How can I prevent WSUS clients from being able to access Windows Update via the same WSUS GPO

I'm a member of domain administrators group in a Windows 2008 R2 domain. I've configured a GPO that directs the members of an OU to get their MS OS updates from our WSUS server. The GPO appears to be working because all members of the OU appear/have reported on WSUS server as obtaining their updates from it. However, they all still have access to windows update or microsoft update via a IE. Which settings in the GPO am I missing that will prevent the WSUS clients from going to access the web (windows updates) for OS updates?
cheyligerAsked:
Who is Participating?
 
Rsilva98Connect With a Mentor Commented:
check here
0
 
DonNetwork AdministratorCommented:
You're looking for this setting:

Remove links and access to Windows Update

If this policy setting is enabled, Automatic Updates receives updates from the WSUS server. Users who have this policy setting enabled cannot get updates from a Windows Update Web site that you have not approved. If this policy setting is not enabled, the Windows Update icon remains on the Start menu; local administrators will be able to visit the Windows Update Web site, from which they could install unapproved software. This happens even if you have specified that Automatic Updates must get approved updates from your WSUS server. In Windows Vista, this setting will gray out the Check for updates option in the Windows Update application.
0
 
cheyligerAuthor Commented:
Hi Rsilva98, thank you very much for providing that link. It was very effective in resolving the issue.
0
 
DonNetwork AdministratorCommented:
Yeah.....and My comment is the correct answer for those who dont want to read thru another link.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.