Thursday, January 10, 2013 1:50 PM
Is there any way in WSUS to limit who can access the WSUS Management Console? Right now, anyone knowing the server name can connect to WSUS and their role is Administrator.
I don't manage the server, i'm just using the console but i was just curious if this is possible.
Thursday, January 10, 2013 5:08 PMBecause the users are local admins they would have access to WSUS. The only way to restrict the users is to remove them as local admins.
- Marked As Answer by Gary__100 Thursday, January 10, 2013 5:10 PM
Thursday, January 10, 2013 7:25 PM
The only way to restrict the users is to remove them as local admins.
Not quite correct.
Account may be not in local administrator group, but successfully administrate WSUS, because this account belongs to *WSUS Administrators* group on server.
IF users accounts not a member of the local Administrators group,also it necessary to check that these accounts (which must be restricted) don't belong to *WSUS Administrators* group.
Friday, January 11, 2013 12:37 PMExactly, thanks for correcting me. So we need to restrict the users by removing them from both local admin as well as WSUS Admin groups.