I am successfully using WSUS to update our fleet.
I have an issue with the timing of the installation and reboots, particularly of Servers.
At 4am (scheduled install time) all servers download, install and reboot.
Which is what its meant to do.
The issue i have is that often the reboots happens within minutes of each other, and worse, may have all Active Directory Servers rebooting at exactly the same time, so for a few minutes there is no AD servers on the network.
I want to be able to randomise the reboots by 1 hour so that they dont all occur at exactly the same time.
I looked at the Maintenance Scheduler GPO settings which should allow randomisation, so that the Automatic Maintenance runs at 3am (plus or minus 1 hour), which should install Updates and reboot if needed. But this doesnt seem to work.
My GPO settings are as below:
Computer Configuration (Enabled)
Windows Components/Maintenance Scheduler
Automatic Maintenance Activation Boundary Enabled
Regular maintenance activation boundary 2000-01-01T03:00:00
Automatic Maintenance Random Delay Enabled
Regular maintenance random delay PT1H
Windows Components/Windows Update
Allow Automatic Updates immediate installation Enabled
Automatic Updates detection frequency Enabled
Check for updates at the following
interval (hours): 6
Configure Automatic Updates Enabled
Configure automatic updating: 4 - Auto download and schedule the install
The following settings are only required and applicable if 4 is selected.
Install during automatic maintenance Enabled
Scheduled install day: 0 - Every day
Scheduled install time: 04:00
If you have selected “4 – Auto download and schedule the install” for your scheduled install day and specified a schedule, you also have the option to limit updating to a weekly, bi-weekly or monthly occurrence, using the options below:
Every week Disabled
First week of the month Disabled
Second week of the month Disabled
Third week of the month Disabled
Fourth week of the month Disabled
Install updates for other Microsoft products Enabled
Do not include drivers with Windows Updates Enabled
Enable client-side targeting Enabled
Target group name for this computer Windows Servers
Specify active hours range for auto-restarts Enabled
Specify the max active hours range:
Max range: 18
Specify intranet Microsoft update service location Enabled
Set the intranet update service for detecting updates: http://wsus.domain.local
Set the intranet statistics server: http://wsus.domain.local
Set the alternate download server:
Download files with no Url in the metadata if alternate download server is set.
Turn off auto-restart for updates during active hours Enabled
Start: 6 AM
End: 10 PM
Turn on recommended updates via Automatic Updates Enabled
Windows Components/Windows Update/Windows Update for Business
Manage preview builds Enabled
Set the behavior for receiving preview builds: Disable preview builds
Select when Quality Updates are received Enabled
After a quality update is released, defer receiving it for this many days: 7
Which im hoping will do this:
Set the Maintenance Windows to be 3am with a Random Delay of 1hour (so hopefully the server installs the updates and reboots at a random 1 hour time, doesnt seem to work)
Install updates immediately if they dont affect the OS.
Check for updates often, every 6 hours
Download and Install the updates everyday during the Maintenance Window and also at 4am (which it does exactly at 4am, but not during Maintenance Window at 3am+-1hour)
Set Active hours to be between 6am and 10pm so no reboots occur during working hours.
Dont install Preview Builds and dont install Quality Updates immediately, wait 7 days before installing.
So what am i doing wrong as the Servers are not installing the Updates during the Maintenance Window, but is waiting until 4am and then they all reboot around the same time?