WSUS: Definition Updates vs Windows Updates deployments

Duchemin, Dominique 2,011 Reputation points
2022-12-08T20:07:20.827+00:00

Hello,

We have the needs to get the Definition Updates installed for System Center Endpoint Protection and Windows Defender applied once a day.

We have the Windows Updates coming from WSUS applied only once a month.

How to get the two different deployments/applications without getting a GPO conflict?

  • Multiple rules?
  • Multiple groups?
  • Multiple GPOs

Thanks,
Dom

Windows for business | Windows Server | User experience | Other
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Duchemin, Dominique 2,011 Reputation points
    2023-01-04T18:53:57.547+00:00

    Hello,

    We have production servers which have no internet access and would want to update SCEP definition updates from WSUS.
    As we have configured GPO to the Manual installation workgroup in WSUS, to not install the updates automatically on these servers and this WSUS option will be enabled only once a month which is not viable for the Definition Updates, we would like to have them daily..
    By design you could have only one GPO applied and would have to enable Configure Automatic updates in the GPO if you would like to update SCEP from WSUS.

    The other option is to allow internet access on these servers so after the server scans from their WSUS, the SCEP definition updates will download from Internet (MMPC or Microsoft update)
    Need to change the source download priority and enable " Allow Security intelligence updates from Microsoft Update" inside Windows Defender container in the existing GPO setting.

    The last option is to download the SCEP definition updates from internet where there is an internet access, place it on a share\network drive and enable GPO setting to download the source from the UNC path.

    What is (are) the options used in your environments?

    Thanks,
    Dom

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.