Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Is there a way to configure GPO to disable Widows Update even though the servers are not part of the domain?

Posted on 2014-03-14
7
Medium Priority
?
269 Views
Last Modified: 2014-04-04
I've disabled Windows update on alot of our servers that are not joined to the domain. However, sometime I find that the settings have reverted back. I don't know by who. So, it would be best to just lock it down via GPO.  If this cannot be accomplished via GPO, what's the best way to lock down this setting for servers not in the domain? I do not want to go through every server and disable it.
0
Comment
Question by:5itface
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 79

Accepted Solution

by:
arnold earned 1000 total points
ID: 39929883
You can configure local using MMC and group policy object editor.

If the username you are using and password on this system, you can use MMC to remotely access those systems and configure their windows update settings within the computer configuration\administrative templates\windows components\windows update.

The files are stored in c:\windows\system32\GroupPolicy

There are different ways to accomplish this, look at powershell, vbscript, etc.
0
 

Author Comment

by:5itface
ID: 39929892
Arnold,

Can you give me step-by-step instructions on how to accomplish this? Do you have any documentation you can provide?
0
 
LVL 79

Expert Comment

by:arnold
ID: 39929916
you want manually or a powershell script?
Here is a reference to the powershell GPO cmdlet
http://technet.microsoft.com/en-us/library/ee461027.aspx

Using MMC and accessing the systems remotely
http://technet.microsoft.com/en-us/library/cc731745.aspx
when you add the snap-in, you will be prompted whether to use the local system or you can connect to a remote one.  NOTE: the credentials with which you are logged in, have to have rights on the remote system. i.e. you are logged in as someuser with somepassword.  This same username with the exact same password must exist on the other system with requisite rights, or you will get an access denied message.
0
Supports up to 4K resolution!

The VS192 2-Port 4K DisplayPort Splitter is perfect for anyone who needs to send one source of DisplayPort high definition video to two or four DisplayPort displays. The VS192 can split and also expand DisplayPort audio/video signal on two or four DisplayPort monitors.

 
LVL 79

Expert Comment

by:arnold
ID: 39929949
The simpler route (NOTE TEST IT FIRST)
On one of the computers, edit the policy using MMC group policy object editor

Then copy the data from c:\windows\system32\GroupPolicy to the other system.
Check whether this does what you are looking for.  Some/Several GPO Settings are registry entries.
psexec is one way to have them imported.

MMC remoting into each system might be the simpler and doable right away.
0
 
LVL 59

Expert Comment

by:Cliff Galiher
ID: 39930351
The acronym GPO stands for group policy object. And as the name implies, it is an active directory object. You cannot use GPOs outside of AD, hence non-domain joined machines do not get GPOs.

Now windows ALSO has the concept of a local security policy. But as ITS name implies, it isn't a full group policy. It is inky a subset of the security settings, of which windows update is not a part.

So no, there is no good automated way to lock down WU settings in box. Even scripting and remote operations cannot guarantee effective state because the machines are not domain joined and therefore the access not guarantees. You are looking at domain joining or 3rd-party tools.
0
 
LVL 79

Expert Comment

by:arnold
ID: 39930388
Cliff,
windows update is configurable via the Local Group POlicy object editor in the same place where it exists computer configurations\administrative templates\windows components\windows update.

Not sure whether your statement is based on versions prior to XP, but ........
0
 
LVL 56

Expert Comment

by:McKnife
ID: 39931338
Your problem is not how to disable windows update but how to manage servers that are not joined to a domain. You would like to deactivate the service and make sure it stays like this.

With the product intune, MS has provided control for non-domain-joined machines. But if you have a domain, why not use it, there is no drawback at all. So I would stop right here until you clarify why you don't join them.

But to give you a preview on options you have without a domain and without intune: you could establish a startup script on each machine that calls a centrally managed batch or whatever script, so you would only need to tune that single script.
But: once you would have to visit each machine, that's for sure.

With that script, you could use sc.exe for example to set the startup type of windows update to disabled.
0

Featured Post

Plug and play, no additional software required!

The ATEN UE3310 USB3.1 Gen1 Extender Cable allows users to extend the distance between the computer and USB devices up to 10 m (33 ft). The UE3310 is a high-quality, cost-effective solution for professional environments such as hospitals, factories and business facilities.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
Container Orchestration platforms empower organizations to scale their apps at an exceptional rate. This is the reason numerous innovation-driven companies are moving apps to an appropriated datacenter wide platform that empowers them to scale at a …
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
Want to learn how to record your desktop screen without having to use an outside camera. Click on this video and learn how to use the cool google extension called "Screencastify"! Step 1: Open a new google tab Step 2: Go to the left hand upper corn…

671 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question