Download as docx, pdf, or txt
Download as docx, pdf, or txt
You are on page 1of 31

rerequlslLes llS 60 wlLh ASneL lnsLalled

SLep 1 CoLo SLarL seLLlngs conLrol panel Add or 8emove rograms




SelecL " Add or 8emove Wlndows ComponenLs"

Check Lhe AppllcaLlon Server" opLlon on Lhe Wlndows ComponenL Wlzard


Check Lhe AppllcaLlon Server Console ASnL1 Lnable neLwork CCM+ access llS on Lhe above lmage

SelecL Lhe 8l1S Common llles llS Manager and Lhen WWW servlces and check Lhe below menLloned

SelecL Lhe AS and WWW Servlce opLlons on Lhe WWW Servlce Wlndow


MlcrosofL 8eporL vlewer SeLup (avallable for download from MlcrosofL aL
hLLp//wwwmlcrosofLcom/downloads/deLallsaspx?famllyld8a166cac738d43c8b637dd7726e61367




















Wsus3.0 Installation

lnsLall Wsus 30 from locaLlon
hLLp//wwwmlcrosofLcom/downloads/deLallsaspx?lamllyldL4A868u7A82046A084u8
Lu6AA4A336u9



Cllck on nexL Lo move forward Lo WSuS SeLup Wlzard

Choose Lhe klnd of lnsLallaLlon depends on your requlremenL




Choose l accepL Lhe Lerms of Lhe llcense agreemenL opLlon and Lhen cllck nexL

Check SLores updaLes locally" Lo sLore Lhe updaLes on Lhe speclfled paLh on Lhe local machlne

?ou can speclfy Lhe daLabase server Lo speclfy where Lo sLore daLa for WSuS30
Cnce speclfy Lhe lnsLance of Lhe daLabase wlll connecL Lo Lhe speclfled lnsLance



Choose Lhe webslLe preference as user Lhe exlsLlng llS uefaulL Web SlLe" and cllck on nexL




















ln case you have a proxy server on you organlzaLlon speclfy proxy seLLlngs else leave all seLLlngs aL
defaulL and cllck nexL lL ls recommended Lo seL Lhe WSuS Lo work wlLhouL a proxy server and allow lL a
dlrecL connecLlon Lo Lhe lnLerneL (open Lhe approprlaLe porLs on Lhe lW



ln Lhe connecL Lo upsLream server page cllck sLarL connecLlng AfLer Lhe server has flnlshed Lhe lnlLlal
sync Lhe nexL buLLon wlll be avallable Cllck nexL
ln Lhe choose languages wlndow choose Lngllsh and Pebrew (or any oLher language of your cholce)
and cllck nexL

Cn Lhe choose producLs page check Lhe producLs you wlsh Lo sync (defaulL wlndows all verslon offlce
all verslons Lxchange all verslons) 1hen cllck nexL


Cn Lhe choose classlflcaLlons page choose all classlflcaLlons and cllck nexL


On the sync schedule page, choose synchronize automatically when Iirst sync is at 12:00:00AM
and the sync per day setting is set to 24. Then click next.

On the Iinished page, check both checkboxes and click Iinish













$&$ INITIAL CONFIG&#ATION:

On the &pdate service administrator console that opens when the setup ends, click options and
on the options tab. On the options window, click automatic approvals



On the automatic approval window, check the deIault automatic approval rule (automaticly
approves critical and security updates) and click new rule iI you wish to add additional auto-
approve rules Ior speciIic products or classiIications

On the add rule wizard speciIy any other auto approve rules that you wish by product or
classiIication.

On the choose product window, check only IoreIront-IoreIront client security and click ok.

Back on the add rule window under step 3, type rule name (ex. FC$ &pdate rule) and click ok
twice.
Open Group Policy Management Console (GPMC). $tart -~ #un -~ write gpmc.msc -~ OK.


#ight click on the Group policy objects container and click new.



rite the policy name and click OK.



Expand the group policy objects container and then right-click the object you have just created
and click edit.

Expand the Computer conIiguration -~ Administrative Templates -~ indows Components -~
indows &pdate.










Now conIigure the Iollowing options:

1. ConIigure Automatic &pdates

2. On the speciIy internet MicrosoIt update service location, enter the netbios name that
your internal clients will need to address when connecting to the wsus server.



#ecommended settings
1. Client $ide targeting $peciIies the target group name or names that should be used to
receive updates Irom an intranet MicrosoIt update service.
II the status is set to Enabled, the speciIied target group inIormation is sent to the intranet
MicrosoIt update service which uses it to determine which updates should be deployed to
this computer.
2. #eschedule automatic updates scheduled installations $peciIies the amount oI time Ior
Automatic &pdates to wait, Iollowing system startup, beIore proceeding with a scheduled
installation that was missed previously.
II the status is set to Enabled, a scheduled installation that did not take place earlier will
occur the speciIied number oI minutes aIter the computer is next started.



note: in order Ior this to work, you need to create groups in the $&$ server.

3. No auto-restart $peciIies that to complete a scheduled installation, Automatic &pdates
will wait Ior the computer to be restarted by any user who is logged on, instead oI
causing the computer to restart automatically.
II the status is set to Enabled, Automatic &pdates will not restart a computer
automatically during a scheduled installation iI a user is logged in to the computer
Instead, Automatic &pdates will notiIy the user to restart the computer.




4. Automatic updates detection Irequency $peciIies the hours that indows will use to
determine how long to wait beIore checking Ior available updates. The exact wait time is
determined by using the hours speciIied here minus zero to twenty percent oI the hours
speciIied. For example, iI this policy is used to speciIy a 20 hour detection Irequency,
then all clients to which this policy is applied will check Ior updates anywhere between
16 and 20 hours.
II the status is set to Enabled, indows will check Ior available updates at the speciIied
interval.
II the status is set to Disabled or Not ConIigured, indows will check Ior available
updates at the deIault interval oI 22 hours.













5. Allow automatic updates immediate installation $peciIies whether Automatic &pdates
should automatically install certain updates that neither interrupt indows services nor
restart indows.
II the status is set to Enabled, Automatic &pdates will immediately install these updates
once they are downloaded and ready to install.









6. Allow non-administrators to receive update notiIications peciIies whether, when logged
on, non-administrative users will receive update notiIications based on the conIiguration
settings Ior Automatic &pdates. II Automatic &pdates is conIigured, by policy or locally,
to notiIy the user either beIore downloading or only beIore installation, these
notiIications will be oIIered to any non-administrator who logs onto the computer.
II the status is set to Enabled, Automatic &pdates will include non-administrators when
determining which logged-on user should receive notiIication.

AIter Iinished conIiguring the GPO, go back to the GPMC console and link the GPO to the O&
that contains the computer objects you wish to work with the $&$ server. Do this by right
clicking the O& and choosing link an existing GPO

You might also like