HomeMicrosoftHow to Windows Server Update Services Setup in Server 2022

How to Windows Server Update Services Setup in Server 2022

Let’s have a look at the Windows Server Update Services setup in Windows Server 2022. This guide will help you if you have a plan to install and configure WSUS Microsoft. I have decided to write this article exclusively for Windows administrators who need to install and configure Windows Server Update Services to manage Windows updates in their organization.

What are Windows Server Update Services?

WSUS Lab Setup

First, let me cover about Window Server Update Services lab setup. In this scenario, I have chosen Windows Server 2022 to install and configure WSUS.
I have installed a few virtual machines in my test lab. Here you can find a list of machines and operating system information.

Server NameRolesRoles Operating System
DC2022Active Directory, DNS, DHCPWindows Server 2022
WSUSWindows Server Update ServicesWindows Server 2022
Windows10Client ComputerWindows 10 Pro

System Requirement WSUS

Please visit Microsoft’s Official Website.

WSUS Firewall Ports for WSUS

When we set up the Windows Server Update Services server, it is important that the WSUS server connect to Microsoft Update to download updates. If you have a corporate firewall between the Internet and the WSUS server, you may need to configure that firewall to ensure WSUS can receive updates.

http://windowsupdate.microsoft.com
http://.windowsupdate.microsoft.com https://.windowsupdate.microsoft.com
http://.update.microsoft.com https://.update.microsoft.com
http://.windowsupdate.com http://download.windowsupdate.com https://download.microsoft.com http://.download.windowsupdate.com
http://wustat.windows.com
http://ntservicepack.microsoft.com
http://go.microsoft.com
http://dl.delivery.mp.microsoft.com
https://dl.delivery.mp.microsoft.com

Install WSUS Role Server 2022

The steps to install Windows Server Update Services Role on Windows Server 2022.
Log on to your Windows 2022 server.
In Server Manager, click Add Roles and Features.

Server manager

Click next

Add roles and features wizard

Select next

Select Role based or feature based installation

Verify the server name, and then click next.

Select the server to install WSUS

On the Server Roles page, choose the checkbox Windows Server Updates Services.

Select Windows Server Update Services role

Click Add Features and then click next

Add features WSUS role

Select next

Add role and features

In the Windows Server Update Services window, click next.

Windows server update services

Choose WID Connectivity, WSUS Services, and then click next.

Select WID Connectivity and WSUS Services

Specify a location to store the updates, and then click next.

WSUS Content Location selection

Web Server Role (IIS) window, click next.

Select web server role IIS

The role services to install a web server (IIS) are selected automatically.
Do not change anything here, and just click next.

Select role services

Click the install button to install WSUS.

WSUS role confirm installation selections

Installing Windows Server Update Services roles is in progress.

WSUS role installation progress

After completing the WSUS installation, click Launch Post-Installation Tasks.

Launch WSUS Post Installation tasks

Wait for the configuration to be successfully completed, and then click close.

WSUS configuration completed successfully

Configure Windows Server Update Services

After we install WSUS, we can configure the WSUS server using the WSUS Server configuration wizard. Click on Tools, and then select Windows Server Update Services.

Search Windows server update services

Windows Server Update Service Configuration Wizard, click next.

WSUS Configuration Wizard

Click next

WSUS configuration wizard

This is only a WSUS server; I will choose Synchronize from Microsoft Update and click next.

WSUS Choose Upstream Server

I have no proxy server; click next.

WSUS configuration specify proxy server

Connect to the Upstream Server window, and click on the Start Connecting button.
Download update information from the Windows Update Server.
Once complete, click next.

WSUS connect to upstream server

Choose the Download updates only in these languages option. Choose the languages for which you want updates, and then click next.

Windows Updates Languages

I am going to select Windows Server 2022, Windows 10 1903, and Windows 11 and above. Click next

Select the Microsoft Products

Select Update Classifications Critical Updates, and then click next.

WSUS Update Classifications

Configure the WSUS Sync Schedule and click next.

Configure WSUS Synchronization Schedule

Choose Begin initial synchronization, and then click Next.

Begin WSUS Initial synchronization

Now complete the steps to configure WSUS, and click finish.

Windows server update services configuration

Windows Update Services console.

Windows server update services

WSUS Configure Group Policy Settings

Once you install and configure WSUS, the next important step is to configure group policy settings for automatic updates. Using group policy, we can point our client computers to the new WSUS server.

In the active directory environment, we can use Group Policy, which specifies the Windows Server Update Services server. The group policy settings will be used to receive automatic updates from WSUS.

We can create a group policy and apply it at the domain level. Or we can create and apply the GPO to a specific organizational unit.

