Check Lhe AppllcaLlon Server" opLlon on Lhe Wlndows ComponenL Wlzard
Check Lhe AppllcaLlon Server Console ASnL1 Lnable neLwork CCM+ access llS on Lhe above lmage
SelecL Lhe 8l1S Common llles llS Manager and Lhen WWW servlces and check Lhe below menLloned
SelecL Lhe AS and WWW Servlce opLlons on Lhe WWW Servlce Wlndow
MlcrosofL 8eporL vlewer SeLup (avallable for download from MlcrosofL aL hLLp//wwwmlcrosofLcom/downloads/deLallsaspx?famllyld8a166cac738d43c8b637dd7726e61367
Wsus3.0 Installation
lnsLall Wsus 30 from locaLlon hLLp//wwwmlcrosofLcom/downloads/deLallsaspx?lamllyldL4A868u7A82046A084u8 Lu6AA4A336u9
Cllck on nexL Lo move forward Lo WSuS SeLup Wlzard
Choose Lhe klnd of lnsLallaLlon depends on your requlremenL
Choose l accepL Lhe Lerms of Lhe llcense agreemenL opLlon and Lhen cllck nexL
Check SLores updaLes locally" Lo sLore Lhe updaLes on Lhe speclfled paLh on Lhe local machlne
?ou can speclfy Lhe daLabase server Lo speclfy where Lo sLore daLa for WSuS30 Cnce speclfy Lhe lnsLance of Lhe daLabase wlll connecL Lo Lhe speclfled lnsLance
Choose Lhe webslLe preference as user Lhe exlsLlng llS uefaulL Web SlLe" and cllck on nexL
ln case you have a proxy server on you organlzaLlon speclfy proxy seLLlngs else leave all seLLlngs aL defaulL and cllck nexL lL ls recommended Lo seL Lhe WSuS Lo work wlLhouL a proxy server and allow lL a dlrecL connecLlon Lo Lhe lnLerneL (open Lhe approprlaLe porLs on Lhe lW
ln Lhe connecL Lo upsLream server page cllck sLarL connecLlng AfLer Lhe server has flnlshed Lhe lnlLlal sync Lhe nexL buLLon wlll be avallable Cllck nexL ln Lhe choose languages wlndow choose Lngllsh and Pebrew (or any oLher language of your cholce) and cllck nexL
Cn Lhe choose producLs page check Lhe producLs you wlsh Lo sync (defaulL wlndows all verslon offlce all verslons Lxchange all verslons) 1hen cllck nexL
Cn Lhe choose classlflcaLlons page choose all classlflcaLlons and cllck nexL
On the sync schedule page, choose synchronize automatically when Iirst sync is at 12:00:00AM and the sync per day setting is set to 24. Then click next.
On the Iinished page, check both checkboxes and click Iinish
$&$ INITIAL CONFIG&#ATION:
On the &pdate service administrator console that opens when the setup ends, click options and on the options tab. On the options window, click automatic approvals
On the automatic approval window, check the deIault automatic approval rule (automaticly approves critical and security updates) and click new rule iI you wish to add additional auto- approve rules Ior speciIic products or classiIications
On the add rule wizard speciIy any other auto approve rules that you wish by product or classiIication.
On the choose product window, check only IoreIront-IoreIront client security and click ok.
Back on the add rule window under step 3, type rule name (ex. FC$ &pdate rule) and click ok twice. Open Group Policy Management Console (GPMC). $tart -~ #un -~ write gpmc.msc -~ OK.
#ight click on the Group policy objects container and click new.
rite the policy name and click OK.
Expand the group policy objects container and then right-click the object you have just created and click edit.
2. On the speciIy internet MicrosoIt update service location, enter the netbios name that your internal clients will need to address when connecting to the wsus server.
#ecommended settings 1. Client $ide targeting $peciIies the target group name or names that should be used to receive updates Irom an intranet MicrosoIt update service. II the status is set to Enabled, the speciIied target group inIormation is sent to the intranet MicrosoIt update service which uses it to determine which updates should be deployed to this computer. 2. #eschedule automatic updates scheduled installations $peciIies the amount oI time Ior Automatic &pdates to wait, Iollowing system startup, beIore proceeding with a scheduled installation that was missed previously. II the status is set to Enabled, a scheduled installation that did not take place earlier will occur the speciIied number oI minutes aIter the computer is next started.
note: in order Ior this to work, you need to create groups in the $&$ server.
3. No auto-restart $peciIies that to complete a scheduled installation, Automatic &pdates will wait Ior the computer to be restarted by any user who is logged on, instead oI causing the computer to restart automatically. II the status is set to Enabled, Automatic &pdates will not restart a computer automatically during a scheduled installation iI a user is logged in to the computer Instead, Automatic &pdates will notiIy the user to restart the computer.
4. Automatic updates detection Irequency $peciIies the hours that indows will use to determine how long to wait beIore checking Ior available updates. The exact wait time is determined by using the hours speciIied here minus zero to twenty percent oI the hours speciIied. For example, iI this policy is used to speciIy a 20 hour detection Irequency, then all clients to which this policy is applied will check Ior updates anywhere between 16 and 20 hours. II the status is set to Enabled, indows will check Ior available updates at the speciIied interval. II the status is set to Disabled or Not ConIigured, indows will check Ior available updates at the deIault interval oI 22 hours.
5. Allow automatic updates immediate installation $peciIies whether Automatic &pdates should automatically install certain updates that neither interrupt indows services nor restart indows. II the status is set to Enabled, Automatic &pdates will immediately install these updates once they are downloaded and ready to install.
6. Allow non-administrators to receive update notiIications peciIies whether, when logged on, non-administrative users will receive update notiIications based on the conIiguration settings Ior Automatic &pdates. II Automatic &pdates is conIigured, by policy or locally, to notiIy the user either beIore downloading or only beIore installation, these notiIications will be oIIered to any non-administrator who logs onto the computer. II the status is set to Enabled, Automatic &pdates will include non-administrators when determining which logged-on user should receive notiIication.
AIter Iinished conIiguring the GPO, go back to the GPMC console and link the GPO to the O& that contains the computer objects you wish to work with the $&$ server. Do this by right clicking the O& and choosing link an existing GPO