Popular Post Michael Posted August 9, 2011 Popular Post Posted August 9, 2011 Hello all, Here's a step by step user guide how to setup WSUS for your network! Firstly you need a server with either Windows Server 2003 SP2, Windows Server 2008 or Windows Server 2008 R2. 2003 Server Install the Microsoft Report Viewer Redistributable 2008 (2MB) You also need (as a minimum) .NET Framework 2.0 installed (22MB) Download WSUS 3.0 SP2 (80MB x86) Whilst these are downloading, add the IIS role. Navigate to Control Panel > Add/Remove Programs > Add/Remove Windows Components. Double click ‘Application Server’ then tick to enable Internet Information Services (IIS). You may need your Windows Server 2003 disc to install all required components. When the installation window appears, choose: Full server installation including Administrative Console > Next Accept the Terms > Next WSUS Setup will choose the volume with the most space. You can change this to D:\WSUS or E:\WSUS as required > Next Use the built in Windows Internal Database > Next Use the existing IIS Default Web site (Recommended) > Next Note: If you do not choose the Default IIS Web site, you’ll need to specify the Microsoft update service location policy differently as follows (for example): Specify intranet Microsoft update service location – Enabled http://SERVERNAME:8080 http://SERVERNAME:8080 When setup completes, cancel the Configuration Wizard that appears. Open WSUS by navigating to Administrative Tools > Windows Server Update Services On the left, expand SERVERNAME > Computers > All Computers. You can create computer groups, such as Workstations, Servers and Notebooks. When your workstations report to WSUS, they’ll appear in the All Computers group, but can be moved as required. Click on Options > Source and Proxy Server > Proxy Server (tab). Enter your proxy and port, then click OK. Products and Classifications. By default few products are displayed, but don’t worry. Choose Windows Server 2003 as a minimum (presuming you have a 2003 Server in your domain). Click the Classifications tab and enable: -Critical Updates -Definition Updates -Security Updates -Update Rollups -Updates, then click OK. Update Files and Languages > Update Languages (tab) > Download updates only in these languages. Tick English, then click OK. Synchronization Schedule > Synchronize Automatically. Specify 04:00:00 and 1 Synchronizations per day. Click OK. Automatic Approvals. Tick to enable Default Automatic Approval Rule. Just below this, click the Critical Updates link. Tick to enable -Critical Updates -Definition Updates -Security Updates -Update Rollups -Updates, click OK, and OK. E-Mail Notifications. Tick to enable Send e-mail notification when new updates are synchronized. Enter your e-mail address. Tick to enable Send Status Reports. Specify: Frequency: Weekly Send reports at: 11:00:00 Recipients: Enter your e-mail address Click the E-mail Server tab. Specify your SMTP server. If you do not know this, enquire with your LA or ISP. Sender name: WSUS E-mail address: [email protected] then click OK. Click Synchronizations (near the top left), then near the top right click Synchronize Now. Wait for the synchronization process to complete, then return back to Options > Products and Classifications. This will now be fully populated. Click additional products such as Windows 7, Windows Server 2008 R2 and Office 2010. Click OK, return back to Synchronizations then click Synchronize Now. To enable your workstations to report to your WSUS server, navigate to Computer Config > Admin Templates > Windows Components > Windows Update Specify the following policies: Do not display ‘Install Updates and Shutdown’ option in Shutdown Windows dialogue box – Not Configured Do not adjust default option to ‘Install Updates and Shutdown’ in Shutdown Windows dialogue box – Not Configured Enabling Windows Update Power Management to automatically wake up the system to install scheduled updates – Not Configured Configure Automatic Updates – Enabled 4 – Auto download and schedule the install 0 – Everyday 11:00 Specify intranet Microsoft update service location – Enabled http://SERVERNAME http://SERVERNAME Automatic Updates detection frequency – Enabled 1 Hour(s) Allow non-administrators to receive update notifications – Disabled Turn on Software Notifications – Not Configured Allow Automatic Updates immediate installation – Enabled Turn on recommended updates via Automatic Updates – Disabled No auto-restart with logged on users for scheduled automatic updates installations – Enabled Re-prompt for restart with scheduled installations – Not Configured Delay restart for scheduled installations – Not Configured Reschedule Automatic Updates scheduled installations – Enabled 15 Minutes Enable client-side targeting – Not Configured Allow signed updates from an Intranet Microsoft Update service location – Disabled Your workstations will then start reporting to your WSUS console. WSUS setup complete! 8
