WSUS Windows Server 2016: Installation and Configuration

-

|

What is WSUS Windows Server 2016?

WSUS Windows Server 2016 is a Microsoft Server role that allows download and installation of Operating System updates to computers in a local network.

System Administrators use WSUS (Windows Server Update Service) to create computer groups to ease patch management. Besides, Windows Server Update Service server can also generate compliance reports to determine computers that need specific updates.

In this tutorial you will learn how to:

  • Install and configure the WSUS Windows Server 2016 Server role
  • Configure group policies for WSUS Windows Server 2016 updates
  • Set up Client-side targeting for WSUS Windows Server 2016

If you follow the setup in this tutorial you should be able to setup a working WSUS server infrastructure.

To walk through the installations and configurations discussed in this tutorial, you need a Domain Controller, 2 WSUS servers (one as upstream, another as downstream server) and a Windows 10 Client computer. All computers must be members of the AD Domain.

Advertisement


Steps to Install and Configure WSUS Windows Server 2016 Server Role

Here are the steps to install and setup Windows Server Update Service in Windows Server 2016

1
Setup Servers that Meet WSUS Installation Requirements

Before you install WSUS Windows Server 2016 role, you need to confirm that your server meets the requirements. Below are the requirements.

System Requirements for Installing WSUS Role

  • Processor: 1.4 gigahertz (GHz) x64 processor (2Ghz or faster is recommended)
  • Memory: WSUS server requires an additional 1.5GB of RAM – above and beyond what is required by Windows Server 2016.
  • Available disk space: 10 GB (recommended: 40GB or more)
  • Network adapter: 100 megabits per second (Mbps) or greater

Other WSUS Windows Server 2016 Role Installation Requirements

  • If there is a pending restart requirement, restart the server before you enable the Windows Server Update Service server role.
  • Additionally, Microsoft .NET Framework 4.5 must be installed on the server.
  • The NT Authority\Network Service account must have Full Control permissions for the following folders:

%windir%\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files and %windir%\Temp folders. This path might not exist prior to installing Internet Information Services (IIS).

  • Finally, the installation account must be a member of the Local Administrators group

WSUS Windows Server 2016 Database Requirements

At least one of these databases is required:

  • Windows Internal Database (WID)
  • Microsoft SQL Server 2017
  • MS SQL Server 2016
  • Microsoft SQL Server 2014
  • MS SQL Server 2012
  • Microsoft SQL Server 2008 R2

Additional Installation Requirements

Apart from the requirements listed above, below are further considerations and requirements:

  • You can install WSUS server role and the database server on separate computers. However,
  • The Database server cannot be a Domain Controller.
  • Also, the WSUS server cannot run Remote Desktop Services
  • The Database server and the WSUS server must be in the same AD Domain. If in different domains, the domains must have a trust relationship.
  • Finally, the two servers must be in the same time zone or be synchronized to the same GMT time source.

Advertisement


Perform WSUS (Windows Server Update Service) Pre-installation Tasks

Before you install Windows Server Update Service role, perform the following tasks:

  • Add the Domain Admin account as member of the Local Administrators group on the server you wish to install WSUS role: Open Server Manager, then click Tools and select Computer Management. On Computer Management, click Local Users and Groups. Double-click Groups then double-click Administrators group. Finally confirm that the installation account is a member of the local administrators group.
WSUS (Windows Server Update Service) - Add the Domain Admin account as member of the Local Administrators group on the server you wish to install WSUS role
  • Confirm that Microsoft .NET Framework 4.5 (4.6 on Windows Server 2016) is installed. If not, install it: Open Server Manager. Then click Add Roles or Features. On the first page click Next. Then select Role-based or Feature-based installation. Click Next until you get to Features.
WSUS pre-installation tasks - Confirm that Microsoft .NET Framework 4.5 is installed
  • Next, confirm that the Network Service account have Full Control permissions to: %windir%\Microsoft.NET\Framework64. Right-click Framework64 and select Properties, then click the Security tab.
Important Tip
To be able to modify the permission of Framework64 you may need to take ownership of the folder. You may also need to add your account to the local administrators group.
  • Confirm that the server you wish to install WSUS role meet the following requirements: Memory is 1.5 GB of RAM – above and beyond what is required by Windows Server 2016. Available disk space: 10 GB (40 GB or greater is recommended). Finally, confirm that your network adapter is 100 megabits per second (Mbps) or greater.
Note
For Windows Server 2016 hardware requirements read Windows Server 2016: A cheat sheet

