Solved

Is there a way to configure GPO to disable Widows Update even though the servers are not part of the domain?

Posted on 2014-03-14
7
262 Views
Last Modified: 2014-04-04
I've disabled Windows update on alot of our servers that are not joined to the domain. However, sometime I find that the settings have reverted back. I don't know by who. So, it would be best to just lock it down via GPO.  If this cannot be accomplished via GPO, what's the best way to lock down this setting for servers not in the domain? I do not want to go through every server and disable it.
0
Comment
Question by:5itface
7 Comments
 
LVL 77

Accepted Solution

by:
arnold earned 500 total points
ID: 39929883
You can configure local using MMC and group policy object editor.

If the username you are using and password on this system, you can use MMC to remotely access those systems and configure their windows update settings within the computer configuration\administrative templates\windows components\windows update.

The files are stored in c:\windows\system32\GroupPolicy

There are different ways to accomplish this, look at powershell, vbscript, etc.
0
 

Author Comment

by:5itface
ID: 39929892
Arnold,

Can you give me step-by-step instructions on how to accomplish this? Do you have any documentation you can provide?
0
 
LVL 77

Expert Comment

by:arnold
ID: 39929916
you want manually or a powershell script?
Here is a reference to the powershell GPO cmdlet
http://technet.microsoft.com/en-us/library/ee461027.aspx

Using MMC and accessing the systems remotely
http://technet.microsoft.com/en-us/library/cc731745.aspx
when you add the snap-in, you will be prompted whether to use the local system or you can connect to a remote one.  NOTE: the credentials with which you are logged in, have to have rights on the remote system. i.e. you are logged in as someuser with somepassword.  This same username with the exact same password must exist on the other system with requisite rights, or you will get an access denied message.
0
Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

 
LVL 77

Expert Comment

by:arnold
ID: 39929949
The simpler route (NOTE TEST IT FIRST)
On one of the computers, edit the policy using MMC group policy object editor

Then copy the data from c:\windows\system32\GroupPolicy to the other system.
Check whether this does what you are looking for.  Some/Several GPO Settings are registry entries.
psexec is one way to have them imported.

MMC remoting into each system might be the simpler and doable right away.
0
 
LVL 56

Expert Comment

by:Cliff Galiher
ID: 39930351
The acronym GPO stands for group policy object. And as the name implies, it is an active directory object. You cannot use GPOs outside of AD, hence non-domain joined machines do not get GPOs.

Now windows ALSO has the concept of a local security policy. But as ITS name implies, it isn't a full group policy. It is inky a subset of the security settings, of which windows update is not a part.

So no, there is no good automated way to lock down WU settings in box. Even scripting and remote operations cannot guarantee effective state because the machines are not domain joined and therefore the access not guarantees. You are looking at domain joining or 3rd-party tools.
0
 
LVL 77

Expert Comment

by:arnold
ID: 39930388
Cliff,
windows update is configurable via the Local Group POlicy object editor in the same place where it exists computer configurations\administrative templates\windows components\windows update.

Not sure whether your statement is based on versions prior to XP, but ........
0
 
LVL 53

Expert Comment

by:McKnife
ID: 39931338
Your problem is not how to disable windows update but how to manage servers that are not joined to a domain. You would like to deactivate the service and make sure it stays like this.

With the product intune, MS has provided control for non-domain-joined machines. But if you have a domain, why not use it, there is no drawback at all. So I would stop right here until you clarify why you don't join them.

But to give you a preview on options you have without a domain and without intune: you could establish a startup script on each machine that calls a centrally managed batch or whatever script, so you would only need to tune that single script.
But: once you would have to visit each machine, that's for sure.

With that script, you could use sc.exe for example to set the startup type of windows update to disabled.
0

Featured Post

Network it in WD Red

There's an industry-leading WD Red drive for every compatible NAS system to help fulfill your data storage needs. With drives up to 8TB, WD Red offers a wide array of solutions for customers looking to build the biggest, best-performing NAS storage solution.  

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Article by: btan
The intent is not to repeat what many has know about Ransomware but more to join its dots of what is it, who are the victims, why it exists, when and how we respond on infection. Lastly, sum up in a glance to share such information with more to help…
Security measures require Windows be logged in using Standard User login (not Administrator).  Yet, sometimes an application has to be run “As Administrator” from a Standard User login.  This paper describes how to create a shortcut icon to launch a…
This tutorial gives a high-level tour of the interface of Marketo (a marketing automation tool to help businesses track and engage prospective customers and drive them to purchase). You will see the main areas including Marketing Activities, Design …
With the power of JIRA, there's an unlimited number of ways you can customize it, use it and benefit from it. With that in mind, there's bound to be things that I wasn't able to cover in this course. With this summary we'll look at some places to go…

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now