Ask a questionAsk a question
 

AnswerSCCM with WSUS and GPO

  • Friday, October 23, 2009 12:19 PMspab1981 Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     
    Ok, here is our situation, we have 2 WSUS servers that we use currently for our monthly patching, we are just setting up a new SCCM server to eventually take over those patching responsibilities, I have been reading a bit and I was looking for a solid answers for our environment. 

    Our clients are configured in GPO to report and grab all the patches from our current WSUS servers.  We would like to deploy new sccm clients to our servers so we can use the features of sccm and start the configuration of them.  This is my concern, I have read somewhere, I can't find the actual post at the moment, that when you install the new sccm client on a machine that is already using a totally different WSUS server assigned through GPO that the previously used WSUS server will not work for patching on the clients that already have the new sccm client?

    Can someone help me out on this?  Thanks!!!

Answers

  • Friday, October 23, 2009 1:33 PMJason SandysMVPUsers MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     Answer
    The ConfigMgr agent will set a local group policy on systems to point the the local Windows Update Agent (WUA) to the SUP. A domain based group policy will override this local group policy, the ConfigMgr agent recognizes this and will "gracefully" not perform any update activity leaving the WUA to coordinate update activity with the WSUS server configured in the domain group policy.

    End result: domain group policy for WSUS trumps ConfigMgr policy.
    Jason | http://myitforum.com/cs2/blogs/jsandys | http://blogs.catapultsystems.com/jsandys/default.aspx | Twitter @JasonSandys
    • Marked As Answer byspab1981 Friday, October 23, 2009 2:05 PM
    •  

All Replies

  • Friday, October 23, 2009 1:33 PMJason SandysMVPUsers MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     Answer
    The ConfigMgr agent will set a local group policy on systems to point the the local Windows Update Agent (WUA) to the SUP. A domain based group policy will override this local group policy, the ConfigMgr agent recognizes this and will "gracefully" not perform any update activity leaving the WUA to coordinate update activity with the WSUS server configured in the domain group policy.

    End result: domain group policy for WSUS trumps ConfigMgr policy.
    Jason | http://myitforum.com/cs2/blogs/jsandys | http://blogs.catapultsystems.com/jsandys/default.aspx | Twitter @JasonSandys
    • Marked As Answer byspab1981 Friday, October 23, 2009 2:05 PM
    •