Dzherelo update windows through the registry. I will securely install it in the working groups. Group Policy Editor

One of the preceding articles described the procedure in detail. In addition, as you set up a server, you need to set up Windows clients (servers and workstations) on the WSUS server to remove the update, the clients received the update from the internal Microsoft Update server through the Internet. At the top of the statistics, it is possible to understand the procedure for setting up clients on the WSUS server server behind the additional group policies of the Active Directory domain.

The AD policy groups allow the administrator to automatically identify computers in the WSUS group, so that there is no need to manually move computers between groups in the WSUS console and to display these groups in the current station. The assignment of clients to the large groups of WSUS is to be rutted on the mitts in the register on the clients (the mitts are set by the group policy or to the direct editing of the reestr). This type of customer service to WSUS groups is called clientsidetargeting(Targeting per client).

Transmitting that in our hedge will be victorious, there will be two developments in the policy of updating - the same policy is being introduced for the server ( Servers) that for working stations ( Workstations). Two groups will need to be located on the WSUS console in the All Computers section.

Porada... Server policy update WSUS customers have a lot of reasons for storing the organizational structure of the OU in Active Directory and the rules for introducing updates in the organization. There is no private option in the statistics, which allows the intelligence of the basic principles of the AD policy for the installation of Windows updates.

First, it is necessary to set the rule of ugrupovannya computers from the WSUS console (targeting). For promos at the WSUS console, computers will be assigned by the group administrator (server side targeting). We are not in charge, so it seems that computers are distributed into groups based on client side targeting (the key is from the client's register). For the whole in the WSUS console, go to the section Options then enter the parameter Computers... Change the value to Use Group Policy or registry setting on computers(Vikoristovuvati group policy or parameters of the register on computers).

You can now open the GPO to configure the WSUS clients. Open the domain Group Policy Management console and open two new group policies: ServerWSUSPolicy and WorkstationWSUSPolicy.

WSUS Group Policy for Windows Servers

How can I describe the server policy ServerWSUSPolicy.

The group policy settings, which are responsible for the Windows Update service robot, are located in the GPO section: ComputerConfiguration -> Policies-> Administrativetemplates-> WindowsComponent-> WindowsUpdate(Computer configuration -> Administrative templates -> Windows components -> Windows Update).

Our organization has a policy of introducing new WSUS to Windows servers. It will be transferred to the Servers group in the WSUS console. In addition, we want to automatically install new updates on servers when they are rejected. The WSUS client is guilty of simply blocking the available updates on the disk, pretend to know about the new updates in the system tray, and to start the installation by the administrator (manually or with a help) for the first time. This means that the productive servers do not automatically start to take over the update and re-enroll without the administrator's approval (ask the robot to be seen by the system administrator within the framework of the thousands of scheduled scheduled maintenance work). For the implementation of such a scheme, the following policies can be set:

  • ConfigureAutomaticUpdates(Automatic update adjustment): Enable... 3 - Autodownloadandnotifyforinstall(Automatically enqueue the update and if it is ready before being installed)- the client will automatically add new updates and help you about the new one;
  • SpecifyIntranetMicrosoftupdateservicelocation(Order the distribution of the Microsoft update service in Intrarezhі): Enable... Set Provide an update service in Intrarezhі for a joke update: http: //srv-wsus. site: 8530, Set the intranet statistics server: http: //srv-wsus. site: 8530- here it is necessary to specify the address of your WSUS server and the statistics server (call the stink);
  • No auto-restart with logged on users for scheduled automatic updates installations(Do not automatically re-enroll before the hour of automatic re-establishment of the update, even if in the system of cleaning the clerk): Enable- the fence is automatically re-secured due to the presence of the session of the koristuvach;
  • Enableclient-sidetargeting ( Allow the client to belong to the whole group): Enable... Target group name for this computer: Servers- at the WSUS console, add clients to the Servers group.

Note... It’s a matter of time to adjust the update policy and respectfully learn about the parameters available in the skin and the GPO option WindowsUpdate and set up information for your infrastructure and organizing parameters.