Automatic Updates WSUS Configuration

To configure Automatic updates group policy for WSUS
In the Active Directory Server, from the server manager, open the Group Policy Management console.

Search group policy management

I am going to configure GPO on the domain level.
Right-click on your local domain, and then click on Create a GPO in this domain.

Create a GPO in this domain

Enter a GPO name, and then click OK.

Create GPO

Right-click on GPO (WSUS) and click Edit.

Group policy management

Expand computer configuration, expand policies, expand administrative templates, expand Windows components, and then click on Windows Update.

Double-click on Configure Automatic Updates.

Group policy management editor

Set it to enabled.
Configure automatic updating settings as per your requirements, and then click OK.

Configure WSUS Automatic Updates

Open Specify Intranet Microsoft Update Service Location
Click Enabled, Specify the intranet update service and intranet statistics server, and then click OK.

Specify intranet Microsoft Update service location

Open Enable client-side targeting settings
Enable it, enter a target group name, and click OK.

Enable client-side targeting

Verify the intranet update service location on the client system using the registry. Open Registry Editor by typing Registry Editor in the search.

Search Registry editor

Go to HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
Confirm the values of WUServer and WUStatusServer, and then confirm if the values match the ones that we supplied in the WSUS GPO.

Registry editor Windowsupdate

Verify intranet Microsoft Update service location

Update GPO

Gpupdate /force
Wuauclt /resetauthorization /detectnow
Wuauclt /reportnow

Gpudate commnad

Configure WSUS Computer Groups

When we launch the WSUS console, we will find two default computer groups
All computers and unassigned computers.
To create a new computer group on the WSUS Server
In the Update Services Console, under Update Services, expand WSUS, expand computers, right-click on All computers, and then select Add Computer Group.

Windows Server update services console

In the Add Computer Group window, enter the name of the new group, and then click Add.

Add new computer group

Select All Computers, and you will see a list of computers. Click on computers, right-click on them, and then select Change Membership.

Change the computer membership

Set the Computer Group Membership window, choose the new group that you just created, and click OK.

WSUS set computer group membership

Choose the target computer group
Select the new group and find those computers.

Windows server update services groups

Select options, and then click on computers.

Windows updates options

Choose the “Use group policy or registry settings on computer” box, and then click OK.

Group policy settings windows updates

Configure Auto Approval Rules in WSUS

If we don’t need to manually approve the Windows updates, we can configure the auto-approval rule in WSUS.
Select Options and click Automatic Approvals.

Windows server update services options

You will find the default automatic approval rule, and if you want, you can edit it and use it.
Click on the New Rule tab to create a new approval rule.

Add automatic approval rule WSUS

Select updates to approve, specify the auto-approval rule name, and then click OK.

WSUS add automatic approval rule

Click Run Rule.

WSUS automatic approval

Select yes

WSUS automatic approval run rule

WSUS running rule.

Updates were approved running rule

Click ok

WSUS automatic approval

Approve and Deploy Updates in WSUS

Expand Updates and then All Updates.
Select the updates that you wish to approve for installation in your computer group.
Right-click on updates and select Approve.

WSUS all updates

Click on the down arrow, and then select approved for installation.

Approve update WSUS

Select your group, and then click the down arrow. Choose Approved for Install and click OK.

WSUS choose approval

The Approval Progress window will pop up, which shows the progress of the tasks that affect update approval. After completing the approval process, click close.

WSUS approval progress

Windows Server Update Services Reports

Click on Reports in the WSUS console, and it will show the list of reports. WSUS comes with some reports to help you find the updated deployment status, computer reports, and sync reports.

Windows server update services reports

These are the steps to install and configure WSUS. I am sure this article will help you set up WSUS. Refer this article how to configure WSUS

Jamil
Jamilhttp://jamiltech.com
A Professional Technology Blog Writer | An energetic professional with more than 20+ years of rich experience in Technology, Planning, Designing, Installation, and Networking.
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -
Google search engine

Most Popular

Recent Comments

what is cryptocurrency and bitcoin on How to Backup and Restore IIS Configuration
경기광주출장안마 on How to Backup and Restore IIS Configuration
영등포출장마사지 on How to Backup and Restore IIS Configuration
Twalsu light mirror for vanity on How to Backup and Restore IIS Configuration
fitspresso analysis on How to Reset Microsoft 365 Password
historical landmarks tours for history buffs on How to Add Hyper-V Server Altaro VM Backup
9780443186882 PDF download on How to Migrate Active Directory 2012 to 2022
Shaik Mohammad Jaheer on How to Enable Night Light on Windows 11