Solved

WSUS Restrictions via a GPO

Posted on 2012-03-23
3
299 Views
Last Modified: 2012-04-05
I have a large AD Domain made up (mostly) of Windows based Workstations and laptops.  The OS's are a mix of Win XP and Win 7 professional editionss.  We manage our windows updates via GPO's - see attached .jpg for example of settings.  

My issue is this: WSUS works fine but I don't seem to be able to restrict users from manually accessing Windows automatic updates.  One of the issues, that I cannot change, is that all staff users (we're a school district) are local Admins on the workstations, so the setting "Allow non-administrators to receive update notifications" doesn't apply.  Is there a way that I can restrict a person's access to manually run Automatic Updates, say for example based on AD group membership, regardless of their status as a local admin?

Thanks,

Noah
WSUSGPO-example.jpg
0
Comment
Question by:nkeables
  • 2
3 Comments
 
LVL 47

Accepted Solution

by:
Donald Stewart earned 250 total points
ID: 37758739
The policy "Allow non-administrators to receive update notifications" is in order to allow normal users to install updates...disabling will also stop them from getting the "Yellow Shield" notifying that updates are available to install.

The settings you are looking for are below.


http://technet.microsoft.com/en-us/library/bb457141.aspx


Preventing Access to Windows Updates and Automatic Updates

You can use Group Policy settings to disable both Windows Update and Automatic Updates.

    To disable Windows Update and Automatic Updates on a per-computer basis, configure Turn off access to all Windows Update features in Computer Configuration\Administrative Templates\System\Internet Communication Management\Internet Communication settings. See “Turn off access to all Windows Update features,” earlier in this document.

    To disable access to Windows Update and Automatic Updates on a per-user basis, configure Remove links and access to Windows Update in User Configuration\Administrative Templates\Start Menu and Taskbar. Enabling this policy setting removes access to Windows Update features for the specified user, but Automatic Updates still checks for updates for the comp
0
 

Author Closing Comment

by:nkeables
ID: 37814297
The article you referenced provided the solution I needed.  I had configured GPO's for updating from our WSUS, but was un-aware of the setting  to turn off all windows update features.  The setting "Turn off access to all Windows Update features" was found at  Computer Configuration\Administrati<wbr />ve Templates\System\Internet Communication Management\Internet Communication settings.  This allows Automatic updates to take place but prohibits all Windows Update  web site interactions.<br /><br />Thank you
0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 37814305
Glad to help
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The System Center Operations Manager 2012, known as SCOM, is a part of the Microsoft system center product that provides the user with infrastructure monitoring and application performance monitoring. SCOM monitors:   Windows or UNIX/LinuxNetwo…
Article by: Leon
Software Metering within our group of companies has always been an afterthought until auditing of software and licensing became a pain point. Orchestrator and SCCM metering gave us the answer and it was an exciting process.
Viewers will learn the different options available in the Backstage view in Excel 2013.
The viewer will learn how to create a normally distributed random variable in Excel, use a normal distribution to simulate the return on an investment over a period of years, Create a Monte Carlo simulation using a normal random variable, and calcul…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question