WSUS Implementation Policy for Workstations

Every allowance, when updating the client's workstations, on the basis of the server policy, will be automatically set up at night as soon as the update is taken into account. After the installation of the new computer is guilty, it is automatically re-availed (re-waiting for 5 khvili).

At tsіy GPO (WorkstationWSUSPolicy) mi vkazuєmo:

  • AllowAutomaticUpdatesimmediateinstallation(Allow non-control of automatic updates): Disabled- a fence on a negativnaya vstanovlennya upgrading at їkh їkh otrimanny;
  • Allownon-administratorstoreceiveupdatenotifications(Allow koristuvacham, as not є administrators, remove the information about the update): Enabled- to show non-administrators about the appearance of new innovations and allow them to be established manually;
  • Configure Automatic Updates:Enabled... Configure automatic updating: 4 - Auto download and schedule the install. Scheduled install day: 0 - Everyday... Scheduled install time: 05:00 - when new clients are rejected, they jump to the local cache and plan, they will be automatically installed at 5:00;
  • Target group name for this computer: Workstations- at the WSUS console, bring the client to the Workstations group;
  • No auto-restart with logged on users for automatic updates installations: Disabled- the system will automatically reload after 5 minutes after the update is finished;
  • Specify Intranet Microsoft update service location: Enable. Set intranet update service for detecting updates: http: //srv-wsus. site: 8530, Set the intranet statistics server: http: //srv-wsus. site: 8530-Addresses of the corporate WSUS server.

In Windows 10 1607, it’s unaffected by those who have been asked to remove the update from the internal WSUS, all the more can go to the Windows Update servers on the Internet. Qia "ficha" be called DualScan... To connect to the Internet, it is necessary to turn on the policy additionally. DonotallowupdatedeferralpoliciestocausescansagainstWindowsUpdate ().

Porada... To paint the patches of computers in the organization, in both policies it is possible to set up the primus to launch the update service (wuauserv) on the clients. For all the razdіlі Computer Configuration -> Policies-> Windows Setings -> Security Settings -> System Services know the Windows Update service and set it to start automatically ( Automatic).

Apparently WSUS policy on OU Active Directory

The upcoming croc - the definition of the policy paths to the up-to-date containers (OU) of Active Directory. In our application, the structure of the OU in the AD domain is as simple as possible: є two containers - Servers (all servers of the organization, in addition to the domain controller) and WKS (Workstations - computers).

Porada... We only need one to reach a simple option of attaching WSUS policies to clients. For real organizations, you can link one WSUS policy on all computers to a domain (GPO with WSUS settings can be found on the root of the domain), assign different types of clients to different OUs (like in our application server - the ), on large distributed domains it is possible to link or sign a GPO on the display or combine different methods.

To indicate the policy on the OU, click at the console of the keruvannya by group policies for the required OU, select the menu item Link as Existing GPO and the choice of policies.

Porada... Do not forget about the OUs with Domain Controllers, in a large number of containers you should attach the "server" WSUS policy.

So it is very necessary to assign the WorkstationWSUSPolicy policy to the AD WKS container, which will run Windows workstations.

There was a lack of new group policies on clients for attaching a client to the WSUS server:

Efforts to adjust the Windows system and update, as set by group politicians, are responsible for appearing in the client register at the hospital HKEY_LOCAL_MACHINE \ SOFTWARE \ Policies \ Microsoft \ Windows \ WindowsUpdate.

The whole reg file can be used to transfer the WSUS setup to your own computers, on which you cannot set up the update parameters for the additional GPO (computers in the workgroup, isolated segments, DMZ is too thin)

Windows Registry Editor Version 5.00

"WUServer" = "http: //srv-wsus.site: 8530"
"WUStatusServer" = "http: //srv-wsus.site: 8530"
"UpdateServiceUrlAlternate" = ""
"TargetGroupEnabled" = dword: 00000001
"TargetGroup" = "Servers"
"ElevateNonAdmins" = dword: 00000000

"NoAutoUpdate" = dword: 00000000 -
"AUOptions" = dword: 00000003
"ScheduledInstallDay" = dword: 00000000
"ScheduledInstallTime" = dword: 00000003
"ScheduledInstallEveryWeek" = dword: 00000001
"UseWUServer" = dword: 00000001
"NoAutoRebootWithLoggedOnUsers" = dword: 00000001

It is also easy to control the setting of WSUS on the clients behind the additional rsop.msc.

