WSUS, or Windows Server Update Services, is a Microsoft tool that enables IT administrators to manage the distribution of operating system updates within a network. It provides a centralized solution for downloading and deploying patches for Microsoft products, reducing vulnerabilities and enhancing system security. By automatically scheduling updates and allowing for customization, WSUS streamlines the update process, ensuring that small projects can effectively maintain their systems in a secure and efficient manner.
Before you start, make sure your server has:
ADDS including DNS
DOUBLE NETWORK CARD
CREATE OU (Organizational Unit) FOR WINSOWS 11 COMPUTERS, AND MOVE ALL WINDOWS 11 MACHINES TO THIS OU (Organizational Unit)
WSUS, or Windows Server Update Services, is a Microsoft tool that enables IT administrators to manage the distribution of operating system updates within a network. It provides a centralized solution for downloading and deploying patches for Microsoft products, reducing vulnerabilities and enhancing system security. By automatically scheduling updates and allowing for customization, WSUS streamlines the update process, ensuring that small projects can effectively maintain their systems in a secure and efficient manner.
Before you start, make sure your server has:
ADDS including DNS
DOUBLE NETWORK CARD
CREATE OU (Organizational Unit) FOR WINSOWS 11 COMPUTERS, AND MOVE ALL WINDOWS 11 MACHINES TO THIS OU (Organizational Unit)
Go Tools --> Active Directory Users and Computers
Right Click on "domain_name" --> New --> Organizational Unit
Name it "win11"
Go Computers --> select computers with windows 11, and move them to OU "win11"
Select "win11" OU and Click OK
1 Go --> Manage --> Add Roles and Features
2 Click Next
3 Next
4 Select Web Server (IIS) & Windows Server Update Services
5 Click Web Add Features
6 Click Next
7 Click Next
8 Click Next
9 Click Next
10 Next & Choose Path where you want to locate Updates, if the path not exist, it will be created automatically.
11 Next
12 Click Next and then Install.
13 Click Close & Wait until the installation is done.
If you Got Error During Installation, Make Sure
Date
Ip Address
IIS
Manage
Internet Information Services IIS
{Server-Name}
Sites
WSUS Administration (remove it and then run task again)
14 Click Toos --> Windows Server Updates Services
15 Click "server-name" --> Options --> WSUS Server Configuration Wizard
16 Click Next
17 Uncheck the box
18 Next
19 Next
20 Click Start Connecting & Next
21 Choose languages updates you want
22 Choose Products updates you want
23 Choose Classifications updates you want
24 Next
25 Finish
1 Right Click on All Computers --> Add Computer Group...
2 Write "win11" & OK
3 Go Tools --> Group Policy Management
4 Right Click on "win11" OU --> create GPO with a name “win11updates”
5 Write "Win11Updates” & OK
6 Right Click on "Win11Updates” --> Edit
7 Right Click on Specify Intranet Microsoft Update Service Location --> Edit
(here you can determine from where client can take updates)
8 Type the Name of Server, Example: "http://server.test.ma:8530" & OK
9 Right Click on Configure Automatic Updates --> Edit.
10 here you can choose the way and when the update will download or install for the user
11 Right Click on Automatic Updates Detection Frequency --> Edit.
12 when the computer will check if there is new updates
13 Right Click on Enable Client-side Targeting --> Edit.
14 to link computers in OU with WSUS, make sure you create OU and new group computers with the same name "win11"
15 Go Back to WSUS & Click Options & Computers & Use Group Policy or registry settings on computers & OK
16 Click on (server-name) & Synchronize Now
(it will take a long time to finish)
17 Go All Updates & Right Click on update you want & Approve...
18 Go Right Click on "win11" & Approve to Install
(To Send Updates to Devices Manually)
19 Accept
20 Close
21 Click on "win11" to see computers that took the updates
22 Right Click on Start & Run
23 Write gpudate /force
this command to make client take the updates fast
24 Click install
the update is available
25 Go WSUS Options & Automatic Approve & New Rule...
(to make clients take updates automatically from the server)
26 Click All Computers
(to select the group that will take updates automatically)
27 Select Win11 & Ok
28 Check box when an update is in a specific classification
Click any classification
29 Check box Security Updates & OK
30 Check box when an update is in a specific product
Click any product
31 Check boxes of all windows 11 & OK
32 Check box of set a deadline for the approval
Click 2
33 Edit time you want & OK
34 Specify a name & OK
35 Finally OK