Open WSUS server setting and follow below steps to configure WSUS Server to download all required Microsoft the updates automatically.
Configure Update Source:
- Go to "Options" and click on "Update source and proxy server".
- Select "Synchronize from Microsoft Update"
- Add proxy details, if required
Configure Product and Classification:
- Go to "Options" and click on "Products and Classifications"
- Select "All products" or "applications", which are applicable to your organization in "Products" Tab
- In “Classification” Tab select “All Classification” OR select “Critical Updates”, “Security Updates”, “Service Packs”, “Update Rollups”, “Updates” and “Upgrades” in “Classification” Tab
Configure Files and Languages:
- Go to "Option" and click on "Update Files and Languages"
- Select "Store update files locally on this server" in "Update Files” tab Select "Download Express installation files".
- Select “Download updates only in these languages” and select all required languages from the list.
Configure Synchronization Schedule:
- Go to "Options" and click on "Synchronization Schedule"
- Select "Synchronize automatically" and set time and per your preferred time
- Also, select "Synchronize per day" to "3" OR as per your preference.
Configure Automatic Approvals:
- Go to "Options" and click on "Automatic Approvals"
- Click on "New Rule" and select "When update in a specific classification"
- Click on When an update is in "any classification" and select "All Classification" OR Use previously selected "Classification" in "Products and Classifications" section.
- Select "When an update is in a specific product"
- Click on When an update is in "any product" and select "All Products" OR Use previously selected "Products" in "Products and Classifications" section.
- Click on Approve the updates for "any computer" and select "All Computer" NOTE: Include "Unassigned Computers" as well
- Specify rule name and click on "OK" to create auto approval rule.
- Select check boxes as shown in the below picture in "Advanced" tab.
Configure Computers Section:
- Go to "Options" and click on "Computers"
- Select "Use Group Policy or Registry settings on computers"
Manual Checklist:
- Check and make sure to apply security updates and upgrades to WSUS server once in a month.
- We have observed due to some reason "auto approval" on certain updates does not happen, once in a month approve updates manually.
- Microsoft releases "Security Patches" every month 2nd week of Tuesday and in rare cases, emergency patches will be released.
- It is good practice to do above first 2 tasks on every month 2nd week of "Friday"
References:
Please refer below references to understand more on WSUS server working,
https://technet.microsoft.com/en-us/library/cc708460(v=ws.10).aspx
https://technet.microsoft.com/en-us/library/cc708519(v=ws.10).aspx
https://technet.microsoft.com/en-us/library/cc720539(v=ws.10).aspx
https://technet.microsoft.com/en-us/library/cc708475(v=ws.10).aspx
https://technet.microsoft.com/en-us/library/cc720525(v=ws.10).aspx
Comments