Group policy for updating registry on client computers

For this reason, client-side targeting GPOs are typically linked to organizational units (OUs) containing the computers that are to be assigned to the respective WSUS groups rather than to domains or sites.

The policy setting will be applied upon the next refresh of Group Policy, which happens every 90 minutes by default.

For more information about this issue and for instructions about how to clear the registry values see article 903262 in the Microsoft Knowledge Base.

After you install and configure the WSUS server software, you must update Automatic Updates on the client computers.

Instead I wanted to show a quick and easy way to add “custom” registry changes using Windows 2008 Group Policy Preferences.

A Group Policy Preference is managed and set in the Group Policy Object. The key thing to know is that preferences offer a simple way to add or modify registry entries without creating custom ADM/ADMXs as you would have to with a typical policy. Here I will use the settings to Disable Machine Account Password changes (often used in Non-persistent desktop environments).

This topic describes how to configure Automatic Updates by using Group Policy.

Updated: July 19, 2011Applies To: Windows Server Update Services, Windows Small Business Server 2011 Standard, Windows Server 2008 R2, Windows Server 2003 with SP2, Windows Server 2008 R2 with SP1If you do not want to use Group Policy to manage Automatic Updates (for example, the WSUS deployment is in a non-Active Directory environment), you can configure Automatic Updates by using Registry Editor.The WSUS Administrative Template in GPMC stores most WSUS Group Policy settings in the Computer Configuration\Administrative Templates\Windows Components\Windows Update\ node.A few WSUS Group Policy settings are stored in the User Configuration\Administrative Templates\Windows Components\Windows Update\ node.Client-side targeting will not function properly if the groups do not exist or don't have names that match those in the corresponding Group Policy or registry settings.Updated: July 19, 2011Applies To: Windows Server Update Services, Windows Small Business Server 2011 Standard, Windows Server 2008 R2, Windows Server 2003 with SP2, Windows Server 2008 R2 with SP1Windows Server Update Services (WSUS) 3.0 SP2 requires that client computers run a compatible version of Automatic Updates., computer groups can be used to control which updates are allowed to be installed on certain machines.

226

Leave a Reply