In a ten hour (to deposit some of the updates and the bandwidth of the channel to the WSUS server), it will be necessary to convert to the third manifestation of merging information about the appearance of new updates. The WSUS console may have clients in the selected groups (the tabular view will display the client's name, IP, OS, and the last updated status date). Because by our politicians we tied computers and servers to the new WSUS groups, the stinks should be removed from the update, grabbed before being installed on the new WSUS groups.

Note... I do not appear on the update client, it is recommended to respectfully update the Windows update service log on the problem client (C: WindowsUpdate.log). Beastly respect, scho Windows 10 (Windows Server 2016) vikorystovutsya. The client will add the update to the local folder C: \ Windows \ SoftwareDistribution \ Download. Then run the new update on the WSUS server, you need to select the command:

wuauclt / detectnow

Also, it is necessary to re-arrange the client on the WSUS server:

wuauclt / detectnow / resetAuthorization

In especially folding vipads, you can try to repair the wuauserv service. At a later date, try changing the frequency of the update to the WSUS server using the additional Automatic Update detection frequency policy.

The offensive statistics have a description of the particularities. It is also recommended to read this article in groups on WSUS servers.

Published on Lutii 18, 2009 by Comments

At the end of the article, I will tell you about the registry keys (Registry Keys) linked to Windows updates (Windows Update). I will show you some of the parameters that you can use to trim the keys to the re-set.

If you missed a part of the statty to a friend, then, be weasel, read

If you want to update Windows (Windows Update) and WSUS, it’s easy to get it right, if you want to update it, you can do more detailed control by making the changes to the Windows registry. At the end of the article, I will show you some of the keys to the registry linked to the Windows updates (Windows Update). I will show you some of the parameters that you can use to trim the keys to the re-set.

For the cob

For the sake of the ear, I will give the lawyers a chance, and the changes made to the restructuring may not be safe anymore. Entering the wrong parameters in the registry can lead to depletion of Windows and / or any programs running on the machine. Before trying the changes made to the reestablishment, it is necessary to restore the backup copy of the system, I am ready to show you how to try.

Є One more rіch, about yaku, I can tell you more. More precisely, I want to tell you about it, I want you to get help, to get rid of it for computers that work on Windows XP keruvans. You can make changes for the singing machines without the help of a middle, or you can save a part of the script at the entrance (login script). Likewise, the keys, about which I open, can not be based on the promises. If you want to vikoristovuvati key, which is not іnuє, then wіll blame іt ѕоmаt yоu. Also guilty of the nobility, the behavior of updating Windows can be carried out with the help of the group policy. Group politicians can sometimes modify the keys to the register in such a way that they smell the behavior they have set.

Adding privileges

One of the problems with rejecting the update from the WSUS server is that it cannot be hardened, because it stinks because it stinks not as members of the local administrators group. However, you can vikoristovuvati registrar, sob to admit the corystuvachi in such a rank, so that the stench is too small to be able to get up, or see what the changes were installed independently, from the members of the group of local administrators (local administrators). From the side, you can also barrow the criminals to get the update and deprive the administrator of the right.

The registry key, which is displayed for the price: HKEY_LOCAL_MACHINE \ SOFTWARE \ Policies \ Microsoft \ Windows \ WindowsUpdate \ ElevateNonAdmins

The ElevateNonAdmins key has two possible values. The value for the umovchannya, but for the road 1, allowing the koristuvachi, who are not the administrators, to establish the update. If you change the value to 0, you will not be able to install the update from the administrator.

