none
How to configure wsus clients

    Pregunta

  • I installed wsus on a 2003 r2 server that is in a workgroup instead of an AD. The clients windows 7 and windows 10 I would like to configure them to connect to the server wsus. The url that shows me the installation of wsus is http: // myserver / selfupdate
    I do not know if I should configure in the registry or by gpo in the clients and where exactly.

    Also, how can I check that my wsus is working correctly?
    Thank you.
    miércoles, 11 de julio de 2018 17:30

Respuestas

  • Hello Erricharl,

     

    Glad to help.

     

    Both GPO and registry will works. In fact, Group Policy is to control the system settings by modifying the corresponding registry key.

     

    On the clients without domain, you could modify GPO by using the Local Group Policy editor.

    Refer to following steps:

     

    1. Run gpedit.msc.
    2. Open Local Computer Policy - Computer Configuration - Administrative Templates - Windows Components - Windows Update.
    3. Click Enabled, and then, server in the Set the intranet update service for detecting updates and Set the intranet statistics server text boxes, type the same URL of the WSUS server. For example, type http://servername in both boxes (where servername is the name of the WSUS server).
    4. In the details pane, double-click Configure Automatic Updates. Click Enabled, and then select one automatic updating setting.
    5. For other policy, refer to this:

    https://docs.microsoft.com/en-us/windows-server/administration/windows-server-update-services/deploy/4-configure-group-policy-settings-for-automatic-updates

     

    Then open a Command prompt window with elevated privileges. Type wuauclt.exe /detectnow, and then press ENTER. You should find this client in the WSUS console.

     

    The best method to check if the wsus is working correctly, is to perform a sync and update.

     

    Hope above answer helps.

     

    Best regards,

    Ray Jia


    Please remember to mark the replies as answers if they help.

    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    • Marcado como respuesta Erricharl jueves, 12 de julio de 2018 6:57
    jueves, 12 de julio de 2018 2:38

Todas las respuestas

  • Hello Erricharl,

     

    Glad to help.

     

    Both GPO and registry will works. In fact, Group Policy is to control the system settings by modifying the corresponding registry key.

     

    On the clients without domain, you could modify GPO by using the Local Group Policy editor.

    Refer to following steps:

     

    1. Run gpedit.msc.
    2. Open Local Computer Policy - Computer Configuration - Administrative Templates - Windows Components - Windows Update.
    3. Click Enabled, and then, server in the Set the intranet update service for detecting updates and Set the intranet statistics server text boxes, type the same URL of the WSUS server. For example, type http://servername in both boxes (where servername is the name of the WSUS server).
    4. In the details pane, double-click Configure Automatic Updates. Click Enabled, and then select one automatic updating setting.
    5. For other policy, refer to this:

    https://docs.microsoft.com/en-us/windows-server/administration/windows-server-update-services/deploy/4-configure-group-policy-settings-for-automatic-updates

     

    Then open a Command prompt window with elevated privileges. Type wuauclt.exe /detectnow, and then press ENTER. You should find this client in the WSUS console.

     

    The best method to check if the wsus is working correctly, is to perform a sync and update.

     

    Hope above answer helps.

     

    Best regards,

    Ray Jia


    Please remember to mark the replies as answers if they help.

    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    • Marcado como respuesta Erricharl jueves, 12 de julio de 2018 6:57
    jueves, 12 de julio de 2018 2:38
  • I follow your instructions and i get this error:

    With procmon tool i see this access denied:

    Time of Day,"Process Name","PID","Operation","Path","Result","Detail"

    10:01:05,7316113,"w3wp.exe","4016","CreateFile","C:\WINDOWS\microsoft.net\Framework64\v2.0.50727\CONFIG\security.config.cch.new","ACCESS DENIED","Desired Access: Generic Write, Read Attributes, Dis File, Attributes: N, ShareMode: None, AllocationSize: 0"

    10:01:05,8900060,"w3wp.exe","4016","CreateFile","C:\Documents and Settings\Default User\Application Data\Microsoft\CLR Security Config","ACCESS DENIED","Desired Access: Read Data/List Directory, Synchronize, Dis Non-Alert, Attributes: N, ShareMode: Read, Write, AllocationSize: 0"

    10:01:05,8905225,"w3wp.exe","4016","CreateFile","C:\WINDOWS\microsoft.net\Framework64\v2.0.50727\CONFIG\enterprisesec.config.cch.new","ACCESS DENIED","Desired Access: Generic Write, Read Attributes, Dis File, Attributes: N, ShareMode: None, AllocationSize: 0"

    10:02:08,4690904,"WsusService.exe","1748","CreateFile","C:\WINDOWS\microsoft.net\Framework64\v2.0.50727\CONFIG\security.config.cch.new","ACCESS DENIED","Desired Access: Generic Write, Read Attributes, Dis OverwriteIf, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: None, AllocationSize: 0"

    10:02:08,5227294,"WsusService.exe","1748","CreateFile","C:\WINDOWS\microsoft.net\Framework64\v2.0.50727\CONFIG\enterprisesec.config.cch.new","ACCESS DENIED","Desired Access: Generic Write, Read Attributes, Dis File, Attributes: N, ShareMode: None, AllocationSize: 0"

    10:02:39,8786863,"w3wp.exe","4676","RegOpenKey","HKLM\System\CurrentControlSet\Services\W3SVC\Parameters","ACCESS DENIED",""

    10:03:06,1761605,"WsusService.exe","4712","CreateFile","C:\WINDOWS\Debug\UserMode\ChkAcc.log","ACCESS DENIED","Desired Access: Read Attributes, Delete, Synchronize, Dis Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"

    10:03:06,1764221,"WsusService.exe","4712","CreateFile","C:\WINDOWS\Debug\UserMode\ChkAcc.log","ACCESS DENIED","Desired Access: Generic Write, Read Attributes, Dis OverwriteIf, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, AllocationSize: 0"

    10:03:17,0226883,"w3wp.exe","932","RegOpenKey","HKLM\System\CurrentControlSet\Services\W3SVC\Parameters","ACCESS DENIED",""

    10:03:17,3667063,"w3wp.exe","932","CreateFile","C:\WINDOWS\Debug\UserMode\ChkAcc.log","ACCESS DENIED","Desired Access: Read Attributes, Delete, Synchronize, Dis Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"

    10:03:17,3670229,"w3wp.exe","932","CreateFile","C:\WINDOWS\Debug\UserMode\ChkAcc.log","ACCESS DENIED","Desired Access: Generic Write, Read Attributes, Dis File, Attributes: n/a, ShareMode: Read, AllocationSize: 0"

    If i open browser i get:

    This is my settings:

    And 



    • Editado Erricharl jueves, 12 de julio de 2018 9:15
    jueves, 12 de julio de 2018 7:18
  • Hello Erricharl,

      

    Thanks for your feedback.

    Please type "http://yourservername"  in Set the intranet update service for detecting updates, not "http://yourservername/selfupdate"

    Best Regards,

    Ray Jia


    Please remember to mark the replies as answers if they help.

    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    viernes, 13 de julio de 2018 3:04