Answered by:
Automatic approved Updates

Question
-
Hi everyone!
I´m running an WSUS Server (Version: 6.3.9600.16384).
I´ve one rule for automatic approval (for install) only for specific product Windows Defender.
But since last month the system had many updates (Classification: Updates, MSRC Severity: Unspecified) automatic set to "Approved for install".
I´d like to understand why this happens....Many thanks in advance
Monday, May 18, 2015 10:32 AM
Answers
-
Hi,
First, please check the detailed information of the Change.log. The default location is "C:\Program Files\Update Services\LogFiles".
If the update is approved by automatic approve rule, the log will show as follows:
Successfully deployed deployment(Install) of Update for Windows Server 2012 R2 (KB2883200) by WUS Server UpdateID:3C26F30C-FB0A-46F6-AD43-DD20BB48CF96 Revision Number:206 TargetGroup:All Computers
If the update is approved by admins, the log will show as follows:
Successfully deployed deployment(Install) of Update for Windows Server 2012 R2 (KB3004908) by CATEST\vm3admin UpdateID:EEE0749E-5D8A-4A0C-A44A-96AE5C805385 Revision Number:200 TargetGroup:All Computers
If the log shows that the update is approved by WUS Server, please check if any other approve rules match this update. Also, please try to remove all the existing rules and recreate the rule.
Best Regards.
Steven Lee Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact tnmff@microsoft.com.
- Edited by Steven_Lee0510 Tuesday, May 19, 2015 7:06 AM
- Proposed as answer by Steven_Lee0510 Wednesday, June 3, 2015 3:13 PM
- Marked as answer by Steven_Lee0510 Thursday, June 4, 2015 3:45 PM
Tuesday, May 19, 2015 7:06 AM
All replies
-
Hi,
First, please check the detailed information of the Change.log. The default location is "C:\Program Files\Update Services\LogFiles".
If the update is approved by automatic approve rule, the log will show as follows:
Successfully deployed deployment(Install) of Update for Windows Server 2012 R2 (KB2883200) by WUS Server UpdateID:3C26F30C-FB0A-46F6-AD43-DD20BB48CF96 Revision Number:206 TargetGroup:All Computers
If the update is approved by admins, the log will show as follows:
Successfully deployed deployment(Install) of Update for Windows Server 2012 R2 (KB3004908) by CATEST\vm3admin UpdateID:EEE0749E-5D8A-4A0C-A44A-96AE5C805385 Revision Number:200 TargetGroup:All Computers
If the log shows that the update is approved by WUS Server, please check if any other approve rules match this update. Also, please try to remove all the existing rules and recreate the rule.
Best Regards.
Steven Lee Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact tnmff@microsoft.com.
- Edited by Steven_Lee0510 Tuesday, May 19, 2015 7:06 AM
- Proposed as answer by Steven_Lee0510 Wednesday, June 3, 2015 3:13 PM
- Marked as answer by Steven_Lee0510 Thursday, June 4, 2015 3:45 PM
Tuesday, May 19, 2015 7:06 AM -
Hi Steven,
thanks for reply.
In the logfile I find "WUS Server" entries only for Windows Defender (thats OK).
But I´m really really sure that my last manual "approval for install" was on 2015-05-05!
And there are a lot of patches after this date set to approved for install, in the log I can see approved by admin :-(
I´ve one more old rule (but not active!), so I´ll delete this and check whats happening.Best regards
Tuesday, May 19, 2015 1:46 PM