Solved

Turn off Automatic Approval on WSUS

Posted on 2016-09-14
6
99 Views
Last Modified: 2016-09-16
Hello,
I  just installed a Server 2012 R2 machine and installed WSUS.  In the past, I know it was setup for automatic approvals, and it would blast down updates to the computers without any interaction.  I've had to do something to stop this from happening, but I can't remember where this setting is located.
Does anyone happen to know where I set that in WSUS?

Thank you in advance!
0
Comment
Question by:zito2000
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 17

Accepted Solution

by:
pjam earned 250 total points
ID: 41798795
You will need to go into Update Services\Options and edit Automatic Approvals:
WSUS auto approve
0
 
LVL 2

Assisted Solution

by:Brad99
Brad99 earned 250 total points
ID: 41798813
Hi,
check this good doc from MS -> https://technet.microsoft.com/de-de/library/cc708458(v=ws.10).aspx

It describes in detail options like "Automatically Approve Updates for Installation" and others.

To automatically approve updates installation

    On the WSUS console toolbar, click Options, and then click Automatic Approval Options.

    In Updates, under Approve for Installation, select the Automatically approve updates for installation by using the following rule check box (if it is not already selected).

    If you want to specify update classifications to automatically approve during synchronization, do the following:
        Next to Classifications, click Add/Remove Classifications.

        In the Add/Remove Classifications dialog box, select the update classifications that you want to automatically approve, and then click OK.

    If you want to specify the computer groups for which to automatically approve updates during synchronization:
        Next to Computer groups, click Add/Remove Computer Groups.

        In the Add/Remove Computer Groups dialog box, select the computer groups for which you want to automatically approve updates, and then click OK.

    Under Tasks, click Save settings, and then click OK.

BR
0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 41800123
Unchecking the "Auto Approve" within WSUS isn't going to have an effect on the updates that are already approved.

What exactly is your issue with computers installing all their updates??
0
Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

 
LVL 47

Expert Comment

by:Donald Stewart
ID: 41800128
The setting that you're probably referring to is

"4 - Auto download and schedule the install"

https://support.microsoft.com/en-us/kb/328010
0
 

Author Closing Comment

by:zito2000
ID: 41801604
Thank you both for your help.
0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 41801667
Again "Unchecking" that option isn't going to change the fact that all previously approved updates are still approved.
0

Featured Post

Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Every now and then, Microsoft does something that totally impresses me. It doesn't happen often, but in this case I must say I am thoroughly impressed with Windows Server Backup. One of the long time issues with Windows Backup has been the ability t…
The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
This tutorial will walk an individual through the process of installing the necessary services and then configuring a Windows Server 2012 system as an iSCSI target. To install the necessary roles, go to Server Manager, and select Add Roles and Featu…
This tutorial will walk an individual through the process of installing of Data Protection Manager on a server running Windows Server 2012 R2, including the prerequisites. Microsoft .Net 3.5 is required. To install this feature, go to Server Manager…

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question