Popular Post Michael Posted August 9, 2011 Author Popular Post Posted August 9, 2011 2008/2008 R2 Server Install the Microsoft Report Viewer Redistributable 2008 (2MB) Add the WSUS role. This will automatically add the IIS role and will also download the right WSUS version for your server, so there’s no need to download it manually from Microsoft. Note: If you have problems downloading WSUS, please make sure you have no WSUS policies set on your Default Domain Policy or your Default Domain Controllers Policy. You can check this by opening up Group Policy Management > Computer Config > Policies > Admin Templates > Windows Components > Windows Update. All should be ‘Not Configured’. If you need to make changes, either reboot the server and re-add the WSUS role or run gpupdate /force and re-add the WSUS role. When the installation window appears, choose: Full server installation including Administrative Console > Next Accept the Terms > Next WSUS Setup will choose the volume with the most space. You can change this to D:\WSUS or E:\WSUS as required > Next Use the built in Windows Internal Database > Next Use the existing IIS Default Web site (Recommended) > Next Note: If you do not choose the Default IIS Web site, you’ll need to specify the Microsoft update service location slightly differently as follows (for example): Specify intranet Microsoft update service location – Enabled http://SERVERNAME:8080 http://SERVERNAME:8080 When setup completes, cancel the Configuration Wizard that appears. Open WSUS by navigating to Administrative Tools > Windows Server Update Services On the left, expand SERVERNAME > Computers > All Computers. You can create computer groups, such as Workstations, Servers and Notebooks. When your workstations report to WSUS, they’ll appear in the All Computers group, but can be moved as required. Click on Options > Source and Proxy Server > Proxy Server (tab). Enter your proxy and port, then click OK. Products and Classifications. By default few products are displayed, but don’t worry. Choose Windows Server 2003 as a minimum (presuming you have a 2003 Server in your domain). Click the Classifications tab and enable: -Critical Updates -Definition Updates -Security Updates -Update Rollups -Updates, then click OK. Update Files and Languages > Update Languages (tab) > Download updates only in these languages. Tick English, then click OK. Synchronization Schedule > Synchronize Automatically. Specify 04:00:00 and 1 Synchronizations per day. Click OK. Automatic Approvals. Tick to enable Default Automatic Approval Rule. Just below this, click the Critical Updates link. Tick to enable -Critical Updates -Definition Updates -Security Updates -Update Rollups -Updates, click OK, and OK. E-Mail Notifications. Tick to enable Send e-mail notification when new updates are synchronized. Enter your e-mail address. Tick to enable Send Status Reports. Specify: Frequency: Weekly Send reports at: 11:00:00 Recipients: Enter your e-mail address Click the E-mail Server tab. Specify your SMTP server. If you do not know this, enquire with your LA or ISP. Sender name: WSUS E-mail address: [email protected] then click OK. Click Synchronizations (near the top left), then near the top right click Synchronize Now. Wait for the synchronization process to complete, then return back to Options > Products and Classifications. This will now be fully populated. Click additional products such as Windows 7, Windows Server 2008 R2 and Office 2010. Click OK, return back to Synchronizations then click Synchronize Now. To enable your workstations to report to your WSUS server, navigate to Computer Config > Policies > Admin Templates > Windows Components > Windows Update Specify the following policies: Do not display ‘Install Updates and Shutdown’ option in Shutdown Windows dialogue box – Not Configured Do not adjust default option to ‘Install Updates and Shutdown’ in Shutdown Windows dialogue box – Not Configured Enabling Windows Update Power Management to automatically wake up the system to install scheduled updates – Not Configured Configure Automatic Updates – Enabled 4 – Auto download and schedule the install 0 – Everyday 11:00 Specify intranet Microsoft update service location – Enabled http://SERVERNAME http://SERVERNAME Automatic Updates detection frequency – Enabled 1 Hour(s) Allow non-administrators to receive update notifications – Disabled Turn on Software Notifications – Not Configured Allow Automatic Updates immediate installation – Enabled Turn on recommended updates via Automatic Updates – Disabled No auto-restart with logged on users for scheduled automatic updates installations – Enabled Re-prompt for restart with scheduled installations – Not Configured Delay restart for scheduled installations – Not Configured Reschedule Automatic Updates scheduled installations – Enabled 15 Minutes Enable client-side targeting – Not Configured Allow signed updates from an Intranet Microsoft Update service location – Disabled Your workstations will then start reporting to your WSUS console. WSUS setup complete! 14
Hightower Posted August 12, 2011 Posted August 12, 2011 Thanks for that, pretty much how I had mine configured (except for the languages!). I have a GPO setup for clients, but how do I go about telling my servers to get the updates from the WSUS, and what settings would you recommend for this. (or should I just keep letting my servers update from the web)
Michael Posted August 12, 2011 Author Posted August 12, 2011 No problem at all, glad you found it of use! Maybe the mods can make it a sticky, as it's a question that crops up many times. You have two choices really Hightower - 2003/2008/2008 R2 Server Open up GPMC (2003) or Group Policy Management (2008) and create a new GPO called WSUS. Now edit the policies (as described above) and then link the Policy to your Curriculum OU for example. You can then easily link it to your Domain Controllers OU too. This is the recommended approach. The alternative method is to edit the Default Domain Controllers Policy directly. By having separate Group Policy Objects, you can configure the policies once, but link the GPO an unlimited number of times no matter how big your domain.
eclass Posted August 15, 2011 Posted August 15, 2011 I've been using WSUS for for some time now, and it seems to be working great however, I'm trying to understand why I can't seem to reach 100% in updates. I have most of them stucvk at 99%.. see attached picture.. any ideas
elsiegee40 Posted August 15, 2011 Posted August 15, 2011 I've been using WSUS for for some time now, and it seems to be working great however, I'm trying to understand why I can't seem to reach 100% in updates. I have most of them stucvk at 99%.. see attached picture.. any ideas There are two things that could cause this: 1. It's vacation season, these updates may well have applied, but the machines have not been rebooted on the network in the last few weeks to check back in with WSUS. Take a look to see when they last checked in. 2. You'll have 1 update not approved. It usually catches me out when I've managed to approve an update for some, but not all computers that need it. Double click on one of the 99% machines and scroll through the report to find which update it is and then approve it.
Michael Posted August 15, 2011 Author Posted August 15, 2011 Most likely it'll be to do with the Windows Malicious Software Removal Tool, however if you right click one of the affected computers, it'll tell you what update(s) it requires authorising.
eclass Posted August 15, 2011 Posted August 15, 2011 Thanks ill double check those setting.. There are two things that could cause this: 1. It's vacation season, these updates may well have applied, but the machines have not been rebooted on the network in the last few weeks to check back in with WSUS. Take a look to see when they last checked in. 2. You'll have 1 update not approved. It usually catches me out when I've managed to approve an update for some, but not all computers that need it. Double click on one of the 99% machines and scroll through the report to find which update it is and then approve it.
Hightower Posted August 16, 2011 Posted August 16, 2011 Open up GPMC (2003) or Group Policy Management (2008) and create a new GPO called WSUS. Now edit the policies (as described above) and then link the Policy to your Curriculum OU for example. You can then easily link it to your Domain Controllers OU too. This is the recommended approach. The alternative method is to edit the Default Domain Controllers Policy directly. With this method, how will restarts be handled on servers? Will they auto restart, and if not how will I be prompted to restart the server when needed?