2
Install WSUS Windows Server 2016 Server Role

Now you are ready to install WSUS. Follow the steps below:

  • Log on to the server and open Server Manager (should normally open by default).
  • From Server Manager (top right corner), click Manage then select Add Roles and Features.
Install WSUS (Windows Server Update Service) - add roles and features
  • On the “Before you begin” page, click Next.
  • On the “Select Installation type” select “Role-based or feature-based installation” and click Next.
Windows Server Update Service
  • Next, on the “Select Destination server page”, select the server you wish to install WSUS (Windows Server Update Service) role and click Next.
  • Next page presents option to select the roles you wish to install. Check the boxes beside Windows Server Update Service. A page will load asking you to confirm additional features to install. Click Add Features. Then click Next.

Advertisement


  • The “Select features” page loads. To proceed click Next.
  • Note the information in the Windows Server Update Services page. Then click Next to proceed.
  • Review the features checked below. Then click Next.
  • Enter a local or remote path to store updates.
  • On the Web Server (IIS) Role information page, read the information then click Next to proceed.
  • Then review the server roles and features you selected. Click Next.
  • Finally, on the confirmation page, review your selections. Check the box Restart the destination server automatically if required and click Install.
WSUS (Windows Server Update Service) - roles installation confirmation page

WSUS role may also be installed by running the PowerShell command below:

Install-WindowsFeature -Name UpdateServices -IncludeManagementTools

Advertisement


3
Configure WSUS Windows Server 2016 Using the WSUS Configuration Wizard

After installing WSUS Windows Server 2016, the next step is configuration. To configure the role:

  • Open Server Manager and click the yellow amber triangle. Then select Launch Post-installation tasks. Wait for the post-installation task to complete. Then proceed to the next step.
  • Still on Server Manager, click Tools then select Windows Server Update Services.
  • Read the information on the “Before you begin” page, then click Next to proceed.
WSUS (Windows Server Update Service) - configuration
  • Next, decide whether you wish to join the Microsoft Update Improvement Program or not. Click Next.
  • The next stage is very critical as this is where you decide the WSUS Server that connects to Microsoft Updates Server. Select Synchronize from Microsoft Update. Then to proceed click Next.
  • If you require a proxy server to connect to the internet, configure it here.
  • Read the relevant information on the Connect to Upstream Server page then click Start Connecting.
WSUS (Windows Server Update Service) - connect to Microsoft Update server
Important Tip
The previous step may take sometime to complete depending on your internet connection.
  • Once the connection task is completed, click Next.
  • Select the languages to download then click Next. I am downloading just English.

Advertisement


  • Choose the products you wish to download updates for. If you are in a production environment, download updates for all products in your environment.
  • Decide updates classification to download. In most cases the defaults are okay.
WSUS (Windows Server Update Service) - Decide updates clarification to download
  • Decide how you wish to synchronize your WSUS server with Microsoft Updates server. In a production environment, this has a lot of implications. Consider the number of updates to download, and your internet bandwidth.
  • On the Finish page, check Begin initial synchronization and click Next. Then click Finish.
WSUS (Windows Server Update Service) - Begin initial synchronization

4
Configure Downstream Servers for WSUS Windows Server 2016

In a production environment with computers in different locations, a downstream server may be required. The downstream server will download updates from your upstream server and distribute the updates to computers in its local network. This way, you avoid updates installing over WAN links.

The steps below will walk you through how to configure a downstream WSUS Windows Server 2016 server.

Important Tip
To perform this task you would have installed Windows Server Update Service role on the downstream server. Moreover, you should also perform post-installation task.
  • Log on to the second WSUS server. From Server Manager click Tools then Select Windows Server Update Services.
  • On the Before you begin page, click Next.
  • Decide whether to join the Microsoft Update improvement program or not. Click Next to proceed.

