Jump to content

Recommended Posts

Posted

Hi all,

 

How are people looking after updates whilst a good proportion in of staff are off site? They usually use WSUS locally, some users do have VPN access and are working as normal.

 

What are the best options?

 

Thanks

Posted
We have wsus set to not cache files locally meaning updates are still controlled by wsus but download from microsofts servers. We added the dns name of our wsus server to our external dns and opened up the wsus port to the internet.
  • Thanks 1
Posted
We have wsus set to not cache files locally meaning updates are still controlled by wsus but download from microsofts servers. We added the dns name of our wsus server to our external dns and opened up the wsus port to the internet.
Makes perfect sense, I really should have set it to the fqdn so I could have done it like this without having to have any back onsite.

 

Thank you!

Posted

Our server is set to cache files and we don't have VPNs set up so staff are having to update manually.

 

I asked all staff with laptops to go into settings, update & security, and click on the "check online for updates from Microsoft update" link. Foolish of me to expect any of them to (a) read this, (b) try to do it and © click on the right thing. Only replies I got were from people clicking "check for updates" (which comes up with an error as they're not connected to the server)

Posted
Could you send a command to them to change setting in registry? I know our antivirus for example can be used to run a command remotely and even when external pc's still check in with av server.
Posted
Our server is set to cache files and we don't have VPNs set up so staff are having to update manually.

 

I asked all staff with laptops to go into settings, update & security, and click on the "check online for updates from Microsoft update" link. Foolish of me to expect any of them to (a) read this, (b) try to do it and © click on the right thing. Only replies I got were from people clicking "check for updates" (which comes up with an error as they're not connected to the server)

I have this option disabled in policy so it's a no go at the moment, and I'd be lucky if they read the email asking them to do it, let alone them actually following the simple instructions!
Posted
Could you send a command to them to change setting in registry? I know our antivirus for example can be used to run a command remotely and even when external pc's still check in with av server.
I don't think so, none of them have local admin rights either, it might just be a case they have to come and sit in the car park to pick up a new policy.
Posted
I changed the policy for any laptops going home to update direct from Microsoft instead of our WSUS server

 

Is there a policy that has some setting like "if not connected to WSUS server for x days, update directly"? This would be very useful for the future!

Posted
There isn’t, no. The settings I put in to block internet updates, plus blocks to the Settings app, rather killed this for us! They’ll have to come on site for ADA after six months anyway [emoji6]
Posted
Is there a policy that has some setting like "if not connected to WSUS server for x days, update directly"? This would be very useful for the future!

 

Not that I know of.

I changed my update group policy before laptops went off site.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...