locked
WSUS issues RRS feed

  • Question

  • Hey there!

    I'm configuring a WSUS server for our business and I've run into some problems.

    The WSUS server is set up on a standalone server, apart from the domain controller.

    On the domain controller I've used the GP manager to direct the user groups that we need to have updated to the WSUS server (specify intranet Microsoft update service location) and I've configured Automatic updates.

    The problem is that no computers have connected to the server, and I don't understand why. I think there might be a problem with some permissions. Earlier, at a Windows Server course we gave the users some "apply to" permissions, but I can't remember in what context.

    I look forward to the answers I get from you guys. Thanks!

    Wednesday, June 25, 2014 9:01 AM

Answers

  • When you say "I've used the GP manager to direct the user groups that we need to have updated to the WSUS server" what do you mean? If you are using security filtering on the group policy to apply to only specific user groups then that is probably not going to work...

    I'm assuming the WSUS settings are COMPUTER settings and thus configuring user groups to use these COMPUTER settings is not going to work. You will have to use groups with computer objects rather than user objects. 

    Then again, I may have misread your post entirely... hope this helps. 

    • Proposed as answer by DonPick Wednesday, June 25, 2014 9:41 PM
    • Marked as answer by Lawrence Garvin Sunday, June 29, 2014 6:52 PM
    Wednesday, June 25, 2014 3:45 PM

All replies

  • first check that the group policy pointing your clients to the WSUS server is infact applying to the end user computers.  You can do that by running a gpresult

    then, check that you have met all the requirements for the WSUS configuration (application and web server roles?).  A detailed list of requirements can be found here:  http://technet.microsoft.com/en-us/library/dd939916(v=ws.10).aspx

    Wednesday, June 25, 2014 2:03 PM
  • When you say "I've used the GP manager to direct the user groups that we need to have updated to the WSUS server" what do you mean? If you are using security filtering on the group policy to apply to only specific user groups then that is probably not going to work...

    I'm assuming the WSUS settings are COMPUTER settings and thus configuring user groups to use these COMPUTER settings is not going to work. You will have to use groups with computer objects rather than user objects. 

    Then again, I may have misread your post entirely... hope this helps. 

    • Proposed as answer by DonPick Wednesday, June 25, 2014 9:41 PM
    • Marked as answer by Lawrence Garvin Sunday, June 29, 2014 6:52 PM
    Wednesday, June 25, 2014 3:45 PM
  • I'm assuming the WSUS settings are COMPUTER settings and thus configuring user groups to use these COMPUTER settings is not going to work. You will have to use groups with computer objects rather than user objects.

    This is correct. The WSUS GPO is applied to Organizational Units containing COMPUTER ACCOUNTS.

    Lawrence Garvin, M.S., MCSA, MCITP:EA, MCDBA
    SolarWinds Head Geek
    Microsoft MVP - Software Packaging, Deployment & Servicing (2005-2014)
    My MVP Profile: http://mvp.microsoft.com/en-us/mvp/Lawrence%20R%20Garvin-32101
    http://www.solarwinds.com/gotmicrosoft
    The views expressed on this post are mine and do not necessarily reflect the views of SolarWinds.

    Wednesday, June 25, 2014 8:57 PM
  • The problem is that no computers have connected to the server, and I don't understand why.

    Sounds like you've improperly configured the GPO.

    See Configure Automatic Updates Using Group Policy for additional help.


    Lawrence Garvin, M.S., MCSA, MCITP:EA, MCDBA
    SolarWinds Head Geek
    Microsoft MVP - Software Packaging, Deployment & Servicing (2005-2014)
    My MVP Profile: http://mvp.microsoft.com/en-us/mvp/Lawrence%20R%20Garvin-32101
    http://www.solarwinds.com/gotmicrosoft
    The views expressed on this post are mine and do not necessarily reflect the views of SolarWinds.

    Wednesday, June 25, 2014 9:00 PM
  • When you say "I've used the GP manager to direct the user groups that we need to have updated to the WSUS server" what do you mean? If you are using security filtering on the group policy to apply to only specific user groups then that is probably not going to work...

    I'm assuming the WSUS settings are COMPUTER settings and thus configuring user groups to use these COMPUTER settings is not going to work. You will have to use groups with computer objects rather than user objects. 

    Then again, I may have misread your post entirely... hope this helps. 

    It worked!

    I created an OU and put one of our computers in there. A few minutes later and the WSUS control panel shows that a computer wants updates.

    Thank you for the help! :)

    Thursday, June 26, 2014 8:25 AM