Wsus disable online check gpo and prevent from updates

Gracjan Podłęcki 61 Reputation points
2020-11-20T14:45:13.147+00:00

Hi Everyone

How to do that:

All our computers (windows 10) uses WSUS as a default update server and that is ok for us.
To prevent users from checking online updates when they are outside the company we set gpo :

  • Computer Configuration/Administrative Templates/System/Internet Communication Management/Internet Communication settings
    Turn off access to all Windows Update features = Enabled

But crucial for us is to how modify wsus gpo to achieve:

when user is outside the company then can check updates, download and install(security, important) but not to get and install "big" updates like version updates (1903>recent 20H2)

thx

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
10,673 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,179 questions
0 comments No comments
{count} votes

Accepted answer
  1. Rita Hu -MSFT 9,626 Reputation points
    2020-11-23T06:41:36.29+00:00

    Hi GracjanPodcki-6418,

    Thanks fr your posting on Q&A.

    It is recommended to apply the below policy to see whether this issue will be resolved or not:
    [Select when Preview Builds and Feature Updates are received]
    Path: Computer Configuration\Administrative Templates\Windows Components\Windows update\Windows Update for business

    Reference picture:
    41805-2.png

    We could test it on a tested computer first. If the policy work normally, we could apply on the all domain.

    If there are any feedbacks about this solution, please keep us in touch.

    Regards,
    Rita


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Gracjan Podłęcki 61 Reputation points
    2020-11-25T10:58:55.68+00:00

    Hi

    Thx for advice but one question
    If i exclude machine from wsus company policy and add machine to this policy above
    Does my computer would be allowed to download and install other updates automatically?