none
WSUS Administrative Delegation

    Question

  • Is it possible to delegate WSUS Update Approvals and/or lockdown Computer groups? For example, we suck down updates for a number of different classifications, but auto approve only Security and Critical updates across the enterprise. We then have seperate Computer groups for Servers and Workstations and would like to delegate the control of those groups to a different subset of WSUS admins. This would allow the workstation admins to manually approve for workstations, but not accidentally approve them for servers. Obviously a separate WSUS server setup could do this, but am curious if there some way to do this in a unified structure using permissions and such.
    Thanks,
    Friday, January 22, 2010 11:33 PM

Answers

  • Is it possible to delegate WSUS Update Approvals and/or lockdown Computer groups?
    Not in the native product, but the WSUS Extension Pack from EminentWare provides exactly this feature you are seeking.

    Lawrence Garvin, M.S., MCITP:EA, MCDBA, MCSA
    Principal/CTO, Onsite Technology Solutions, Houston, Texas
    Microsoft MVP - Software Distribution (2005-2010)
    My MVP Profile: http://mvp.support.microsoft.com/profile/Lawrence.Garvin
    My Blog: http://onsitechsolutions.spaces.live.com
    Saturday, January 23, 2010 8:58 PM
    Moderator