Installing WSUS and applying GPO

Install WSUS

You can do it by GUI guide such as from:


Or you can do it by Powershell (read on).

But be sure to have fully updated your server, or you might not get the server to synchronise with Windows Update.


Script (assuming D:\WSUS allready Exists and proper permission are set:

Check your dependencies with: Install-WindowsFeature -Name UpdateServices -IncludeManagementTools -WhatIf If it's ok, run the command without -WhatIf.


Install-WindowsFeature -Name UpdateServices -IncludeManagementTools

sl "C:\Program Files\Update Services\Tools"

.\wsusutil.exe postinstall CONTENT_DIR=D:\WSUS


Setup the products for which the updates should by synchronised by executing the WSUS Console and select your products within.

Synchronise the updates (which can take long if you have many products selected).

1. You need to create computer groups within WSUS.
2. You need to create a policy (GPO) to specify the clients to use this WSUS server and put them into a specific group.

Little hint:

Notice: The intranet and the statistics server will only receive the clients requests on:


3.Configure your auto approval rules …


After this: create a batch file as follows

wuauclt /detectnow

wuauclt /reportnow

Put this script in GPO Computer configuration > Administrative Templates > Logon Script Apply the scope to which computers it must be applied.

If it does not appear on WSUS, wait for 15 minutes and else I suggest you reboot the computer.