Scroll To Top

Installing & Configuring WSUS in Windows Server 2016

Posted in Article, Networking, Windows Server1 year ago • Written by Nyaz10 Comments

In this article I am going to show to, installing and Configuring WSUS in Windows Server Update Services rule in Windows server 2016. Windows Server Update Services (WSUS) is Server rule include in the windows server 2016 Operating system and WSUS is available in server 2012 R2 Os also, and that download distributes update to windows client and Servers.

  • WSUS can obtain update that are application to the operating system (OS) and common Microsoft application such as Microsoft office and Microsoft SQL server.
  • In the simplest configuration, a small organization can have a single WSUS server that downloads updates from Microsoft update.
  • The WSUS server then distribute the update to computers that are configured to obtain automatic updates from the WSUS server (Using group policy. You must approve the updates before client can download.

Installing WSUS in Windows Server 2016

On your Windows Server 2016 machine, launch Server Manager, You can either launch it using the icon in the taskbar or you can click the Start button and just search for “server manager”.

1.  On the server manager click manage and then click Add Rule and Feature. On the before you begin page click Next.

2. On the select installation type page, click Rule-based or Feature-based installation, and then click Next.

installing WSUS

installing WSUS

3. On the Select destination serverpage, select the appropriate server, and then click Next. By default the Hyper.com server has selected.

4. On the Select server rolespage, scroll down and then select Windows Server Update Services check box. in the Add feature that are required for Windows Server Update Services? click Add Features and click Next. This task will install the Windows Server Update Services Tools which included in Windows Remote server administration tools. As shown in figure.

WSUS

WSUS

5. On the Features screen, leave the default selections and click Next click Next.

Feature Page

Feature Page

6.   On the “Windows server Update Services” Page, click Next.

Windows Server Update Services

Windows Server Update Services

7. On the Role Services page, make sure WID Connectivity and WSUS Services are selected (They should be selected by default) install database used by WSUS into WID. Click Next

Select Rule Services

Select Rule Services

8. This page will allow you to set the destination directory for the downloaded updates. Tick the checkbox for Store updates in the following location.

  • If you have a drive formatted with NTFS and at least 6 GB of free disk space you can use it store update for client computer to download quickly.
  • If need to have disk space, clear the check box to store updates on the Microsoft update; download will be slower.
Content Location

Content Location

Enter the path here. It can either be a local or a remote path. Keep in mind that WSUS will take up considerable amount of storage as time goes on. It is not unusual to find update folders of sizes greater than 100 GB.

9. On the “Web Server Rule (IIS)” page, just click Next.

Web Services Rule

Web Services Rule

10. On the “Select Rule Service” page, Leave all selections as default on the Role Services page and click Next.

Rule Services

Rule Services

11. On the Confirmation screen, check the Restart the destination server automatically if required option if you wish to do so, otherwise you can leave it unchecked.

Confirmation

Confirmation

When the installation process complete successfully, click Close and go to Server Manager dashboard.  Now we have the Windows Server Update Services role and lets try to configure WSUS.

Configuring WSUS in Windows Server 2016

Configuring WSUS is very important and necessary, because for configuring WSUS is some twist, but do not worry, I will show in this article step by step, so you should focus and read this article from beginner tell last.

1. In server manager, at the top of server manager, click on tools menu, in the tools menu scroll-down and click on Windows Server Update Services (WSUS).
WSUS installation

WSUS installation

WSUS post installation process can run those step for, click on run. Since it’s the first time you’re opening it, it’ll take a while to set up. Wait for it to complete and then hit Close.

Do three thing before configuring Windows Server Update Services.

  • Confirm whether the PCs on your network can communicate with this server.
  • Your WSUS server should be able to communicate with Microsoft Update (Make sure your firewall isn’t blocking it)
  • If your environment uses a proxy, make sure you have the proxy server credentials before continuing.

2. On the “before you begin” page, click next.

Configuring WSUS

Configuring WSUS

3. On the “join Microsoft Update Improvement Program” page, if you would like to join the Microsoft update improvement program, click the check box and then click next.

Join the Microsoft update improvement program

Join the Microsoft update improvement program

4. On the “Choose upstream Server” page, if you want to synchronize from Microsoft update, choose the first one and then click next.

Choose Upstream server

Choose Upstream server

5. In most cases, you should be able to leave the proxy server settings alone. However, if you have a proxy server, you will need to specify the information, then click Next.

Proxy Server

Proxy Server

6. To Configure WSUS on the following screen, we need to apply your upstream server and proxy server setting and synchronize about available update. Click Start connecting to save and download upstream server.

Connect to upstream server

Connect to upstream server

This process might take several munities or longer, depending on your connection speed. After download update information from Microsoft, just click Next.

7. On the “Choose Product” page, all product are in here, Choose the products you want your WSUS server to house updates for, then click Next.

Choose Products

Choose Products

8. On the “Choose Classifications” page, select the update classifications you want to download, and then click next.

Choose Classification

Choose Classification

9. On the “Set Sync Schedule” page, configure when this server synchronizes with Microsoft update. You can synchronize update manually or set a schedule for daily automatic, and then click next.

Set Sync Schedule

Set Sync Schedule

10. Do not check the box to begin synchronization at this point. The database will be moved first from its default location on the system partition to a different partition to ensure that the system partition does not run out of room because of WSUS database growth.

Finish Configure

Finish Configure

11. On the “Update Services console” Click Synchronizations from the left pane. If synchronize will not start automatically just click Synchronize now.

