Fixed Scheduled Installation of Updates from 2012 WSUS Server using only GPO

Ronald Seow 206 Reputation points
2020-08-20T08:30:35.177+00:00

Good afternoon!

I am new to WSUS and would like to seek clarifications from anyone willing to share your knowledge with me.

I am currently working at a site that have quite a number of Servers and their Updates are gotten from 1 2012 WSUS Server. We have created Groups in AD and assigned the Servers to their respective Group.

We are able to create and configure different GPO for the different Groups of Servers as listed below;

  • Configure Automatic Updates
  • Specify Internet Microsoft Update Service Location
  • Do not connect to any Windows Update Internet Locations
  • Allow Automatic Updates Immediate Installation
  • Enable Client-Side Targeting

Are these policies in the GPO sufficient to fulfill the followings;

  • Check and Download Updates from WSUS Server Daily
  • Install Updates and Reboot Server Immediately on a Fixed Schedule (Exact Day and Time) based on Groups Schedule Once a Week

Appreciate if anyone can show me how to do it.

Thank you and best regards.
Ronald

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,777 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,184 questions
{count} votes

3 answers

Sort by: Most helpful
  1. Adam J. Marshall 8,706 Reputation points MVP
    2020-08-20T10:50:43.68+00:00

    Take a read through my 8 part blog series on How to Setup, Manage, and Maintain WSUS.

    https://www.ajtek.ca/guides/how-to-setup-manage-and-maintain-wsus-part-1-choosing-your-server-os/

    It also would be a good idea to read through the rest of the guides and blog posts.

    0 comments No comments

  2. Hannah Xiong 6,231 Reputation points
    2020-08-21T02:43:23.137+00:00

    Hello Ronald,

    Thank you so much for posting here.

    There are several policies about WSUS. Of course, we do not have to enable all of them. We will only focus on the necessary policies we will need in order to fulfill our requirements.

    As per my research and knowledge, these mentioned policies might be sufficient to fulfill our requirements. Automatic Updates Detection Frequency controls how frequently devices scan for updates. We could kindly have a check whether this policy is required.

    Here we would like to share with you more information about Windows Update settings.

    Deploy Windows 10 updates using Windows Server Update Services (WSUS)
    https://learn.microsoft.com/en-us/windows/deployment/update/waas-manage-updates-wsus

    Manage additional Windows Update settings
    https://learn.microsoft.com/en-us/windows/deployment/update/waas-wu-settings#related-topics

    Hope the provided information is helpful. For any question, please feel free to contact us.

    Best regards,
    Hannah Xiong

    0 comments No comments

  3. Ronald Seow 206 Reputation points
    2020-08-24T02:58:08.95+00:00

    Hi! Hannah,

    Thanks for your reply and follow up. I have not been able to fully test it as I have not been able to access my Lab. Will update you as soon as I can.

    Thank you and best regards.
    Ronald