Advertisement


  • On the Choose Upstream Server page, enter the name of your upstream WSUS server. Then check the boxes Use SSL when synchronizing update information and This is a replica of the upstream server. To proceed click Next.
WSUS (Windows Server Update Service)
Important Tip
Depending on your environment, you may decide not to configure the downstream server as a replica of the upstream. However, it is strongly recommended to use SSL.
  • On the Specify Proxy Server page, click Next.
  • Finally, to synchronize with the upstream WSUS server, click Start Connecting.
WSUS (Windows Server Update Service)
Important Tip
If you receive HTTP error, check that your upstream server is configured to accept SSL connection. Alternatively, you could go back and uncheck Use SSL when synchronizing update information.

Continue with Downstream Server Configuration

In the last task when you click Start Connecting, it may take sometime for the wizard to process your request.

  • When the Next button becomes available, click it to proceed.
WSUS (Windows Server Update Service)
  • Compared to the same screen when we configured the upstream server, the only available language is English. Click Next to proceed.
WSUS (Windows Server Update Service) -
  • Earlier in the tutorial we configured sync schedule for the upstream server. Do the same below. If you are working in a production environment, be sure to set the time below to happen after the upstream server has synced.

Advertisement


  • Finally, check Begin initial synchronization box then click Finish.

5
Configure Group Policies for WSUS Windows Server 2016 Updates

The next step is to use group policy settings to automatically configure WSUS.

Important Tip
In a complex production environment, you can create different Group Policy Objects (GPOs) and link them to different Organizational Units (OUs). For this tutorial, I will link a single GPO to the top of the domain.
  • To begin, login to the Domain Controller. Open Server Manager, click Tools then select Group Policy Management.
Important Tip
To get to the Domain, you may need to expand the Forest container then expand the Domain container.
  • Next, make a copy of the Default Domain Policy GPO. To do this expand the Group Policy Objects container. Then Drag the Default Domain Policy GPO into the Group Policy Objects container.
  • Then, on the Copy GPO dialogue box, accept the default permission and click Ok. The GPO will be copied. Click Ok on the copy dialogue box.
  • A new GPO, Copy of Default Domain Policy is created.
  • It is a good idea to rename the copied GPO to a more memorable name. I called mine “WSUS GPO”. To rename the GPO right-click it then select Rename. In the next step, you will edit the GPO and configure WSUS settings

Advertisement


WSUS (Windows Server Update Service) - navigate to Windows Update GPO

Configure GPO for WSUS Windows Server 2016

Now that you have created a GPO for WSUS Windows Server 2016, next step is to configure the GPO settings.

  • To begin, right-click the new GPO and select Edit. The Group Policy Management Editor opens.
WSUS (Windows Server Update Service)
  • Beneath the Computer Configuration container, expand Policies. Then navigate to \Administrative Templates\Windows Components. Click Windows Update. Finally, beneath the window select the Standard tab.
  • In the details pane, double-click Configure Automatic Updates. On the GPO settings, select Enabled, then configure automatic updates settings. Read the help page (right) to help you make a choice to meet your requirement. When you finish click Ok to save your changes.
WSUS (Windows Server Update Service)
  • Back to the Group Policy Management Editor double-click the Specify intranet Microsoft update service location policy.
  • Click the Enable option. Then on the Set the intranet update service for detecting updates and Set the intranet statistics server boxes, enter the WSUS server name you wish to use. Enter in the format shown. Finally, click Ok to apply your changes.
Important Tip
If you used a different port number, remember to include it here. Also as important is the SSL option. If your server is configured for SSL, use https, otherwise use http.
  • Before you close Group Policy Management Editor confirm that the two policy settings (highlighted in red below) are Enabled. Then close the editor and proceed to the next step.

Link the WSUS Windows Server 2016 GPO to a Container

As I said earlier, you can link your WSUS GPO to OUs or directly on the domain. Best practice is to link the GPO to OUs containing your Computers. For this tutorial though, I will be linking the GPO to the domain.

