Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

WSUS removal in SBS 2008 and now cant do windows update

Posted on 2012-12-20
6
Medium Priority
?
1,022 Views
Last Modified: 2013-01-05
Hi, I just took over a SBS2008 server and the previous admin had removed WSUS from it (not appearing on the add remove programs list) as it was taking up to much space on the server.

However since then none of the client pcs nor the server can check for updates.  Also if we try to check manually for updates it wont let us install. says error 80072EFD  Windows encountered a unknown error

Also when doing a manual update, the systems still say that the windows updates are managed by system administrator.

Any help ?
0
Comment
Question by:c45
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 8

Expert Comment

by:teomcam
ID: 38711573
Hi,

Yes that is quite normal because after removal they must forget to default the Group Policies related to this.
Please open Group Policy Management console and navigate to Computer Configuration-Administartive Templates-Windows Components/Windows Updates-Policy and set the followigns to DEFAULT

1-Specify intranet Microsoft update service location
2-Set the intranet update service for detecting updates
3-Set the intranet statistics server
4-Check for updates at the following interval (hours):  20

Also there might be some special policies such as when updates will be checked, update installation automatic or manual etc.
0
 

Author Comment

by:c45
ID: 38714998
sorry for the delayed response.  When i open the GPM all i see is

Forest
and the domain

Sorry a bit lost here
gpm.png
0
 
LVL 23

Accepted Solution

by:
yo_bee earned 2000 total points
ID: 38746746
I guess this was neglected by the helper.
 
From your image you will need to expand the Domain Node and locate the GPO that has the settings.  
It is a computer configuration GPO so you are looking for a GPO linked to the OU with the Computers and/or  Servers.

If you want to take a screenshot the Domain Node expanded maybe the naming convention the previous ADMIN can be isolated with this setting we are looking for.
 
GPO1GPO2GPO3
Change all settings to Not configured.

To try and test without making any changes I recommend creating a completely new OU with Blocked GP Inheritance.

Open ADUC (Active Directory Users & Computers MMC)
Right click on the Domain and select New
aduc1
Name it (example: Sterile)
Then move one of your workstations into this OU for testing
aduc2
aduc3
Then Open GPMC again and block inheritance.
Locate the OU just created > Right click on it and select Block Inheritance.

gpo4gpo5
Once you have done this run GPUPDATE /FORCE on the computer that you moved into the Sterile OU > Restart.

Next you want to confirm that there are no setting of the old Link GPO still set.

Open the Registry to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate

Make sure you do not see any values pointing to local server like https://SBS2008:8530 or Target Group.

You may need to run Windows System Readiness Tool as well at the end of this.
Make sure you run the proper flavor of the tool

http://www.microsoft.com/en-us/download/details.aspx?id=3132 (32Bit)
http://www.microsoft.com/en-us/download/details.aspx?id=20858(64Bit)
0
 
LVL 35

Expert Comment

by:Cris Hanna
ID: 38747183
While the question has an accepted answer I'm still going to chime in.  Why not simply repair WSUS and use it as designed on SBS?  http://technet.microsoft.com/en-us/library/dd443475(v=ws.10).aspx

Probably the easiest repair process in all of SBS.
0

Featured Post

Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many admins will agree: WSUS is is a nice invention but using it on the client side when updating a newly installed computer is still time consuming as you have to do several reboots and furthermore, the procedure of installing updates, rebooting an…
You may have discovered the 'Compatibility View Settings' workaround for making your SBS 2008 Remote Web Workplace 'connect to a computer' section stops 'working around' after a Windows 10 client upgrade.  That can be fixed so it 'works around' agai…
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …

670 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question