WSUS never PUSHES any updates ever. WSUS is a repository where updates are stored and is a pull system from each individual client. It is the Windows Update Agent (WUA) on each client that does everything - checking for updates, downloading updates, installing updates, restarting the computer, connecting back to WSUS and reporting back any changes.
Group Policies are responsible for controlling how the WUA operates, and from what your screenshot shows, you have chosen option #3 to automatically download updates and notifiy when they are ready to be installed. What this means is that when an update is needed by the client, is approved and fully downloaded on the WSUS server, the client will find the update, download it, but NOT INSTALL it - instead it will notify the user that an update is waiting to be installed.
If you want the computer to automatically install the updates you need to choose option # 4 as noted in part 4 of my guide on How to Install, Manage, and Maintain WSUS.
https://www.ajtek.ca/wsus/how-to-setup-manage-and-maintain-wsus-part-4-creating-your-gpos-for-an-inheritance-setup/
I'd recommend reading the whole series from start to finish, and then re-reading it while adjusting your settings to work how you want them to in accordance with my guide.