Libraries with Active Directory servers (Server 2000, Server 2003 or Server 2008) can use Group Policy to set up automatic Windows patch management with the OSL WSUS server. Group Policy is particularly useful for patching staff computers. Please note that you should create a new folder ("Organization Unit") for the WSUS policy.
I. WSUS Group Policy in Active Directory - Overview
- Create new Organizational Unit (OU). For example: wsus
- Create and edit a policy
- Move computers to the new wsus OU from the regular Computers folder
II. Creating and applying WSUS Policy in Active Directory
- On the Server, open Active Directory Users and Computers
- Right-click on server name and select new
- Select 'Organization Unit'
- Type name for new folder (suggested: wsus )
- Right-click on the new 'wsus' folder
- Chose Properties
- Select Group Policy tab
- Select New
- Type a name for the policy (e.g., StaffPC)
- Click Edit
- Open Computer Configuration
- Open Administrative Templates
- Open Windows Components
- Open Windows Update. There are 15 items that can be configured. Section III (below) has a complete list with suggested settings for use with OSL WSUS.
- When you finish editing the policy, close all of the Windows in Group Policy
- Open to the Computers folder in the Active Directory list.
- Right-click on the computer(s) you want to change, and select Move. Then select the new wsus folder as the destination.
Client computers will get the new Group Policy after they have been rebooted or logged in again.
III. Suggested WSUS Group Policy Windows Update settings
- Do not display 'Install Updates and Shut Down' option in Shut Down Windows Dialog box: NOT CONFIGURED
- Do not adjust default option to 'Install Updates and Shut Down' in Shut Down Windows Diaslog box: NOT CONFIGURED
- Configure Automatic Updates: ENABLED. Configure automatic updating: '4 - Auto download and schedule the install. The following settings are only required and applicable if 4 is selected: Scheduled install day: 0 - Every day. Scheduled install time: 08:00 for staff PCs in the morning, or 00:00 for public PC's at night.
- Specify Intranet Microsoft update service location: ENABLED. Set the inranet update service for detecting updates: http://204.17.98.45. Set the intranet statistics server: http://204.17.98.45
- Enable client-side targeting: NOT CONFIGURED
- Reschedule Automatic Updates scheduled installations: ENABLED. Wait after system startup (minutes): 1
- No auto-restart with logged on users for scheduled automatic updates installations: ENABLED
- Automatic Updates detection frequency: ENABLED. Check for updates at the following interval (hours): 22
- Allow Automatic Updates immediate installation: ENABLED
- Delay Restart for scheduled installations: ENABLED. Wait the following period before proceeding with a scheduled restart (minutes): 5
- Re-prompt for restart with scheduled installations: NOT CONFIGURED
- Allow non-administrators to receive update notifications: ENABLED
- Enable recommended updates via Automatic Updates: ENABLED
- Enabling Windows Update Power Management to automatically wake up: ENABLED
- Allow signed content from intranet Microsoft update service location: ENABLED