Windows 7 / Getting Started

Configuring Group Policy Settings for WSUS

You can configure any single setting one time with Group Policy and have it apply to all the clients in a site, domain, or organizational unit (OU). If you want all the clients to receive their updates from your WSUS server, you can configure the clients with Group Policy. You can either create a new Group Policy object (GPO) or modify an existing one.

The Group Policy node that is configured is Computer Configuration → Policies → Administrative Templates → Windows Components → Windows Update.

GPO setting that can be manipulated to configure clients for Automatic Updates. Once the setting is set to Enabled, you can select one of four settings from the Configure Automatic Updating drop-down box.

The choices available from the Configure Automatic Updating drop-down box are numbered 2 through 5. If Configure Automatic Updates is set to Disabled, updates must be downloaded and installed manually, and this value is 1 (which isn't selectable from the drop-down box). The four choices numbered 2 through 5 are as follows:

2 - Notify for Download and Notify for Install When updates become available for download, an icon appears in the status area of the taskbar to inform the user that updates are available, but the update is not automatically downloaded. This can be used for clients located in remote sites who need to connect to the WSUS server over a slow wide area network connection. However, it has an inherent risk because it depends on the user to download and install the updates.

3 - Auto Download and Notify for Install This is the default setting when this Group Policy setting is enabled, but it is not the best setting. The update is downloaded based on the schedule but not installed. An icon appears in the status area that the user can click to initiate the installation. Just as with the previous option, it has an inherent risk because it depends on the user to take action to install the updates.

4 - Auto Download and Schedule the Install When using WSUS, this is the commonly used setting. The update is automatically downloaded to the client, and the installation of the update is scheduled. By default, the scheduled install occurs every day at 3:00 AM, though you can change the day and time setting.

5 - Allow Local Admin To Choose Setting This option allows a local administrator to select one these options. However, the local administrator cannot disable Automatic Updates. In other words, Automatic Updates will be scheduled, but the local administrator can choose whether the update is automatically downloaded and/or automatically installed via the Windows Update console.

The Specify Intranet Microsoft Update Service Location Properties setting. You'd use this to confi gure the clients to use the WSUS server for updates instead of getting updates from the Windows Update site.

The WSUS statistics server is a single WSUS server that collects information from all WSUS-managed clients in the enterprise.

Note If your environment has multiple WSUS servers, you can direct some clients to use one WSUS server with one GPO and direct other clients to use other WSUS servers with other GPOs However, a central WSUS server would still be used for overall statistics in the enterprise, so the intranet statistics server setting would be the same for all clients in the enterprise.

You can also configure how often clients check to see if updates are available. The Automatic Updates Detection Frequency with an interval of 20 hours selected. This time isn't specific but is instead randomized around the number entered.

The actual time when a client is checked is a random number between 80 percent of the given number and 120 percent of the number. With the number at 20, the client would check at some point between 16 hours (20 x 0.80) and 24 hours (20 x 1.2) after the last check. The default setting is 22, causing clients to check for updates at random intervals of between about 17.6 and 26.4 hours. Other Group Policy settings exist that can be manipulated, but these are the common ones.

[Previous] [Contents] [Next]

In this tutorial:

  1. Windows 7 and Other software Up to Date
  2. Understanding Windows Live
  3. Updates versus upgrades
  4. Why updates are important
  5. Windows Update
  6. Windows Update: The essentials
  7. Types of Updates
  8. Completing an Update
  9. Configuring automatic Updating
  10. Windows Update Applet and Functions
  11. Manually Install Updates Using Windows Update
  12. Action Center
  13. Updates Do Not Install Properly
  14. Other Windows Update Settings
  15. Configuring Windows 7 Update to Use a Proxy Server
  16. Can't Find Hidden Update
  17. Viewing and Changing Installed Updates
  18. Can't Uninstall Current Update
  19. Upgrade Windows Anytime
  20. Understanding Windows Server Update Services
  21. Windows Update Policies
  22. Updating Drivers
  23. Using Device Manager to Update Drivers
  24. Windows Update Driver Settings
  25. Windows 7 Service Packs
  26. Basic Service Pack Information
  27. Installation of Service Packs
  28. Installing and Removing Software
  29. Installation via CD or DVD
  30. Problem Installing from Disc
  31. Installation via Downloaded Program
  32. Viewing and Changing Programs
  33. Uninstalling Software
  34. Compatibility Issues in 64-Bit Version
  35. Upgrade Issues with 64-Bit Windows 7
  36. Other Program Compatibility Issues
  37. Side-by-Side Installs and Virtual Registries
  38. Removing Updates from Windows 7
  39. Thwarting Exploits with DEP
  40. Microsoft Baseline Security Analyzer
  41. Picking Computers to Scan
  42. Vulnerability Checks
  43. Installing MBSA
  44. Running the MBSA
  45. Running the MBSACLI
  46. MBSACLI Location
  47. Running in an Isolated Environment
  48. Using Windows Server Update Services
  49. WSUS Updates
  50. WSUS Requirements
  51. Installing, Configuring, and Using WSUS
  52. Adding the Application Server and Web Server (IIS) Roles
  53. Installing the Report Viewer
  54. Installing WSUS
  55. Configuring Group Policy Settings for WSUS
  56. Creating a GPO to Configure Clients to Use WSUS
  57. Verifying That Clients Are Using GPO Settings for WSUS
  58. Verifying That Clients Are Using GPO Settings with GPResult
  59. Creating Computer Groups on WSUS
  60. Approving Updates in WSUS
  61. Viewing WSUS Reports