Target Groups

One of the miraculous speeches from WSUS is that it’s because it’s okay to allow the client side targeting. The idea of ​​\ u200b \ u200bthe positions of the clientele side of the field is that you can ask for the development of the group's computers and grant the rights to establish an update on the basis of membership in the group. For the position of the clientele side, you don’t want to be victorious, if you do it, then there are two keys to the registry, which will help you to get started. The first of these keys includes the positioning of the client side targeting, and the first one I will name the group before the computer is located. Offense with all the keys to blame, but they are in: HKEY_LOCAL_MACHINE \ SOFTWARE \ Policies \ Microsoft \ Windows \ WindowsUpdate \

The first key is a DWORD key named TargetGroupEnabled. You can give the value 0 to the key, by yourself having enabled client side targeting, or 1, which includes the position of the client side targeting.

The second key, which is guilty, must be called TargetGroup and the number of mothers is different. The meaning of the key is the name of the group, up to which the computer is assigned.

Installing the WSUS Server

As soon as the design of the hem is made up to the robot with the hem, you know, that the design of the hem is tendency to change in an hour. Such speeches, as a growing company, new to security and corporate interconnection, often lie in the basis for changing the net. How about new Windows? WSUS is scaled up and can be set up in an architectural way. This means that the organization can have a number of installed WSUS servers. As the PC moves to the company's part, the WSUS server, which is a collection of values ​​for your computer, may no longer be suitable for a new mission. Happily, a few simple modifications to the registry can help change the WSUS server, from which PC will be able to display the update.

There are two keys, which are used to identify the WSUS server. Leather stitches from them in: HKEY_LOCAL_MACHINE \ SOFTWARE \ Policies \ Microsoft \ Windows \ WindowsUpdate \. The first key is called WUServer. For this key, you need to specify a text value that describes the URL of the WSUS server (for example: http: // servername).

The main key, which is required to change - the whole key under the name WUStatusServer. The idea behind this is that the computer (PC) is responsible for its status to the WSUS server in such a rank, that the WSUS server is of noble status, as it was installed on the computer. The WUStatusServer key is called to revenge the same value as the WUServer key (for example: http: // servername).

Automatic Update Agent

Otzhe, I told about those how to connect the computer (PC) to the singing WSUS server of the target group, but only half of the process. Updating Windows Update is an update agent, which is an update agent. Є A number of keys in the registry, which can be repaired in HKEY_LOCAL_MACHINE \ SOFTWARE \ Policies \ Microsoft \ Windows \ WindowsUpdate \ AU and the automatic update agent control.

The first of these keys is the whole key of AUOptions. A number of DWORD parameters can be assigned a value of 2, 3, 4 or 5. A value of 2 means that the agent is guilty of being responsible when the update is blocked. A value of 3 means that the update will be automatically locked, and the update will be notified about the update. A value of 4 means that the update is automatically locked up and installed according to the plan. In order for the option to work, it is also necessary to set the values ​​for the keys ScheduledInstallDay and ScheduledInstallTime. I will give a report about all the keys to the bottom. I nareshty, value 5 means that it is necessary to update automatically, but it can be adjusted by kintsev koristuvachi.

The key that I want to talk about is the AutoInstallMinorUpdates key. The whole key can accept the value 0 or 1. If the value of the key is 0, then minor updates will be updated if it is. If the value of key is 1, then minor updates are quietly installed in the background.

The most important key for the Automatic Update Agent is the DetectionFrequency key. The key is allowed to be given, as the agent is often guilty of turning around for new developments. The value of the key can be used only in the number of 1 to 22, which represents the number of years in the course of development.

Bindings from them the reєstroy key is the DetectionFrequencyEnabled key. The name of the key allows you to enable or disable the Detection Frequency function. If the value of the key is set to 0, then the value of the DetectionFrequency key is ignored, and if the value of the key is set to 1, then the agent will be guilty of the value of the DetectionFrequency key.

The offensive key, about which I want to be resolved, is the NoAutoUpdate key. As soon as the value of the key is 0, the automatic update is switched on. As soon as the key value is door 1, it is automatically updated.

