Server Updating over GPO

Davide Cordani 1 Reputation point
2020-07-30T07:55:29.877+00:00

Hello to everybody,

I'm planning to create a GPO in order to download and install Microsoft Update on my server infrastructure.

My idea is that once a week, scheduled task reboot automatically the servers but they should be ready to install the patch during this reboot.

I dont want to use WSUS to manage them.

There is some guide or advice to create this policy?

Thanks
Davide

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
5,493 questions
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. Leon Laude 85,816 Reputation points
    2020-07-30T08:56:25.07+00:00

    Hi,

    You'll find the official Microsoft documentation for deploying Windows Updates with Group Policy over here:

    Walkthrough: Use Group Policy to configure Windows Update for Business
    https://learn.microsoft.com/en-us/windows/deployment/update/waas-wufb-group-policy

    Best regards,
    Leon

    0 comments No comments

  2. Vicky Wang 2,731 Reputation points
    2020-07-31T08:42:09.637+00:00

    To configure the Configure Automatic Updates and Intranet Microsoft Update Service Location Group Policy settings for your environment

    Open Group Policy Management Console (gpmc.msc).

    Expand Forest\Domains\Your_Domain.

    Right-click Your_Domain, and then select Create a GPO in this domain, and Link it here.

    In the New GPO dialog box, name the new GPO WSUS – Auto Updates and Intranet Update Service Location.

    Right-click the WSUS – Auto Updates and Intranet Update Service Location GPO, and then click Edit.

    In the Group Policy Management Editor, go to Computer Configuration\Policies\Administrative Templates\Windows Components\Windows Update.

    Right-click the Configure Automatic Updates setting, and then click Edit.

    In the Configure Automatic Updates dialog box, select Enable.

    Under Options, from the Configure automatic updating list, select 3 - Auto download and notify for install, and then click OK.

    Right-click the Specify intranet Microsoft update service location setting, and then select Edit.

    In the Specify intranet Microsoft update service location dialog box, select Enable.

    Under Options, in the Set the intranet update service for detecting updates and Set the intranet statistics server options, type http://Your_WSUS_Server_FQDN:PortNumber, and then select OK.

    reference:https://learn.microsoft.com/en-us/windows/deployment/update/waas-manage-updates-wsus#:~:text=In%20the%20Group%20Policy%20Management,setting%2C%20and%20then%20click%20Edit.&text=In%20the%20Specify%20intranet%20Microsoft,location%20dialog%20box%2C%20select%20Enable.

    Hope this information can help you
    Best wishes
    Vicky

    0 comments No comments

  3. Vicky Wang 2,731 Reputation points
    2020-08-04T01:27:21.707+00:00

    Hi,
     
    Just checking in to see if the information provided was helpful. Please let us know if you would like further assistance.
     
    Best Regards,
    Vicky

    0 comments No comments

  4. Davide Cordani 1 Reputation point
    2020-08-06T06:21:48.533+00:00

    Hi,

    thanks for the advice.

    However, as wrote above, I don't want to use WSUS for the server.

    I would like to configure them in order to get the update installed and I will chose when restart the server for completing the installation.

    Kind regards,

    Davide

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.