WSUS and seperating desktops and servers

Hi,

I was thinking of setting up a 2nd WSUS server as I want to be able to have my servers point to one and desktops another.  We struggle a bit with the WSUS view and distinguishing between servers and desktops, which patch for which, with our one WSUS server. This is probably just me! I thought that if I have desktops point at one, and servers the new WSUS server, it would be much easier.  We're not a large site and this might be a bit extravagant but we’re not too worried about “wasting” resource (bandwidth, space, etc) if that’s what the easiest and tidiest solution requires.

Ideally I want to be able to launch WSUS for desktop and only see desktop and relevant patches and launch the server instance and only servers and relevant patches.

Can I just build a separate standalone 2nd WSUS server, have this pull the patches from MS and point servers to this? Or is there a better way to do this?


Thanks
kswan_expertAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

McKnifeCommented:
"Can I just build a separate standalone 2nd WSUS server, have this pull the patches from MS and point servers to this?" - Sure you can.
"Or is there a better way to do this?" - I would not separate those. You can use groups of machines, clients and servers separated. As for updates: why would you want to separate here, do you plan not to install certain updates on servers? Again groups could be used, just set those up in WSUS.
0
Seth SimmonsSr. Systems AdministratorCommented:
instead of manually managing groups in WSUS, easier to configure your GPO to use client-side targeting and match the name with the WSUS name so the system will go into that group automatically.  just remember to configure WSUS to use that instead of the default manually managed groups.

one WSUS instance is sufficient
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Max LoiSr. System EngineerCommented:
I agree, you don't need another WSUS Server, simply use groups.
Here some useful sites where you can learn how to do:

http://www.vkernel.ro/blog/configure-wsus-to-deploy-updates-using-group-policy
http://windowsitpro.com/windows-8/group-policy-settings-wsus

Max
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Microsoft Server OS

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.