The rest key to the restore, which I want to talk about is the NoAutoRebootWithLoggedOnUsers key. Yak vi, ymovіrno, you know, deyakі upgrading can’t be done without rewiring the system. Yaksho koristuvach u tsei chas pratsyuє, then re-zapping can be even more unimportant. It’s especially true, as long as the criminals were seen from their workmanship, and they didn’t take their work. The key NoAutoRebootWithLoggedOnUsers can help a whole lot of them. The value of the key can be 0 or 1. If the value of the key is 0, the key values ​​are set to 5 before the change, as the system will automatically go to the rewrite. As long as the key is given 1, then the key is simply rejected as soon as possible;

Visnovok

Find more keys to the Windows registry. About the sieve from them, I will tell you from another part of the statistics.

www.windowsnetworking.com


Also wonder:

Readers Comments

Exchange 2007

If you want to read the front part of the series of articles, go for the best: Monitoring Exchange 2007 with the help of the System manager ...

Intro I want to show you the process of transitioning from the current Exchange 2003 middle age to the latest statistics from some parts.

If you missed the first part of the whole series, be a weasel, read the Vikoristanny's help for the Exchange Server Remote Connectivity Analyzer Tool (Part ...

If you missed the front part of the series of articles, go to Monitoring Exchange 2007 with the help of the System Center Operations manager ...

Everyone is grateful for themselves, and the list of servers is updated for Windows Update. For some reason, in good time, well, on the other hand, if you rejected the pardon, the update was not known when the WSUS role was installed, for, for whatever reason, you want to ban them, for the economy of traffic, especially Windows is not very good for you, it’s so In the luckiest versions, I think there is no sense in the sensu nagaduvati about the pardon, if you want the list you can keep going further. The reason is not important, the smut of the nobility, but it is also possible that it is pratsyuvati. Below I will show you the methods of fence the address of the server update microsoft, which is universal, which is suitable for an okry computer, as well as for centralized management within an enterprise.

What Windows has not been installed

The axis of the screen shot of the pardon if you do not have the address of the Microsoft update server. Yak bachite, the gravy is not very informative. I will take the role of WSUS on the server, but it’s not a memory, but it’s also a local center of innovation for enterprises, for economy of traffic, and the axis here, for example, does not install Windows update through the inaccessibility of Microsoft servers.

Robiti, as not to install Windows updates

  • We should be guilty of reconciling why you have an Internet connection, which is why there is a need for a large number of people, because you do not have an Active Directory domain, but you will use your WSUS
  • As far as the Internet є, marveling at the pardon code, it’s also necessary for new information about the latest problems (for the rest of the problems, I can aim the butt, as you see Pomilka 0x80070422, or the Pomilka c1900101 itself can be kept like that)
  • Converted on my proxy servers, there is no fence to such a server address is updated microsoft.

The list of servers itself onovlen microsoft

  1. http://windowsupdate.microsoft.com
  2. http: //*.windowsupdate.microsoft.com
  3. https: //*.windowsupdate.microsoft.com
  4. http://crl.microsoft.com/pki/crl/products/MicProSecSerCA_2007-12-04.crl
  5. http: //*.update.microsoft.com
  6. https: //*.update.microsoft.com
  7. http: //*.windowsupdate.com
  8. https://activation.sls.microsoft.com/
  9. http://download.windowsupdate.com
  10. http://download.microsoft.com
  11. http: //*.download.windowsupdate.com
  12. http://wustat.windows.com
  13. http://ntservicepack.microsoft.com
  14. https://go.microsoft.com/
  15. http://go.microsoft.com/
  16. https://login.live.com
  17. https://validation.sls.microsoft.com/
  18. https://activation-v2.sls.microsoft.com/
  19. https://validation-v2.sls.microsoft.com/
  20. https://displaycatalog.mp.microsoft.com/
  21. https://licensing.mp.microsoft.com/
  22. https://purchase.mp.microsoft.com/
  23. https://displaycatalog.md.mp.microsoft.com/
  24. https://licensing.md.mp.microsoft.com/
  25. https://purchase.md.mp.microsoft.com/

Problems with the security of the numerical system are resolved, a complex of problems is brought up, one of which is the timely updating of operating systems and software security.

