Answered by:
Updates has been installed ignoring Domain Policies

Question
-
I'm the AD Admin (including WSUS [WSUS 6.3 on Win2012]) of an enterprise with 1 domain /8 child domains (Server 2008R2) and about 10000 users. This night the chaos has reigned: the Windows Update Policy has been ignored by the most of the servers and 4 new updates (KB4012212, KB4012215, KB4012204 and KB4013867) has been deployed and installed, restarting part of those servers. Affected servers are from various domains and Windows 2008/2012. This policy auto-downloads and notify for install updates. The servers I have checked are in the correct OU and the correct Policy was applied to. Checking the registry, the settings for the policy are correct. However, the patches has been installed and the servers rebooted. This policies has been worked fine until today.
I'm puzzled and I do not know what else to look at. What else can I check?
******
UPDATE
******
Question: I'd configured a "deadline" of 7 days for a group of servers to install updates. Can somebody confirm that the application of this deadline ignores the group policies about WSUS?
Thanks in advance!
- Edited by Jordisans Wednesday, March 22, 2017 4:03 PM
Wednesday, March 22, 2017 11:56 AM
Answers
-
Hi Jordisans,
You may refer to the following article to check if the behavior is following the deadline behavior:
Client Behavior with Update Deadlines
https://technet.microsoft.com/en-us/library/cc708585%28v=ws.10%29.aspx?f=255&MSPPError=-2147217396
Best Regards,
Please remember to mark the replies as answers if they help.
If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.- Marked as answer by Jordisans Thursday, March 23, 2017 8:38 AM
Thursday, March 23, 2017 8:05 AM -
Am 22.03.2017 schrieb Jordisans:
****
UPDATE
****
Question: I'd configured a "deadline" of 7 days for a group of servers to install updates. Can somebody confirm that the application of this deadline ignores the group policies about WSUS?Yes, it ignore your GPO for Restart or another settings. Deadline is
very bad.Winfried
WSUS Package Publisher: http://wsuspackagepublisher.codeplex.com/
http://technet.microsoft.com/en-us/windowsserver/bb332157.aspx
http://www.wsuswiki.com/Home- Marked as answer by Jordisans Thursday, March 23, 2017 8:38 AM
Thursday, March 23, 2017 5:54 AM
All replies
-
Am 22.03.2017 schrieb Jordisans:
****
UPDATE
****
Question: I'd configured a "deadline" of 7 days for a group of servers to install updates. Can somebody confirm that the application of this deadline ignores the group policies about WSUS?Yes, it ignore your GPO for Restart or another settings. Deadline is
very bad.Winfried
WSUS Package Publisher: http://wsuspackagepublisher.codeplex.com/
http://technet.microsoft.com/en-us/windowsserver/bb332157.aspx
http://www.wsuswiki.com/Home- Marked as answer by Jordisans Thursday, March 23, 2017 8:38 AM
Thursday, March 23, 2017 5:54 AM -
Hi Jordisans,
You may refer to the following article to check if the behavior is following the deadline behavior:
Client Behavior with Update Deadlines
https://technet.microsoft.com/en-us/library/cc708585%28v=ws.10%29.aspx?f=255&MSPPError=-2147217396
Best Regards,
Please remember to mark the replies as answers if they help.
If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.- Marked as answer by Jordisans Thursday, March 23, 2017 8:38 AM
Thursday, March 23, 2017 8:05 AM