Jump to content

Recommended Posts

Posted

Thanks for that, pretty much how I had mine configured (except for the languages!).

 

I have a GPO setup for clients, but how do I go about telling my servers to get the updates from the WSUS, and what settings would you recommend for this. (or should I just keep letting my servers update from the web)

Posted

No problem at all, glad you found it of use! :) Maybe the mods can make it a sticky, as it's a question that crops up many times.

 

You have two choices really Hightower -

 

2003/2008/2008 R2 Server

 

Open up GPMC (2003) or Group Policy Management (2008) and create a new GPO called WSUS. Now edit the policies (as described above) and then link the Policy to your Curriculum OU for example. You can then easily link it to your Domain Controllers OU too. This is the recommended approach. The alternative method is to edit the Default Domain Controllers Policy directly.

 

By having separate Group Policy Objects, you can configure the policies once, but link the GPO an unlimited number of times no matter how big your domain.

Posted

I've been using WSUS for for some time now, and it seems to be working great however, I'm trying to understand why I can't seem to reach 100% in updates. I have most of them stucvk at 99%..

 

see attached picture.. any ideas

cute.png

Posted
I've been using WSUS for for some time now, and it seems to be working great however, I'm trying to understand why I can't seem to reach 100% in updates. I have most of them stucvk at 99%..

 

see attached picture.. any ideas

There are two things that could cause this:

 

1. It's vacation season, these updates may well have applied, but the machines have not been rebooted on the network in the last few weeks to check back in with WSUS. Take a look to see when they last checked in.

 

2. You'll have 1 update not approved. It usually catches me out when I've managed to approve an update for some, but not all computers that need it. Double click on one of the 99% machines and scroll through the report to find which update it is and then approve it.

Posted
Most likely it'll be to do with the Windows Malicious Software Removal Tool, however if you right click one of the affected computers, it'll tell you what update(s) it requires authorising.
Posted

Thanks ill double check those setting..

 

There are two things that could cause this:

 

1. It's vacation season, these updates may well have applied, but the machines have not been rebooted on the network in the last few weeks to check back in with WSUS. Take a look to see when they last checked in.

 

2. You'll have 1 update not approved. It usually catches me out when I've managed to approve an update for some, but not all computers that need it. Double click on one of the 99% machines and scroll through the report to find which update it is and then approve it.

Posted

Open up GPMC (2003) or Group Policy Management (2008) and create a new GPO called WSUS. Now edit the policies (as described above) and then link the Policy to your Curriculum OU for example. You can then easily link it to your Domain Controllers OU too. This is the recommended approach. The alternative method is to edit the Default Domain Controllers Policy directly.

 

With this method, how will restarts be handled on servers? Will they auto restart, and if not how will I be prompted to restart the server when needed?

Posted
On both 2003 and 2008/2008 R2, you'll receive a small pop-up prompting you to restart. The server won't just restart. I generally restart servers out of hours remotely to minimise downtime.
  • 4 weeks later...
Posted

please help...

 

Summer of 2010 our main curriculum server was rebuilt with server 2008 R2.

 

WSUS has been activated, no machines have ever connected to it...

 

machine on the network must be updated manually which of cause is a ball ache!!..

 

Can some advise where im going wrong? I have approx 200 machines, 5 of which are win 7 pro (x64), 1 is business vista...the rest are xp pro (x86)

 

many thanks in advance.

 

Cheers

 

C

Posted

This bit should help you:

 

To enable your workstations to report to your WSUS server, navigate to Computer Config > Policies > Admin Templates > Windows Components > Windows Update

 

Specify the following policies:

 

Do not display ‘Install Updates and Shutdown’ option in Shutdown Windows dialogue box – Not Configured

 

Do not adjust default option to ‘Install Updates and Shutdown’ in Shutdown Windows dialogue box – Not Configured

 

Enabling Windows Update Power Management to automatically wake up the system to install scheduled updates – Not Configured

 

Configure Automatic Updates – Enabled

4 – Auto download and schedule the install

0 – Everyday

11:00

 

Specify intranet Microsoft update service location – Enabled

http://SERVERNAME

http://SERVERNAME

 

Automatic Updates detection frequency – Enabled

1 Hour(s)

 

Allow non-administrators to receive update notifications – Disabled

 

Turn on Software Notifications – Not Configured

 

Allow Automatic Updates immediate installation – Enabled

 

Turn on recommended updates via Automatic Updates – Disabled

 

No auto-restart with logged on users for scheduled automatic updates installations – Enabled

 

Re-prompt for restart with scheduled installations – Not Configured

 

Delay restart for scheduled installations – Not Configured

 

Reschedule Automatic Updates scheduled installations – Enabled

15 Minutes

 

Enable client-side targeting – Not Configured

 

Allow signed updates from an Intranet Microsoft Update service location – Disabled

 

Your workstations will then start reporting to your WSUS console. WSUS setup complete!

  • Thanks 2
Posted
This bit should help you:

 

Hi Michael

 

Many thanks for you reply.

