?
Solved

Removing Admin rights to the users laptops breaking WSUS windows updates

Posted on 2013-01-23
4
Medium Priority
?
393 Views
Last Modified: 2013-01-25
Is that a legitimate excuse not to remove admin rights to the users laptops?  My vendor does't want to do it because issues at the previous project.  It broke WSUS updates and Windows updates cannot be pushed.
Anyone saw the same issue before?
0
Comment
Question by:Tiras25
4 Comments
 
LVL 16

Accepted Solution

by:
Chris H earned 500 total points
ID: 38811702
The windows update service does not run with local user permissions on windows 7. I've seen it break on XP prior to the windows 3.1 installer needing to be installed through IE.
0
 
LVL 24

Assisted Solution

by:smckeown777
smckeown777 earned 500 total points
ID: 38811712
No...WSUS will push to a client machine, nothing to do with the user account...

What server OS are we talking about here?

SBS 2003/2008/2011 will push updates to client machines without issue regardless of the user being an admin, that's how WSUS is designed...but maybe some of the WSUS GPO settings are different/changed from the default...
0
 
LVL 57

Assisted Solution

by:Mike Kline
Mike Kline earned 500 total points
ID: 38811718
The don't need admin rights, that would be a horrible design.

In the immortal words of Joe Richards

"Please slap that consultant and say it was from me."  :)

Thanks

Mike
0
 
LVL 57

Assisted Solution

by:McKnife
McKnife earned 500 total points
ID: 38811762
> Anyone saw the same issue before?
What issue? Please describe it a little at least. "broken" is not very descriptive.
WSUS does not push, but clients pull. And yes again, the update service does not care about what group the user is in - if the update service is set to do scheduled installs.
0

Featured Post

How to Use the Help Bell

Need to boost the visibility of your question for solutions? Use the Experts Exchange Help Bell to confirm priority levels and contact subject-matter experts for question attention.  Check out this how-to article for more information.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Active Directory can easily get cluttered with unused service, user and computer accounts. In this article, I will show you the way I like to implement ADCleanup..
Unable to change the program that handles the scan event from a network attached Canon/Brother printer/scanner. This means you'll always have to choose which program handles this action, e.g. ControlCenter4 (in the case of a Brother).
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
If you’ve ever visited a web page and noticed a cool font that you really liked the look of, but couldn’t figure out which font it was so that you could use it for your own work, then this video is for you! In this Micro Tutorial, you'll learn yo…
Suggested Courses

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question