In this article I am going to show to, installing and Configuring WSUS in Windows Server Update Services rule in Windows server 2016. Windows Server Update Services (WSUS) is Server rule include in the windows server 2016 Operating system and WSUS is available in server 2012 R2 Os also, and that download distributes update to windows client and Servers.
- WSUS can obtain update that are application to the operating system (OS) and common Microsoft application such as Microsoft office and Microsoft SQL server.
- In the simplest configuration, a small organization can have a single WSUS server that downloads updates from Microsoft update.
- The WSUS server then distribute the update to computers that are configured to obtain automatic updates from the WSUS server (Using group policy. You must approve the updates before client can download.
Installing WSUS in Windows Server 2016
On your Windows Server 2016 machine, launch Server Manager, You can either launch it using the icon in the taskbar or you can click the Start button and just search for “server manager”.
1. On the server manager click manage and then click Add Rule and Feature. On the before you begin page click Next.
2. On the select installation type page, click Rule-based or Feature-based installation, and then click Next.
3. On the Select destination serverpage, select the appropriate server, and then click Next. By default the Hyper.com server has selected.
4. On the Select server rolespage, scroll down and then select Windows Server Update Services check box. in the Add feature that are required for Windows Server Update Services? click Add Features and click Next. This task will install the Windows Server Update Services Tools which included in Windows Remote server administration tools. As shown in figure.
5. On the Features screen, leave the default selections and click Next click Next.
6. On the “Windows server Update Services” Page, click Next.
7. On the Role Services page, make sure WID Connectivity and WSUS Services are selected (They should be selected by default) install database used by WSUS into WID. Click Next
8. This page will allow you to set the destination directory for the downloaded updates. Tick the checkbox for Store updates in the following location.
- If you have a drive formatted with NTFS and at least 6 GB of free disk space you can use it store update for client computer to download quickly.
- If need to have disk space, clear the check box to store updates on the Microsoft update; download will be slower.
Enter the path here. It can either be a local or a remote path. Keep in mind that WSUS will take up considerable amount of storage as time goes on. It is not unusual to find update folders of sizes greater than 100 GB.
9. On the “Web Server Rule (IIS)” page, just click Next.
10. On the “Select Rule Service” page, Leave all selections as default on the Role Services page and click Next.
11. On the Confirmation screen, check the Restart the destination server automatically if required option if you wish to do so, otherwise you can leave it unchecked.
When the installation process complete successfully, click Close and go to Server Manager dashboard. Now we have the Windows Server Update Services role and lets try to configure WSUS.
Configuring WSUS in Windows Server 2016
Configuring WSUS is very important and necessary, because for configuring WSUS is some twist, but do not worry, I will show in this article step by step, so you should focus and read this article from beginner tell last.
WSUS post installation process can run those step for, click on run. Since it’s the first time you’re opening it, it’ll take a while to set up. Wait for it to complete and then hit Close.
Do three thing before configuring Windows Server Update Services.
- Confirm whether the PCs on your network can communicate with this server.
- Your WSUS server should be able to communicate with Microsoft Update (Make sure your firewall isn’t blocking it)
- If your environment uses a proxy, make sure you have the proxy server credentials before continuing.
2. On the “before you begin” page, click next.
3. On the “join Microsoft Update Improvement Program” page, if you would like to join the Microsoft update improvement program, click the check box and then click next.
4. On the “Choose upstream Server” page, if you want to synchronize from Microsoft update, choose the first one and then click next.
5. In most cases, you should be able to leave the proxy server settings alone. However, if you have a proxy server, you will need to specify the information, then click Next.
6. To Configure WSUS on the following screen, we need to apply your upstream server and proxy server setting and synchronize about available update. Click Start connecting to save and download upstream server.
This process might take several munities or longer, depending on your connection speed. After download update information from Microsoft, just click Next.
7. On the “Choose Product” page, all product are in here, Choose the products you want your WSUS server to house updates for, then click Next.
8. On the “Choose Classifications” page, select the update classifications you want to download, and then click next.
9. On the “Set Sync Schedule” page, configure when this server synchronizes with Microsoft update. You can synchronize update manually or set a schedule for daily automatic, and then click next.
10. Do not check the box to begin synchronization at this point. The database will be moved first from its default location on the system partition to a different partition to ensure that the system partition does not run out of room because of WSUS database growth.
11. On the “Update Services console” Click Synchronizations from the left pane. If synchronize will not start automatically just click Synchronize now.
Now you can synchronize will start automatically, if it will not start auto click synchronize now. Synchronization will take several munities or longer, depending on your internet connection speed.
WSUS COMPUTER GROUP ASSIGNMENT
One of the first things you should do once you have installed WSUS and performed the first sync is enabled the Group Policy computer group assignment. This allows the clients that connect to your WSUS server to be automatically configured in the correct targeting group when they connect to the WSUS server. The target group on the client is controlled using the group policy setting
12. On the “Update Services console” click Options from the left pane, click on computers option, on computers page you have to choices, in my case select Use group Policy or registry setting on computer. You should select this before synchronization.
13. On the “Update Services” page, click all Updates from the left pane, You will have to Approve them so that they can be pushed out to your test computer. From the Actions sidebar on the right, select Approve… (you can also right-click the selected updates and do the same)
In the window that pops up, right-click All Computers and select Approved for Install.
Configuring Group Policy setting to deploy updates using WSUS
Let’s start with the description of the server policy ServerWSUSPolicy.
14. Open the Group Policy Management console, and open an existing GPO or create a new one.
15. Navigate to Computer Configuration, Policies, Administrative Templates, Windows Components, Windows Update.
16. Double-click Configure Automatic Updates and set to Enabled, then configure your update settings and click OK.
17. Double-click Specify intranet Microsoft update service locationand set to Enabled, and set the URI of your WSUS server. If you selected the defaults this will be http://<server name>:8530–for example, http://Hyper-2016.Hyper.com Enter this in both text entry boxes and click OK.
18. Double-click allow none-administrators to receive update notifications and set to Enable, and click ok.
19. If you want to configure a computer group, double-click Enable client-side targeting, set to Enabled, and enter the target group name that exactly matches one defined in WSUS, then click OK.
20. Close the Group Policy Management Editor.
Refresh policy on your client machines that are in the domain or OU linked for the GPO, and they will have the new settings. Once the policy has been applied, opening the Windows Update control panel applet will show settings have been configured by the administrator. Below is an image of the policy items that should be set in your GPO.
21. To update group Policy object or group Policy Management, press Windows +R then it will open Run and, in the run dialog box appear, type CMD, after opened CMD or common prompt Gpupdate /force then press enter, then it will be update, and then close.
22. On the “Update Services” console, Click computers and right-click all Computers from the left pane, click on add computer group, on the name dialog box, specify a name for the new computer group, and then click add.
Enter the name of the group. I entered the same group name that I had specified in my GPO.
WSUS deploy Windows 10
if server is not displaying in the console.
23. Check group Policy or run the command for manual detection “WUAUCLT /DETECTNOW” on client Computer.
24. Open Settings, and click/tap on the Update & security icon. Click/tap on Windows Update on the left side, and click/tap on the Check for updates button. (see screenshot bellow).
Now your windows will downloading the update of WSUS server, when update is completed, and then install.
Hope this guide installing and Configuring WSUS was useful to you. You can leave your feedback in the comments below.