 

I have tried following the steps you provided and the steps listed at the top of the thread...

 

 

however (i think im being really dense here) i cannot find Computer Config anywhere..... not in GPM etc...

 

i have checked server manager and with the roles installed WSUS in there.

 

Any ideas? Just a reminder, I am running Win 2008 R2

 

Thanks

Posted

If you open up Group Policy Management, expand the menu on the left, then look for 'Group Policy Objects'.

 

This lists all GPOs in your domain. Locate the GPO you wish to add settings to, right click it and navigate to 'GPO Status'.

 

Make sure 'Computer Configuration Settings Disabled' is not ticked, otherwise Ccomputer Configuration should be listed.

Posted
If you open up Group Policy Management, expand the menu on the left, then look for 'Group Policy Objects'.

 

This lists all GPOs in your domain. Locate the GPO you wish to add settings to, right click it and navigate to 'GPO Status'.

 

Make sure 'Computer Configuration Settings Disabled' is not ticked, otherwise Ccomputer Configuration should be listed.

 

Hi again Michael,

 

i have found trhe above as suggested.... and i can confirm the 'Computer Configuration Settings Disabled" is not ticked.

 

However can you advise where i look or goto for "To enable your workstations to report to your WSUS server, navigate to Computer Config > Policies > Admin Templates > Windows Components > Windows Update"

 

im on the server.... no probs...looked in WSUS...cant find the above..... getting a lttle lost now..

 

any advise (other that finding a new profession? lol)

 

Many thanks in advance..

 

Cookie

Posted

On the same policy you right clicked, right click it again and select 'Edit', then on the left expand:

 

Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Update

 

Enable/Disable the policies as required.

Posted
On the same policy you right clicked, right click it again and select 'Edit', then on the left expand:

 

Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Update

 

Enable/Disable the policies as required.

 

Cool!! i found eveything.!!! and turns out the WSUS in GPO had already been configured.

 

Only difference was the server name section... the guide says http://SERVERNAME however i've got http://SERVERNAME:8530 in there...

 

Ive approved a load of updates etc in WSUS....

 

however its still informing me that no machines have connected :(

 

How do i rectify this?

 

cheers once again

Posted

It just means WSUS (when it was originally installed) wasn't put in the default IIS Site. If you did, then it should just read http://SERVERNAME

 

As for your workstations, it can take upto 90 minutes (default Group Policy behaviour), or alternatively a reboot can force the update through quicker.

 

If this still doesn't work, then it's difficult for me to say without knowing more about your Active Directory structure.

  • Thanks 1
Posted (edited)

wish this was a straight forward as this should be......good job i shave my head otherwise id be pulling my hair out lol

 

after checking the WSUS console (or Update Services window as i see on the screen) i highlighted the server and in the middle panel under TO DO is says the following:

"Your WSUS server currently shows that no computers are registered to receive updates"

 

i have ran gpupdate /force on the server as well as my workstation (running Vista business with SP2) and it still not reporting on WSUS :(

 

in terms of the computers within AD, they are listed in one group, then into sub division of the type (i.e. interactive white board and Key Stage group).

 

The WSUS GPO is at the top of the tree so it should be pushed out to all machines....

 

cheers again

Edited by cookie_monsta
Posted
From what you're saying, yes the policy should be picked up. The best advice I can offer is to create a separate OU and a new policy, then move your workstation object (in AD) into it and experiment with the settings.
  • Thanks 1
Posted

Finally got machines to report to WSUS!!!!

 

thank you Michael for all your help.... youve been a superstar!!

 

Now to search the forums for help on creating users ids for the kids via powershell...

 

and hopefully something in GPO to stop the kids from changing the resolution and stopping screen rotation....... ideas or links are always welcome :)

Posted

 

2. You'll have 1 update not approved. It usually catches me out when I've managed to approve an update for some, but not all computers that need it. Double click on one of the 99% machines and scroll through the report to find which update it is and then approve it.

 

Did this work for anyone?

 

In WSUS, my Vista machine is showing 100% complete (other XP sp3 machines are showing 98% or 99% complete) however my machine is constantly now telling me there is an update available...

 

and its always Windows Malicious Removal tool - July 2010 (KB890830) .... and according to the history is installs successfully..... then minutes later it tell me there is another update available Windows Malicious Removal tool - February 2011 (KB890830 again this installs successfully.

 

But, minutes later again it tells me that july 2010 version is ready for installtion.

 

i have approved this update many times in WSUS.....and its getting annoying now...

 

any firm fix for it out there?

 

Thanks in advance :)

 

Cookie

Posted
Be carefull with Automatic Approval unless you are going to test first. There's nothing worse than an update causing problems or killing all your workstationsn thru a conflict with an app or driver.
Posted
Be carefull with Automatic Approval unless you are going to test first. There's nothing worse than an update causing problems or killing all your workstationsn thru a conflict with an app or driver.

 

I know what your saying....

 

our updates are firstly approved at the city council level and then we download them from their approved list on their WSUS server....

 

i hope they test them first etc...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...