Avatar of Hiep Nguyen
Hiep Nguyen
 asked on

GPO server 2016

How do I use GPO to control Windows Updates with the following specs?
Download only and allow administrator install manually.  No user allows to install.

My current config. showed below.  But when login as administrator, "Install Now" button is grayed out.  What policy I need to change so that only admin. can install updates?
Screenshot_1.png
Thank you
Remote AccessMicrosoft Server OSActive Directory

Avatar of undefined
Last Comment
Hiep Nguyen

8/22/2022 - Mon
Paul MacDonald

"But when login as administrator"
Local Administrator or Domain Administrator?  Because Domain Administrators are generally immune to Group Policies.

Regardless, just add Domain Admins to the policy and explicitly deny them permission to read the policy, that will block it from applying to them.
Hiep Nguyen

ASKER
"Install Now" button grayed out for both local & domain\administrator.
McKnife

If you deny read for dom. admins, the policy will no longer be configurable by domain admins. Don't!
If you wanted to exclude someone, just remove the "apply GPo" permission.

It's worth noting, that "Domain Administrators are NOT generally immune to Group Policies." - Paul, where did that idea come from?
Your help has saved me hundreds of hours of internet surfing.
fblack61
Hiep Nguyen

ASKER
Thanks.  I don't plan to do that.  I'm looking for a policy that allows only administrator to install updates, not user.  There must be a way to accomplish this goal.
Paul MacDonald

"where did that idea come from"
I was a Microsoft Certified Trainer.  

Users in the Domain Admins can be restricted by membership in other groups (like Domain Users), but a user whose group membership is only Domain Admins will be largely unfettered by Group Policies.

You're right that they've added the "Apply GPO" permission, which I'd forgotten.  I've not tested it, but I would be surprised if it were possible for a Domain Admin to lock themselves out of a Group Policy, regardless of what permissions are set on the object.

Hiep Nguyen

ASKER
In RDS environment, how do you limit Windows Updates only to local/server administrator?  I'm trying to prevent users from install Windows updates.  Is that possible?
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
McKnife

You should remember that Computer Configuration GPOs just as the one you display, are not caring who is logged on, so "Remove access to all windows update features" will apply to administrators as well. Remove that setting.
Hiep Nguyen

ASKER
I removed it, but now everyone can install Windows updates and that's a problem.
McKnife

Tell me why that is a problem and I'll tell you what to do.
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes
Hiep Nguyen

ASKER
Because Windows updates broke our application sometimes so I need to test first before roll out Windows updates.
McKnife

Is a wsus available?
Hiep Nguyen

ASKER
No.
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
McKnife

You may configure settings that disallow updating and change those settings when you have finished testing, install the updates and afterwards again disallow updating. That is all you can do unless you change your mind and setup a WSUS server. Disallowing updates can be done either by pointing windows to use a non-existent wsus server or by setting https://getadmx.com/?Category=Windows_10_2016&Policy=Microsoft.Policies.WindowsUpdate::DoNotConnectToWindowsUpdateInternetLocations 
Hello There

How to block user access to Windows Update on Windows Server: The default settings in Windows Server allow user who are not an administrator to scan for and apply Windows Updates. Administrators may want to change this setting to limit access to Windows Updates, especially in Remote Desktop Services Host deployments. To change this setting, use the Group Policy "Remove access to use all Windows update features." The full path to this Group Policy is: Computer Configuration\Administrative Templates\Windows Components\Windows update\Remove access to use all Windows update features

https://support.microsoft.com/en-us/help/4014345/how-to-block-user-access-to-windows-update-on-windows-server-2016 

Another solution might be to enable User Configuration\Administrative Templates\Start Menu and Taskbar\Remove links and access to Windows Update, and use Security Filtering. (https://superuser.com/questions/607311/prevent-users-from-installing-windows-updates). I haven't tried it but it might work.
ASKER CERTIFIED SOLUTION
Hiep Nguyen

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
McKnife

The author had that policy in his screenshot already.
Please note that this is a computer policy and excluding users is not possible, so it's not solved.
Come back any time.
I started with Experts Exchange in 2004 and it's been a mainstay of my professional computing life since. It helped me launch a career as a programmer / Oracle data analyst
William Peck
Hiep Nguyen

ASKER
Basically, I moved "Remove access to use all Windows update features" policy into a separate GPO (luckily I already a GPO for this purpose so I don't have to create a new one), then exclude admin from applying it.

Thank you everyone!
McKnife

You don't seem to understand. Computer policies apply to computers, not users. Thus, you cannot exclude users.
Hiep Nguyen

ASKER
You're right.  It's not working.  Forget it.  I'm going to enable it until I want to install Windows updates then just disable it.
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.