  • To link the WSUS GPO to a container, drag it to the container. Mine is linked to the domain. You will be prompted to confirm the link. Click Yes.
  • The GPO is now linked to the domain!

Final Notes Regarding WSUS (Windows Server Update Service) GPO

Computers in the container are expected to accept the configuration in the GPO. When a computer updates the GPO it should appear in the WSUS (Windows Server Update Services) console.

Computers may take up to 30 minutes to show up in WSUS console. To force GPO update on a computer, run the command below from the computer:

gpupdate /force

To force a computer to be detected immediately by the WSUS server, execute the command below:

wuauclt.exe /detectnow

Advertisement


6
Configure Client-Side Targeting for WSUS Windows Server 2016

Client-side targeting, configured via Group Policy is used to add computers to WSUS groups. The WSUS group a computer belongs determines the updates that will be applied to it.

When client-side targeting is enabled, client computers identifies WSUS computer groups they should be added to. The information is sent to the server when the client communicates with the server. The WSUS server then uses the information received from the client to determine which updates are deployed to the client computer.

The steps below will walk you through enabling client-side targeting via group policy.

  • Log on to the Domain Controller and open Group Policy Management (via Server Manager).
  • Next, right-click the GPO you created earlier and select Edit. Group Policy Management Editor opens. Navigate to \Administrative Templates\Windows Components. Click Windows Update
  • In the details pane, double-click Enable Client-side targeting Policy.
WSUS (Windows Server Update Service)
  • Enable the policy. Then on the Target group name for this computer, enter the name of the WSUS group. Click Ok to save your changes.
Important Tip
The name of the group entered above must be created under the All Computers container in WSUS.

There you have it – WSUS installation and configuration! If you have any questions or comments, use the “Leave a Reply” form below.

Other Helpful Guides

Additional Resources and References

LEAVE A REPLY

Please enter your comment!
Please enter your name here

FEATURED POSTS

How to Share a Folder in Windows 10 (3 Methods)

Introduction This guide demos how to share folder in windows 10. It covers 3 methods. Options...

How to Map Network Drive in Windows 10 (5 Methods)

Introduction This guide demos 5 methods to Map Network Drive in Windows 10. Options to...
How to Install Windows 10 1909 Preview Build

How to Install Windows 10 19H2 Preview Build

Introduction If you are a member of Windows 10 Insider Program you can install Windows 10 19H2 Preview Build....

How to Sign in to Windows 10 with a Microsoft Account

Introduction When you installed Windows 10 you may have created and signed in with a local account. You can...
Disable IPv6 in Windows 10

How to Disable IPv6 in Windows 10 (3 Methods)

Introduction This guide demos 3 methods to disable IPv6 in Windows 10: Disable IPv6 from...

Advertisement

TRENDING POSTS

Remote Desktop Connection

Remote Desktop Connection an Internal Error Has Occurred [Fixed]

Introduction I recently received the error message "Remote Desktop Connection an Internal Error Has Occurred". It was strange because...

Find My Samsung: Register and Use Samsung Find my Mobile

Introduction Ever wondered how you could find your Samsung phone if you lost it? Find my Samsung or Samsung...
What is the Difference Between PowerShell and CMD?

Windows Powershell vs CMD: Differences and Similarities

Introduction This short guide compares Windows PowerShell vs CMD (Windows command prompt). I will cover the history and nature...
Spotify No Longer Supports this Version of Microsoft Edge

Spotify No Longer Supports this Version of Microsoft Edge [Fixed]

Introduction When you open Spotify web player on Microsoft Edge, you may receive the error message "Spotify No Longer...
Windows 10 Won't Boot

Windows 10 Won’t Boot With Black Screen? 3 Ways to Fix It

Why Won't Windows 10 Boot Up? If your Windows 10 stops with a black screen, the first question in...

