Solved

Is there a way to configure GPO to disable Widows Update even though the servers are not part of the domain?

Posted on 2014-03-14
7
261 Views
Last Modified: 2014-04-04
I've disabled Windows update on alot of our servers that are not joined to the domain. However, sometime I find that the settings have reverted back. I don't know by who. So, it would be best to just lock it down via GPO.  If this cannot be accomplished via GPO, what's the best way to lock down this setting for servers not in the domain? I do not want to go through every server and disable it.
0
Comment
Question by:5itface
7 Comments
 
LVL 76

Accepted Solution

by:
arnold earned 500 total points
ID: 39929883
You can configure local using MMC and group policy object editor.

If the username you are using and password on this system, you can use MMC to remotely access those systems and configure their windows update settings within the computer configuration\administrative templates\windows components\windows update.

The files are stored in c:\windows\system32\GroupPolicy

There are different ways to accomplish this, look at powershell, vbscript, etc.
0
 

Author Comment

by:5itface
ID: 39929892
Arnold,

Can you give me step-by-step instructions on how to accomplish this? Do you have any documentation you can provide?
0
 
LVL 76

Expert Comment

by:arnold
ID: 39929916
you want manually or a powershell script?
Here is a reference to the powershell GPO cmdlet
http://technet.microsoft.com/en-us/library/ee461027.aspx

Using MMC and accessing the systems remotely
http://technet.microsoft.com/en-us/library/cc731745.aspx
when you add the snap-in, you will be prompted whether to use the local system or you can connect to a remote one.  NOTE: the credentials with which you are logged in, have to have rights on the remote system. i.e. you are logged in as someuser with somepassword.  This same username with the exact same password must exist on the other system with requisite rights, or you will get an access denied message.
0
IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

 
LVL 76

Expert Comment

by:arnold
ID: 39929949
The simpler route (NOTE TEST IT FIRST)
On one of the computers, edit the policy using MMC group policy object editor

Then copy the data from c:\windows\system32\GroupPolicy to the other system.
Check whether this does what you are looking for.  Some/Several GPO Settings are registry entries.
psexec is one way to have them imported.

MMC remoting into each system might be the simpler and doable right away.
0
 
LVL 56

Expert Comment

by:Cliff Galiher
ID: 39930351
The acronym GPO stands for group policy object. And as the name implies, it is an active directory object. You cannot use GPOs outside of AD, hence non-domain joined machines do not get GPOs.

Now windows ALSO has the concept of a local security policy. But as ITS name implies, it isn't a full group policy. It is inky a subset of the security settings, of which windows update is not a part.

So no, there is no good automated way to lock down WU settings in box. Even scripting and remote operations cannot guarantee effective state because the machines are not domain joined and therefore the access not guarantees. You are looking at domain joining or 3rd-party tools.
0
 
LVL 76

Expert Comment

by:arnold
ID: 39930388
Cliff,
windows update is configurable via the Local Group POlicy object editor in the same place where it exists computer configurations\administrative templates\windows components\windows update.

Not sure whether your statement is based on versions prior to XP, but ........
0
 
LVL 53

Expert Comment

by:McKnife
ID: 39931338
Your problem is not how to disable windows update but how to manage servers that are not joined to a domain. You would like to deactivate the service and make sure it stays like this.

With the product intune, MS has provided control for non-domain-joined machines. But if you have a domain, why not use it, there is no drawback at all. So I would stop right here until you clarify why you don't join them.

But to give you a preview on options you have without a domain and without intune: you could establish a startup script on each machine that calls a centrally managed batch or whatever script, so you would only need to tune that single script.
But: once you would have to visit each machine, that's for sure.

With that script, you could use sc.exe for example to set the startup type of windows update to disabled.
0

Featured Post

New My Cloud Pro Series - organize everything!

With space to keep virtually everything, the My Cloud Pro Series offers your team the network storage to edit, save and share production files from anywhere with an internet connection. Compatible with both Mac and PC, you're able to protect your content regardless of OS.

Join & Write a Comment

Know what services you can and cannot, should and should not combine on your server.
OfficeMate Freezes on login or does not load after login credentials are input.
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now