Entry

For the preparation of the current standard of operating systems and software security of the information systems of the company, there are regular updates. This can be viewed from the Microsoft Update site with a skin client computer, or behind an additional Windows Server Update Services (WSUS) server / servers. If we are talking about a corporate fringe, then the recommendation option is a WSUS server victorian. When using a designated service, the Internet traffic is reduced and the possibility of centralized kerfing through the process of unloading the system and software security, acquired by Microsoft, is not provided.

Would like it to mean that on March 23, 2011 Microsoft announced the new Windows Intune product, one of the functions that would be the same as the previous announcement to WSUS.

To secure the functionality of upgrading computers in clients, you need:

1. Viconati project

2. Create a server / WSUS server;

3. Ensure regular synchronization of the WSUS server from the Microsoft Update resource;

4. Set up parameters for the WSUS server / server robots;

5. Create target groups and upload client computers from target groups to WSUS servers.

6. Nalashtuvati clients victorian servers WSUS;

7. Make sure to secure the WSUS server / servers.

We do not have a view of the stages of projecting and rooting, synchronization, and more about setting up clients and securing the security of the WSUS server.

Nalashtuvannya server clients

Setting up clients on the WSUS server victorian in three ways:

  1. vicarious group policy;
  2. vikorystannya local computer policy;
  3. Bezposredn introduced changes to the re-establishment of stations of clients.

In the nicest way є victorian Ob'ktiv Group Policy div. rice. 1, tied to the required AD container (for Windows 2003) or AD DS (for Windows 2008), however, the same option can be removed from the list, as the Active Directory directory service is deployed in the organization. The ability of the group policy to adjust the interaction with the server management and management of the procedures for updating the clients will make it easier for the administrator to use it. For some reason, we can turn over by looking at fig. 1. Change of available layering to reach wide.

Small. 1. Installing the WSUS client.

If the service to the catalog in the organization is not open, then the implementation of the possibility of the client's modality from WSUS is possible either for additional local policy, or by way of direct introduction of changes to the system registry of the workstation, if I want to forget the server. On the basis of the policy, it is not the same as the interface to the registry.

Furnish, for some workstations and servers that are not AD clients, there can be a variety of options, for example:

· Vikoristannya service to the catalog of third forms, however, like servers of additional data, file servers, working stations of clientele vikoristovuyutsya solutions on the basis of Microsoft operating systems;

· The need to induce a "guest" zone to provide access to the "call" of the host to the Internet;

· The lack of "maturity" of the company, through the centralization of the service, the catalog is not flashed, for the visibility is consumed by the designated services.

1. It is necessary to distribute the update service in the statistics server, as well as the distribution of clients by groups.

Have razdіlі reєstru

It is necessary to specify the address, for the name of the server is updated, until the client is used and the number of the port, which is addressed to the robot with the WSUS server. For umovchannyam rely on the uvaz 80th port.

"WUStatusServer" = http://192.168.1.100

Oscillations are required to distribute computers in clients from central groups, then we are responsible for assigning computers to those in central groups:

"TargetGroupEnabled" = dword: 00000001

Our variant of the target group is called "WSUS-Test-WKS". For customers, who are the whole group, who will be the only ones, the whole field will have more meaning. The TargetGroupEnabled parameter is used to protect the control of the group from the side of the client.

For all the razdіlі reєstru

"TargetGroup" = "WSUS-Test-WKS"

"TargetGroupEnabled" = dword: 00000001

"WUServer" = "http://192.168.1.100"

"WUStatusServer" = "http://192.168.1.100"

"NoAutoUpdate" = dword: 00000000

"AUOptions" = dword: 00000004

"ScheduledInstallDay" = dword: 00000000

"ScheduledInstallTime" = dword: 00000009

"UseWUServer" = dword: 00000001

"RescheduleWaitTime" = dword: 00000001

" NoAutoRebootWithLoggedOnUsers "=dword: 00000000

Having secured the delivery of the specified file, it is possible to set up the WSUS server clientele, not until the group policy victorious. For a description of the best resourcing tools that can be used for robots with a server, see the Windows Server Update Services 3.0 SP2 Deployment Guide.