Synchronization

Synchronization

Now you can synchronize will start automatically, if it will not start auto click synchronize now. Synchronization will take several munities or longer, depending on your internet connection speed.

WSUS COMPUTER GROUP ASSIGNMENT

One of the first things you should do once you have installed WSUS and performed the first sync is enabled the Group Policy computer group assignment. This allows the clients that connect to your WSUS server to be automatically configured in the correct targeting group when they connect to the WSUS server. The target group on the client is controlled using the group policy setting

12. On the “Update Services console” click Options from the left pane, click on computers option, on computers page you have to choices, in my case select Use group Policy or registry setting on computer. You should select this before synchronization.

Using group policy

Using group policy

13. On the “Update Services” page, click all Updates from the left pane, You will have to Approve them so that they can be pushed out to your test computer. From the Actions sidebar on the right, select Approve… (you can also right-click the selected updates and do the same)

Approve update

Approve update

In the window that pops up, right-click All Computers and select Approved for Install.

Configuring Group Policy setting to deploy updates using WSUS

Let’s start with the description of the server policy ServerWSUSPolicy.

14. Open the Group Policy Management console, and open an existing GPO or create a new one.

15. Navigate to Computer Configuration, Policies, Administrative Templates, Windows Components, Windows Update.

Group policy management editor

Group policy management editor

16. Double-click Configure Automatic Updates and set to Enabled, then configure your update settings and click OK.

Configure automatic update

Configure automatic update

17. Double-click Specify intranet Microsoft update service locationand set to Enabled, and set the URI of your WSUS server. If you selected the defaults this will be http://<server name>:8530–for example, http://Hyper-2016.Hyper.com Enter this in both text entry boxes and click OK.

Enable-Specify internet microsoft update

Enable-Specify internet microsoft update

18. Double-click allow none-administrators to receive update notifications and set to Enable, and click ok.

Enable-Allow non-administrator

Enable-Allow non-administrator

19. If you want to configure a computer group, double-click Enable client-side targeting, set to Enabled, and enter the target group name that exactly matches one defined in WSUS, then click OK.

Group Policy Management

Group Policy Management

20. Close the Group Policy Management Editor.

Refresh policy on your client machines that are in the domain or OU linked for the GPO, and they will have the new settings. Once the policy has been applied, opening the Windows Update control panel applet will show settings have been configured by the administrator. Below is an image of the policy items that should be set in your GPO.

Configuring WSUS

Configuring WSUS

21. To update group Policy object or group Policy Management, press Windows +R then it will open Run and, in the run dialog box appear, type CMD, after opened CMD or common prompt Gpupdate /force then press enter, then it will be update, and then close.

CMD-gpupdate /force

CMD-gpupdate /force

22. On the “Update Services” console, Click computers and right-click all Computers from the left pane, click on add computer group, on the name dialog box, specify a name for the new computer group, and then click add.

Add Computer Group

Add Computer Group

Enter the name of the group. I entered the same group name that I had specified in my GPO.

WSUS deploy Windows 10

WSUS deploy Windows 10

WSUS deploy Windows 10

if server is not displaying in the console.

23. Check group Policy or run the command for manual detection “WUAUCLT /DETECTNOW” on client Computer.

CMD-WUAUCLT /DETECTNOW

CMD-WUAUCLT /DETECTNOW

24. Open Settings, and click/tap on the Update & security icon.  Click/tap on Windows Update on the left side, and click/tap on the Check for updates button. (see screenshot bellow).

Configuring WSUS

Configuring WSUS

Now your windows will downloading the update of WSUS server, when update is completed, and then install.

Hope this guide installing and Configuring WSUS was useful to you. You can leave your feedback in the comments below.

 

 

TAGS: , ,

10 Comments so far. Feel free to join this conversation.

  1. Shais March 27, 2016 at 1:48 pm - Reply

    Good step by step articles for newbies. Thanks

  2. Nyaz March 27, 2016 at 6:08 pm - Reply

    Thanks dear sir

  3. Qurban Ali March 28, 2016 at 10:27 am - Reply

    Nice and clear information, step by step configuration for those who want learn step by step.

  4. Nyaz March 28, 2016 at 10:33 am - Reply

    Thanks qurban ali

  5. Marion January 24, 2017 at 8:22 pm - Reply

    Great guide – more useful than the official documentation – everything worked first time 🙂

    • Nyaz January 24, 2017 at 9:24 pm - Reply

      Dear marion! You are welcome to this website. this is the place you can learn step by step tutorials (IT). Share this post with your all friends.

  6. zenviral review February 8, 2017 at 11:55 am - Reply

    2) Article Marketings – Many peple think that marketing wwith articles only can be useful for building backlink.
    A site map links the web pages online and a good webite
    may help visitors to navigate easily oon the
    site. No one wants to write in the forum, when certain individuals get
    preferential treatment.

  7. Sahin Dag March 24, 2017 at 5:38 am - Reply

    Hello,

    great guide. Do someone has console crash problem with server 2016+wsus role?

  8. jAiHTVC June 9, 2017 at 10:30 am - Reply

    4078 576797I actually enjoy reading on this web site, it holds wonderful articles . 118598

  9. www.linux.ca August 30, 2017 at 4:04 am - Reply

    Working as a fгeelance paralegal has factors in its favor,
    and components that are unfavourable to some people.
    If a ѕense of journey and pleasure іn your wοrk life is what would
    suit you tһe best, freelancing could be an ideal choice foг you!

Leave A Response