Advertisement

BEST OF ITECHGUIDES

DISM.exe /Online /Cleanup-Image /Restorehealth

DISM.exe /Online /Cleanup-Image /Restorehealth Explained

What is DISM.EXE /Online /Cleanup-image /RestoreHealth? "DISM.exe /Online /Cleanup-Image /Restorehealth" is a DISM command that repairs issue with the...
dropbox login

Dropbox Login: Your Ultimate Guide to Dropbox

Introduction Dropbox login allows you to sign in to and use Dropbox. But what is Dropbox? Let's kick off...
windows 10 lock screen timeout

How to Change Screen Time Out Setting in Windows 10

Introduction There are two easy ways to change Windows 10 lock screen timeout settings: Desktop...
internet explorer has stopped working

Internet Explorer Has Stopped Working [Fixed]

Introduction If you receive "Internet Explorer Has Stopped Working" error, it may result in some of these symptoms:
C:\G-Drive\Work Tools\Products Portal\1. New Business\2. Content Sites\1. iTechGuides.com\Posts\2. FIX IT\Microsoft\Windows 10\remote desktop can't connect to the remote computer

How to Fix “Remote Desktop Can’t Connect to the Remote Computer”

Introduction Recently, I tried to RDP to a computer and received the error message "Remote Desktop can't connect to...

RECENT POSTS

How to Enable Hyper-V in Windows 10 (3 Methods)

How to Enable Hyper-V in Windows 10 (3 Methods)

Introduction This guide demos 3 methods to enable Hyper-V in Windows 10. To install Hyper-V...
RSAT Tools in Windows 10 Explained: Plus How to Install RSAT

RSAT Tools in Windows 10 Explained: Plus How to Install RSAT

Introduction Starting from October 2018 (1809) update, RSAT Tools became part of Windows 10. From this version of Windows...

How to Enable RSAT for Active Directory in Windows 10 (3 Methods)

Introduction This guide demos 3 methods to enable Active Directory in Windows 10. It is not exactly enabling "Active...
How to Install Windows 10 1909 Preview Build

How to Install Windows 10 1909 (19H2) Preview Build

Introduction Windows 10 1909 Preview is available for Windows Insiders. Made available early September, 2019 you have to be...
How to Install RSAT in Windows 10 (3 Methods)

How to Install RSAT in Windows 10 (3 Methods)

Introduction This guide demos how to Install RSAT in Windows 10. Starting with Windows 10...

How to Share a Folder in Windows 10 (3 Methods)

Introduction This guide demos how to share folder in windows 10. It covers 3 methods. Options...
Configure Map Network Drive with Group Policy

Map Network Drive in Windows 10 with Group Policy

Introduction This guide demos how to map network drive with group policy. This guide is...

How to Map Network Drive in Windows 10 (5 Methods)

Introduction This guide demos 5 methods to Map Network Drive in Windows 10. Options to...
How to Download Windows 10 ISO with Media Creation Tool

How to Download Windows 10 ISO with Media Creation Tool

Introduction This guide demos the steps to download Windows 10 ISO. You can download Windows 10 ISO with Media...

How to Install Windows 10 from Network Boot (Via WDS Server)

Introduction This guide demos how to install Windows 10 from network boot. The steps discussed in...

Advertisement

MUST READ

change computer name - rename a windows 10 pc

4 Methods to Rename (Change the Name of) a Windows 10 PC

Introduction This guide demos 4 methods you can use to change computer name for a Windows 10 PC. You...
DISM.exe /Online /Cleanup-Image /Restorehealth

DISM.exe /Online /Cleanup-Image /Restorehealth Explained

What is DISM.EXE /Online /Cleanup-image /RestoreHealth? "DISM.exe /Online /Cleanup-Image /Restorehealth" is a DISM command that repairs issue with the...
Amazon best sellers

Amazon Best Sellers: Your Definitive Guide to Find Them

What are Amazon Best Sellers? Amazon Best Sellers are the most popular products on Amazon, based on sales. Amazon...

How to Create System Image in Windows Server 2016

Introduction This guide demos how to create system image in Server 2016. Steps to Create...
windows server 2016 router configuration

How to Configure Windows Server 2016 as a Router

Introduction This guide demos Windows Server 2016 router configuration. It walks you though how to configure Windows Server 2016...

By using this website you agree to accept our Privacy Policy and Terms & Conditions