Solved

How to configure a GPO that will allow the members of an OU to get Updates from the WSUS server

Posted on 2013-06-10
6
743 Views
Last Modified: 2013-06-11
I'm a member of the domain admins group in a windows 2008 R2 domain, and would like to configure a GPO so that the members of an OU receives its updates from the WSUS server. However, when I log on to the DC as the domain admin and open the group policy management console I do not see any templates related WSUS. How can I create a new GPO within the domain that is linked an OU so that the members of the OU receives their MS updates from the WSUS server?
0
Comment
Question by:cheyliger
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 81

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 400 total points
ID: 39236670
I've used this for years

wsus.bat

@============ START Script Code===========
@echo off
::
Echo Save the batch file as "WSUS.bat". This batch file will do the following:
Echo 1.    Stops the Automatic Update Service (wuauserv) service.
Echo 2.    Imports WUA settings for workstations in workgroup to detect/download/install updates from WSUS.
Echo 3.    Starts the Automatic Update Service (wuauserv) service.
Echo 4.    Force update detection.
Echo 5.    More information on http://msmvps.com/Athif
REM INSTRUCTIONS:
REM Place both the files (WSUS.reg and WSUS.bat) in same location (single folder)
REM Double-click WSUS.bat to import WSUS.reg which contains Windows Update Agent (WUA) settings. 
REM for WUA in a workgroup environment. In this sample, WSUS.reg and WSUS.bat 
REM are placed in 'c:\'.

REM Author:- Mohammed Athif Khaleel :- Date April 30, 2006
Pause
Net Stop "wuauserv"
Echo Importing WSUS.reg
%windir%\Regedit.exe /s C:\WSUS.reg
Echo WSUS.reg imported succesfully
Net Start "wuauserv" 
Echo Forcing update detection
wuauclt /detectnow
Pause

Open in new window


[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate]
"WUServer"="http://SERVER2008R2:8530"
"WUStatusServer"="http://SERVER2008R2:8530"
"TargetGroupEnabled"=dword:00000001
"TargetGroup"="IT Department"
"ElevateNonAdmins"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU]
"NoAutoUpdate"=dword:00000000
"AUOptions"=dword:00000004
"ScheduledInstallDay"=dword:00000000
"ScheduledInstallTime"=dword:0000000a
"NoAutoRebootWithLoggedOnUsers"=dword:00000001
"AutoInstallMinorUpdates"=dword:00000001
"RebootRelaunchTimeoutEnabled"=dword:00000001
"RebootRelaunchTimeout"=dword:0000003c
"RescheduleWaitTimeEnabled"=dword:00000001
"RescheduleWaitTime"=dword:0000000f
"DetectionFrequencyEnabled"=dword:00000001
"RebootWarningTimeoutEnabled"=dword:00000001
"RebootWarningTimeout"=dword:0000001e
"UseWUServer"=dword:00000001
"NoAUShutdownOption"=dword:00000000
"NoAUAsDefaultShutdownOption"=dword:00000000

Open in new window

0
 
LVL 78

Assisted Solution

by:arnold
arnold earned 100 total points
ID: 39236671
Windows update settings are under the computer configuration, administrative templates, windows components, windows update.
There is intranet URL and client target.
Which mode is your wsus setup GPO/registry or you have to move clients into their group on the WSUS?

http://technet.microsoft.com/en-us/library/cc720539(v=ws.10).aspx

I breakup the update settings
Top level define the Intranet URL

Each OU then gets the client targeting, and update settings.
0
 
LVL 81

Accepted Solution

by:
David Johnson, CD, MVP earned 400 total points
ID: 39236685
0
Ransomware: The New Cyber Threat & How to Stop It

This infographic explains ransomware, type of malware that blocks access to your files or your systems and holds them hostage until a ransom is paid. It also examines the different types of ransomware and explains what you can do to thwart this sinister online threat.  

 
LVL 47

Expert Comment

by:Donald Stewart
ID: 39237862
"How to configure a GPO that will allow the members......" ???


WSUS policies are computer based, not user based
0
 

Author Comment

by:cheyliger
ID: 39239244
Arnold, your link works fine too but Ve3ofa (link from Petri) was more concise is more relevant in windows 2008 R2. In addition I will be looking more closely at script which he also provided.
0
 
LVL 78

Expert Comment

by:arnold
ID: 39239686
A GPO sets all the parameters within the registry such that no script that modify the registry are needed and I've found that modifying registry under some circumstance prevents the application of a GPO that tries to make changes to those registry entries.
i.e. you setup a GPO to alter the intranet URL, but you previously made the registry changes to point to an intrante URL.  The one set by GPO on a system will change the next time the GPO refresh occurs. The one manually set may not change at all as it is fixed and not GPO dependent even if it references the same information as the prior version of the GPO.

As to the point assignment.  Thanks for the explanation, but none was needed. It is completely up to the asker to assign points as they determine which was helpful to them in resolving/addressing their issue.
0

Featured Post

[Webinar] Code, Load, and Grow

Managing multiple websites, servers, applications, and security on a daily basis? Join us for a webinar on May 25th to learn how to simplify administration and management of virtual hosts for IT admins, create a secure environment, and deploy code more effectively and frequently.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Back in July, I blogged about how Microsoft's new server pricing model, combined with the end of the Small Business Server package, would result in significant cost increases for many small businesses (see SBS End of Life: Microsoft Punishes Small B…
Experts-Exchange users below are the steps you can follow to upgrade your Lync server to latest CU's or cumulative updates. Note: Perform it during non-production hours.   Step 1: Backup your lync and SQL server database. Follow below article: h…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question