I'm a member of domain administrators group in a Windows 2008 R2 domain. I've configured a GPO that directs the members of an OU to get their MS OS updates from our WSUS server. The GPO appears to be working because all members of the OU appear/have reported on WSUS server as obtaining their updates from it. However, they all still have access to windows update or microsoft update via a IE. Which settings in the GPO am I missing that will prevent the WSUS clients from going to access the web (windows updates) for OS updates?