Follow the guide here - https://www.ajtek.ca/wsus/client-machines-not-reporting-to-wsus-properly/
Automatic Updates are fine to be on if you're using WSUS - WSUS is the 'control' factor. If you don't approve the updates, the clients never see the updates as even possible.
See my 8 part blogs series on How to Setup, Manage, and Maintain WSUS:
https://www.ajtek.ca/wsus/how-to-setup-manage-and-maintain-wsus-part-1-choosing-your-server-os/