Michael Posted August 16, 2011 Author Posted August 16, 2011 On both 2003 and 2008/2008 R2, you'll receive a small pop-up prompting you to restart. The server won't just restart. I generally restart servers out of hours remotely to minimise downtime.
cookie_monsta Posted September 9, 2011 Posted September 9, 2011 please help... Summer of 2010 our main curriculum server was rebuilt with server 2008 R2. WSUS has been activated, no machines have ever connected to it... machine on the network must be updated manually which of cause is a ball ache!!.. Can some advise where im going wrong? I have approx 200 machines, 5 of which are win 7 pro (x64), 1 is business vista...the rest are xp pro (x86) many thanks in advance. Cheers C
Michael Posted September 9, 2011 Author Posted September 9, 2011 This bit should help you: To enable your workstations to report to your WSUS server, navigate to Computer Config > Policies > Admin Templates > Windows Components > Windows Update Specify the following policies: Do not display ‘Install Updates and Shutdown’ option in Shutdown Windows dialogue box – Not Configured Do not adjust default option to ‘Install Updates and Shutdown’ in Shutdown Windows dialogue box – Not Configured Enabling Windows Update Power Management to automatically wake up the system to install scheduled updates – Not Configured Configure Automatic Updates – Enabled 4 – Auto download and schedule the install 0 – Everyday 11:00 Specify intranet Microsoft update service location – Enabled http://SERVERNAME http://SERVERNAME Automatic Updates detection frequency – Enabled 1 Hour(s) Allow non-administrators to receive update notifications – Disabled Turn on Software Notifications – Not Configured Allow Automatic Updates immediate installation – Enabled Turn on recommended updates via Automatic Updates – Disabled No auto-restart with logged on users for scheduled automatic updates installations – Enabled Re-prompt for restart with scheduled installations – Not Configured Delay restart for scheduled installations – Not Configured Reschedule Automatic Updates scheduled installations – Enabled 15 Minutes Enable client-side targeting – Not Configured Allow signed updates from an Intranet Microsoft Update service location – Disabled Your workstations will then start reporting to your WSUS console. WSUS setup complete! 2
spc-rocket Posted September 9, 2011 Posted September 9, 2011 Excellent Guide Michael, top stuff!! Ash.
cookie_monsta Posted September 14, 2011 Posted September 14, 2011 This bit should help you: Hi Michael Many thanks for you reply. I have tried following the steps you provided and the steps listed at the top of the thread... however (i think im being really dense here) i cannot find Computer Config anywhere..... not in GPM etc... i have checked server manager and with the roles installed WSUS in there. Any ideas? Just a reminder, I am running Win 2008 R2 Thanks
Michael Posted September 15, 2011 Author Posted September 15, 2011 If you open up Group Policy Management, expand the menu on the left, then look for 'Group Policy Objects'. This lists all GPOs in your domain. Locate the GPO you wish to add settings to, right click it and navigate to 'GPO Status'. Make sure 'Computer Configuration Settings Disabled' is not ticked, otherwise Ccomputer Configuration should be listed.
cookie_monsta Posted September 20, 2011 Posted September 20, 2011 If you open up Group Policy Management, expand the menu on the left, then look for 'Group Policy Objects'. This lists all GPOs in your domain. Locate the GPO you wish to add settings to, right click it and navigate to 'GPO Status'. Make sure 'Computer Configuration Settings Disabled' is not ticked, otherwise Ccomputer Configuration should be listed. Hi again Michael, i have found trhe above as suggested.... and i can confirm the 'Computer Configuration Settings Disabled" is not ticked. However can you advise where i look or goto for "To enable your workstations to report to your WSUS server, navigate to Computer Config > Policies > Admin Templates > Windows Components > Windows Update" im on the server.... no probs...looked in WSUS...cant find the above..... getting a lttle lost now.. any advise (other that finding a new profession? lol) Many thanks in advance.. Cookie
Michael Posted September 20, 2011 Author Posted September 20, 2011 On the same policy you right clicked, right click it again and select 'Edit', then on the left expand: Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Update Enable/Disable the policies as required.
