I'm trying to setup a WSUS, having everything on the server installed, updates downloaded and accepted, etc... ready to go
Problem is, when I go into group policy and try to change the 2 relevant settings:
Computer Config > Policy > admin template > windows component > windows updates
Configure automatic updates (to set update policy, I tried allow local admin to choose)
specify intranet microsoft update service location (to set WSUS location, mandatory for WSUS use am I correct?)
But once I kick out this GPO, the local users are no longer able to run updates themselves, getting a message that states The settings are controlled by system admin
.
I want to use WSUS, but I also want the ability to manually run updates to still be in the hands of users - especially onsite people who may need to manually run updates either after restoring a machine or because an update may be required for something else to run correctly
What am I missing? Is there a way to set the GPO to tell computers to use the WSUS location but otherwise leave the settings alone?