Xp not updating wsus

In our example OU structure is extremely simple: there are two containers – Servers (it contains all servers of the company, as well as domain controllers) and WKS (Workstations – user computers). We consider only a fairly simple option of binding the WSUS policies to clients.

In real world, it is possible to bind a single WSUS policy to all domain computers (a GPO is assigned to the domain root), distribute different computers between different OUs (like in our example), in distributed networks it’s worth to bind different WSUS servers to the AD sites, or to assign a GPO based on the WMI filters, or even combine these methods.

In this article we will consider how to configure clients of the WSUS server using Active Directory GPO (Group Policies).

AD Group Policies allow the administrator to automatically assign computers to different WSUS groups, saving him the trouble of manually moving the computers between groups in the WSUS console and support these groups up-to-date.

It is expected that our network will use two different update policies: one for servers (Servers) and another one for workstations (Workstations). The policy of using the WSUS server by its clients depends largely on the organizational structure of the Active Directory OU (organization units) and update installation rules in the company.

In this article we will try to understand the basic principles of using AD policies to install Windows updates.

Besides, we want to disable the automatic installation of updates on the servers when they are received.