cookie_monsta Posted September 21, 2011 Posted September 21, 2011 On the same policy you right clicked, right click it again and select 'Edit', then on the left expand: Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Update Enable/Disable the policies as required. Cool!! i found eveything.!!! and turns out the WSUS in GPO had already been configured. Only difference was the server name section... the guide says http://SERVERNAME however i've got http://SERVERNAME:8530 in there... Ive approved a load of updates etc in WSUS.... however its still informing me that no machines have connected How do i rectify this? cheers once again
Michael Posted September 21, 2011 Author Posted September 21, 2011 It just means WSUS (when it was originally installed) wasn't put in the default IIS Site. If you did, then it should just read http://SERVERNAME As for your workstations, it can take upto 90 minutes (default Group Policy behaviour), or alternatively a reboot can force the update through quicker. If this still doesn't work, then it's difficult for me to say without knowing more about your Active Directory structure. 1
cookie_monsta Posted September 21, 2011 Posted September 21, 2011 (edited) wish this was a straight forward as this should be......good job i shave my head otherwise id be pulling my hair out lol after checking the WSUS console (or Update Services window as i see on the screen) i highlighted the server and in the middle panel under TO DO is says the following: "Your WSUS server currently shows that no computers are registered to receive updates" i have ran gpupdate /force on the server as well as my workstation (running Vista business with SP2) and it still not reporting on WSUS in terms of the computers within AD, they are listed in one group, then into sub division of the type (i.e. interactive white board and Key Stage group). The WSUS GPO is at the top of the tree so it should be pushed out to all machines.... cheers again Edited September 21, 2011 by cookie_monsta
Michael Posted September 22, 2011 Author Posted September 22, 2011 From what you're saying, yes the policy should be picked up. The best advice I can offer is to create a separate OU and a new policy, then move your workstation object (in AD) into it and experiment with the settings. 1
cookie_monsta Posted September 22, 2011 Posted September 22, 2011 Finally got machines to report to WSUS!!!! thank you Michael for all your help.... youve been a superstar!! Now to search the forums for help on creating users ids for the kids via powershell... and hopefully something in GPO to stop the kids from changing the resolution and stopping screen rotation....... ideas or links are always welcome
cookie_monsta Posted September 22, 2011 Posted September 22, 2011 2. You'll have 1 update not approved. It usually catches me out when I've managed to approve an update for some, but not all computers that need it. Double click on one of the 99% machines and scroll through the report to find which update it is and then approve it. Did this work for anyone? In WSUS, my Vista machine is showing 100% complete (other XP sp3 machines are showing 98% or 99% complete) however my machine is constantly now telling me there is an update available... and its always Windows Malicious Removal tool - July 2010 (KB890830) .... and according to the history is installs successfully..... then minutes later it tell me there is another update available Windows Malicious Removal tool - February 2011 (KB890830 again this installs successfully. But, minutes later again it tells me that july 2010 version is ready for installtion. i have approved this update many times in WSUS.....and its getting annoying now... any firm fix for it out there? Thanks in advance Cookie
Davit2005 Posted September 22, 2011 Posted September 22, 2011 Be carefull with Automatic Approval unless you are going to test first. There's nothing worse than an update causing problems or killing all your workstationsn thru a conflict with an app or driver.
cookie_monsta Posted September 22, 2011 Posted September 22, 2011 Be carefull with Automatic Approval unless you are going to test first. There's nothing worse than an update causing problems or killing all your workstationsn thru a conflict with an app or driver. I know what your saying.... our updates are firstly approved at the city council level and then we download them from their approved list on their WSUS server.... i hope they test them first etc...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now