Hi All,
I wonder if someone can offer me some advice. I recently inherited a server farm consisting of Server 2012, 2012 R2, 2016, 2019 and 2022 VMs. For some reason I cannot figure out why, the Server 2016 servers ALL appear to be bypassing WSUS and getting updates directly from Windows Update online. However, all the other servers are working as expected and waiting on approved WSUS updates.
All the servers are being configured for WSUS with the same group policy settings. The registry keys for HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate and \AU are identical on all servers. They all have the WSUS server correctly specified in the WUServer and WUStatusServer keys and all have UseWSUerver set to "1".
WSUS is seeing the 2016 servers without issue and can see that the unapproved updates are installed on them.
After doing some digging, it looks like adding in the Do not connect to any Windows Update Internet locations setting will probably fix the problem, but I'd like to understand why this issue is happening and why it's only happening on the Server 2016 boxes.
Our previous network admin has left the organisation, so I'm unable to ask any questions as to any changes made over the years.
Thanks for the help,
Tim