How to Configure WSUS Server on Windows Server 2012 R2

How to configure WSUS Server on Windows Server 2012 R2- Windows Server Update Services

In this post, we learn the steps to configure WSUS Server 2012 R2 on Windows Server 2012 R2. In old post, we learned the steps to install WSUS Server 2012 R2.

1. To configure WSUS server on Windows Server 2012 R2, open Update services console, click on “options” to configure WSUS. Under the Options wizard, click on “WSUS Server Configuration Wizard”.

WSUS 192.168.1.23-2016-03-16-15-55-11

2. On Before You Begin console, we can read all the pre-requisite tasks to be performed before proceeding further. Click on next.

WSUS 192.168.1.23-2016-03-16-15-55-17

3. On Join the Microsoft update Improvement Program console, select “Yes, I would like to join the Microsoft Update Improvement Program” if you want that your WSUS server will send information to Microsoft about the quality of updates. Otherwise remain it unchecked and click on Next to continue.

WSUS 192.168.1.23-2016-03-16-15-55-51

4. On Choose Upstream Server console, we can choose the upstream server from which our WSUS server synchronizes updates. To configure WSUS Server, select “Synchronize from Microsoft Update” for syncing the updates directly from Microsoft. If we select the option of “Synchronize from another Windows Server Update Services Server” then we have to specify the name of other WSUS server from which our WSUS server synchronize.

To configure WSUS server, we have selected the first option i.e. “Synchronize from Microsoft Update“. Click on Next to continue. Please ensure you are connected to internet to synchronize the Microsoft Updates.

WSUS 192.168.1.23-2016-03-16-15-55-59

5. On Specify Proxy Server console, we can configure the proxy server settings if WSUS server requires a proxy server to access the updates from Microsoft Update. In this practical, we are not configuring any proxy server. Click on Next to proceed.

WSUS 192.168.1.23-2016-03-16-15-56-04

6. On Connect to Upstream Server console, click on “Start Connecting” for establishing the connection with the upstream server for synchronizing information like types of updates available, products that can be updated, available languages.

WSUS 192.168.1.23-2016-03-16-15-56-10

7. When our WSUS server successfully establishes the connection with upstream server click on Next to continue.

WSUS 192.168.1.23-2016-03-16-15-56-31

8. On Choose languages console, either select the option of “Download updates in all languages, including new languages” or select “Download updates only in these languages“. Select languages that are relevant for your environment and click Next. We have selected only English language.

WSUS 192.168.1.23-2016-03-16-15-56-52

9. On  Choose Products console, we can specify the Microsoft products for which we want updates. we selected the windows 7, windows 8.1 and  windows server 2012 r2. Click on next.

WSUS 192.168.1.23-2016-03-16-15-57-51

10. On Choose Classifications console, we can specify what classifications of updates we want to synchronize. we selected Critical updates, Definition updates, Drivers and Security updates. Please select it carefully as per your requirement. Click on next to continue.

WSUS 192.168.1.23-2016-03-16-15-58-09

11. To configure WSUS Server, on  Set Sync Schedule console, we configure this server to synchronize with Microsoft updates and we have two ways to synchronize this server, first is manually and second is automatically. We select Synchronize manually and click on next. However, you can select automatically and define the time and frequency.

WSUS 192.168.1.23-2016-03-16-15-58-30

12. This console shows the initial configuration of the WSUS server is finished and We can launch the WSUS Administration Console or start the initial synchronization without select any option click on next.

WSUS 192.168.1.23-2016-03-16-15-58-36

13. Click on Finish to get WSUS Server integrated into the environment.

WSUS 192.168.1.23-2016-03-16-15-58-42

For the installation of patches, we have to deploy two group policies related to WSUS

Second phase to configure WSUS Server is to modify the Group Policies to deploy patches to all the workstations.

14. Open GPMC console, right click on GPO(WSUS Policies) then, click on edit.

DC01 192.168.1.10-2016-03-17-11-35-37

15. In the Group Policy Management Editor, expand Computer Configuration, expand Administrative Templates, expand Windows ComponentsWindows Update, and then double click on Configure Automatic Updates.

DC01 192.168.1.10-2016-03-17-11-36-29

16.In configure Automatic updates console, click on Enabled and select one of the following options:

  1. Notify for download and notify for install
  2. Auto download and schedule the install
  3. Auto download and notify for install
  4. Allow local admin to choose setting

We have selected the third option Auto download and notify for install, and we can also schedule day and time also. Click on Ok.

DC01 192.168.1.10-2016-03-17-11-36-39

17. In the Group Policy Management Editor, expand Computer Configuration, expand Administrative Templates, expand Windows ComponentsWindows Update and then double click on Specify Intranet Microsoft update service location.

DC01 192.168.1.10-2016-03-17-11-36-57

18. Click on Enabled and type the HTTP URL of the WSUS server (http://WSUS.itingredients.com:8530) in the Set the intranet update service for detecting updates box and in the Set the intranet statistics server box.

DC01 192.168.1.10-2016-03-25-12-17-25

19. To configure WSUS server, on Update Services console, expand updates. Click on All Updates. Here, we can see all the updates which our update server synchronizes with the Microsoft Update. Right click on any update and then click on Approve to approve this update for the installation on client computers.

WSUS 192.168.1.23-2016-03-25-12-36-38

20. On Approve Update console, right click on Unassigned Computers and then, click on “Approved for Install“. Click on Ok to approve the updates.

WSUS 192.168.1.23-2016-03-25-12-36-49

21. On Approval Progress console, we can see that the security updates approval is completed without errors. Click on close to close this console.

WSUS 192.168.1.23-2016-03-25-12-37-43

22. On any client computer having Windows 8.1 operating system installed open Windows Update. Click on check for update. we can see that there are two important updates are there to install. Click on install update option to install it.

Win8-1 192.168.1.19-2016-03-25-12-37-13

23. We can see that the installation of updates is completed.

Win8-1 192.168.1.19-2016-03-25-12-39-06

Hope you understood the steps to Configure WSUS Server 2012 R2 on Windows Server 2012 R2. Please feel free to leave your comments, suggestions and queries in the comments section.

active-directory-group-policy-2012-lab
Share this post:

Leave a Reply

Your email address will not be published. Required fields are marked *