Link to home
Start Free TrialLog in
Avatar of Graham Hirst
Graham HirstFlag for United Kingdom of Great Britain and Northern Ireland

asked on

WSUS - Remote Users

Hi Experts,

Hoping you can provide your experience here
As part of our continued improvements to our system we are reviewing our WSUS patching policy

What i am curious about is how to best handle remote user where they are out of the office most of the time

I noticed, in GPO, under specify an intranet Microsoft update service location, you can specify an alternative download server
Is it possible to reference the default public Microsoft update URL here, so that laptop users, not in the office can still obtain updates?

If not, how have people overcome this issue?

Kind Regards
Avatar of Don
Don
Flag of United States of America image

I would have a second WSUS configured to not store updates locally and point the remote clients to that.
You could also Implement an Internet-Facing WSUS

https://technet.microsoft.com/en-us/library/gg537354.aspx
ASKER CERTIFIED SOLUTION
Avatar of Don
Don
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Graham Hirst

ASKER

Cheers Don. I take it if you were to create the internet facing WSUS server, you would make it an upstream server to your internal server?
Or would you keep them completely separate?

Kind Regards
I would go with upstream, that way you don't have to deal with additional approval rules.
Cheers Don, if i make it an upstream, can i still define the externally facing server to not store the updates locally, but keep the WSUS server that's internal set to download them?
Cheers for your Help Don