ALL,
Recently created and configured a WSUS server into my domain, created GPOs to set domain to download initial patches but not to install. Now when I go to hosts in that domain in update and security states this option is managed by your organization. I've been looking around for any other locations that could be blocking the update feature. This is currently not happening on the domain controllers that do not have this GPO.
GPO Settings: Confirmed via gpresult.exe
Windows Components/Windows Update/Manage end user experience/Configure Automatic
Updates - Enabled (3)
System/Internet Communication Management/Internet Communication settings/Turn off
access to all Windows Update features - Disabled
Windows Components/Windows Update/Manage end
user experience/Remove access to use all Windows Update features - Disabled
Regedit.msc: Validated that registry keys are not blocking
computer\hkey_local_machine\software\policies\windows\windowsUpdate\disabledwindowsupdateaccess(0)
computer\hkey_local_machine\Software\Policies\Microsoft\Windows\WindowsUpdate(0)