Hello,
In my opinion, as you have WSUS used, your client should always get updates through WSUS. But for Windows 10, users should have option to check online updates.
You may enable policy: Do not connect to any Windows Update Internet Locations.
If you enable this setting, you will not only disable the ability to check online for updates from Microsoft Update, but you
will also disable the ability to install software from the Windows Store.
In addition, you may set network bandwidth limitation for bits through group policy, so that update would not cost any bandwidth, please refer to the article below for more details:
https://thomas-barthelemy.github.io/2016/08/12/windows-update-bandwidth/
Regards,
Yan Li
Please remember to mark the replies as answers if they help. If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.