Windows Update Web site at, from the Windows Update hyperlink on the Start menu, and also on the Tools menu in Internet Explorer. Windows automatic updating is also disabled; you will neither be notified about nor will you receive critical updates from Windows Update. This setting also prevents Device Manager from automatically installing driver updates from the Windows Update Web site.

    Supported on: At least Microsoft Windows XP Professional or Windows Server 2003 family (although this works on 2000 as well – Rob)

    ***** Rob’s notes: *****

    Found under ‘User Configuration’> ‘Administrative Templates’ > ‘Windows Update’

    This will block all access to the Windows Update site so the only location you can pull updates from is your WSUS server.

    How this relates to WSUS:

    This option will cause the option ‘restart later’ to be grayed out even if the user is a local administrator on the PC. The only way to eliminate this message is either to click ‘restart now’, or to stop the ‘Automatic Updates’ service. It is an effective way to remove the ability to defer restarts to all of your users, including administrators!

    You may end up annoying a LOT of people with this setting, so be careful!

    NOTE: This is a user-based policy.

    Featured Post

    Looking for New Ways to Advertise?

    Engage with tech pros in our community with native advertising, as a Vendor Expert, and more.

    Join & Write a Comment

    Suggested Solutions

    Lync meeting or Lync conferencing is what many organizations would like to deploy to allow them save money. But companies are now giving up for various reasons, one of which is that they cannot join external meetings (non-federated company meetings)…
    This collection of functions covers all the normal rounding methods of just about any numeric value.
    Viewers will learn how to maximize accessibility options in an Excel workbook for users with accessibility issues.
    The viewer will learn how to create a normally distributed random variable in Excel, use a normal distribution to simulate the return on an investment over a period of years, Create a Monte Carlo simulation using a normal random variable, and calcul…

    732 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    22 Experts available now in Live!

    Get 1:1 Help Now