For the security of the server itself, there are a number of simple recommendations:

1. As far as we need to ensure secure information exchange between clients and servers and / or between WSUS servers, then the ability to transfer to the SSL protocol is transmitted. Contact the Windows Server Update Services Deployment Guide () for the "Securing WSUS with Secure Sockets Layer" distribution. For the duration of the stitching exchange between the servers, the transferred tributes will be taken care of at the viglyadi of the new bearing. An alternative way to hijack, for the ill-health of SSL, is to secure the IPsec protocol. Div. "Overview of IPsec Deployment" http://go.microsoft.com/fwlink/?LinkId=45154.

2. The WSUS server, which synchronizes with Microsoft Update, will then move behind the firewall and gain access to all the universities that they need to operate. Div. I distributed "Configure the Firewall" from the Windows Server Update Services Deployment Guide (http://go.microsoft.com/fwlink/?LinkId=79983).

3. As for file access, it is not necessary to push overworldly permissions on the resources, the description of access rights can be found in the "Before You Begin" section of the Windows Server Update Services Deployment Guide (http://go.microsoft.com/fwlink/? LinkId = 79983).

4. If the update server has access to the Internet (for a number of users it may not be possible, for example, to see synchronization with the WSUS server, which is possible), then it is recommended that this database is available for non-available computers. “Appendix B: Configure Remote SQL” from the Windows Server Update Services Deployment Guide (http://go.microsoft.com/fwlink/?LinkId=79983).

5. For keruvannya by the WSUS server it is reasonable to vikoristovuvati vbudovan group WSUS Administrators, as it will be shut down when rozgortannі.

Leonid Shapiro.

List of literature.

Anita Taylor Windows Server Update Services 3.0 SP2 Deployment Guide.

Anita Taylor Windows Server Update Services 3.0 SP2 Operations Guide

[i] DMZ - demilitarizedzone

Not everything is looked at here, depriving the main parameters of the WSUS client setting.

You can go to the shukannyh servers as if for an additional address, which was broken in the directed application, as well as for the additional name of the server, having transferred the option to allow the name of the server in its IP-address.

Here the abstract іm'ya test group is induced.

With the development of the Internet, the continuous update of the operating system has become a beastly phenomenon. Now the dealers can correct that additional system by extending the current term and condition. As for parts of Windows 10, don't get it right. The very thing is good inside the keys.

Reasons for automatic updating

Reasons can be different, and only you can see it, if you need to enable the update. With a lot of varto vrahovuvati, at once, because of the reduced quiet of the possibilities, you will start to improve the efficiency of the system's urges. But all the same, the situations, if independent updates are enabled, often come to fruition:

  • Paid internet is an update that is even great, and it can be expensive if you pay for traffic. In such a case, it is more beautiful than the power of entangling and enhancing for other minds;
  • It’s not easy for an hour - when the update is overridden, it’s over and over again in the process of running the computer. It may not be handy, if you need to quickly complete a robot, for example, a laptop. If you don't want to restart your computer early enough, Windows 10 will be able to restart your computer, but if you don’t miss it, then after an hour you will restart the primus. All the prices are correct;
  • Bezpeka - by its own means, I would like to often take revenge on the important corrections of the system, but it is impossible to transfer everything. As a result of one update, you can open your system for a viral attack, and simply destroy the robot immediately upon installation. Reasonable pidhіd at the tsіy situation - they catch up in a ten hour to the entrance of the Chergovy version, having inserted the widgets in front of them.

How to automatically update Windows 10

There are many ways to get Windows 10 updated. Deyakі from them is much simpler for a koristuvach, іnshі folding, and the third is to establish third-party programs.

Vimknennya through the center of new development

Vikoristannya center for connection is not the best option, I would like to propose it as an official solution for Microsoft. You can vimknuti automatically entangled updates through їх nalashtuvannya. The problem here is that the price of the solution is so fast. The release of the great Windows 10 update to change the price of the new system. Ale mi is all one vivchimo connection process:

When there is little change, there is no longer any improvement. Alle the solution is not possible for you to get used to the entangled update.