How to Configure WSUS Server on Windows Server 2012 R2
How to configure WSUS Server on Windows Server 2012 R2- Windows Server Update Services
In this post, we learn the steps to configure WSUS Server 2012 R2 on Windows Server 2012 R2. In old post, we learned the steps to install WSUS Server 2012 R2.
1. To configure WSUS server on Windows Server 2012 R2, open Update services console, click on “options” to configure WSUS. Under the Options wizard, click on “WSUS Server Configuration Wizard”.
2. On Before You Begin console, we can read all the pre-requisite tasks to be performed before proceeding further. Click on next.
3. On Join the Microsoft update Improvement Program console, select “Yes, I would like to join the Microsoft Update Improvement Program” if you want that your WSUS server will send information to Microsoft about the quality of updates. Otherwise remain it unchecked and click on Next to continue.
4. On Choose Upstream Server console, we can choose the upstream server from which our WSUS server synchronizes updates. To configure WSUS Server, select “Synchronize from Microsoft Update” for syncing the updates directly from Microsoft. If we select the option of “Synchronize from another Windows Server Update Services Server” then we have to specify the name of other WSUS server from which our WSUS server synchronize.
To configure WSUS server, we have selected the first option i.e. “Synchronize from Microsoft Update“. Click on Next to continue. Please ensure you are connected to internet to synchronize the Microsoft Updates.
5. On Specify Proxy Server console, we can configure the proxy server settings if WSUS server requires a proxy server to access the updates from Microsoft Update. In this practical, we are not configuring any proxy server. Click on Next to proceed.
6. On Connect to Upstream Server console, click on “Start Connecting” for establishing the connection with the upstream server for synchronizing information like types of updates available, products that can be updated, available languages.
7. When our WSUS server successfully establishes the connection with upstream server click on Next to continue.
8. On Choose languages console, either select the option of “Download updates in all languages, including new languages” or select “Download updates only in these languages“. Select languages that are relevant for your environment and click Next. We have selected only English language.
9. On Choose Products console, we can specify the Microsoft products for which we want updates. we selected the windows 7, windows 8.1 and windows server 2012 r2. Click on next.
10. On Choose Classifications console, we can specify what classifications of updates we want to synchronize. we selected Critical updates, Definition updates, Drivers and Security updates. Please select it carefully as per your requirement. Click on next to continue.
11. To configure WSUS Server, on Set Sync Schedule console, we configure this server to synchronize with Microsoft updates and we have two ways to synchronize this server, first is manually and second is automatically. We select Synchronize manually and click on next. However, you can select automatically and define the time and frequency.
12. This console shows the initial configuration of the WSUS server is finished and We can launch the WSUS Administration Console or start the initial synchronization without select any option click on next.
13. Click on Finish to get WSUS Server integrated into the environment.
For the installation of patches, we have to deploy two group policies related to WSUS
Second phase to configure WSUS Server is to modify the Group Policies to deploy patches to all the workstations.
14. Open GPMC console, right click on GPO(WSUS Policies) then, click on edit.
15. In the Group Policy Management Editor, expand Computer Configuration, expand Administrative Templates, expand Windows Components, Windows Update, and then double click on Configure Automatic Updates.
16.In configure Automatic updates console, click on Enabled and select one of the following options:
- Notify for download and notify for install
- Auto download and schedule the install
- Auto download and notify for install
- Allow local admin to choose setting
We have selected the third option Auto download and notify for install, and we can also schedule day and time also. Click on Ok.
17. In the Group Policy Management Editor, expand Computer Configuration, expand Administrative Templates, expand Windows Components, Windows Update and then double click on Specify Intranet Microsoft update service location.
18. Click on Enabled and type the HTTP URL of the WSUS server (http://WSUS.itingredients.com:8530) in the Set the intranet update service for detecting updates box and in the Set the intranet statistics server box.
19. To configure WSUS server, on Update Services console, expand updates. Click on All Updates. Here, we can see all the updates which our update server synchronizes with the Microsoft Update. Right click on any update and then click on Approve to approve this update for the installation on client computers.
20. On Approve Update console, right click on Unassigned Computers and then, click on “Approved for Install“. Click on Ok to approve the updates.
21. On Approval Progress console, we can see that the security updates approval is completed without errors. Click on close to close this console.
22. On any client computer having Windows 8.1 operating system installed open Windows Update. Click on check for update. we can see that there are two important updates are there to install. Click on install update option to install it.
23. We can see that the installation of updates is completed.
Hope you understood the steps to Configure WSUS Server 2012 R2 on Windows Server 2012 R2. Please feel free to leave your comments, suggestions and queries in the comments section.