banner



How To Install Wsus Server 2016

How to Install and Configure WSUS in Windows Server 2022

What is WSUS Windows Server 2022?

WSUS Windows Server 2022 is a Microsoft Server role that allows download and installation of Operating System updates to computers in a local network.

Organization Administrators apply WSUS (Windows Server Update Service) to create calculator groups to ease patch management. Also, Windows Server Update Service server can also generate compliance reports to determine computers that demand specific updates.

In this tutorial you lot will acquire how to:

  • Install and configure the WSUS Windows Server 2022 Server role
  • Configure group policies for WSUS Windows Server 2022 updates
  • Set up upwardly Client-side targeting for WSUS Windows Server 2022

If you lot follow the setup in this tutorial you should be able to setup a working WSUS server infrastructure.

To walk through the installations and configurations discussed in this tutorial, you need a Domain Controller, two WSUS servers (i as upstream, another as downstream server) and a Windows 10 Client reckoner. All computers must be members of the Ad Domain.

Steps to Install and Configure WSUS Windows Server 2022 Server Function

Hither are the steps to install and setup Windows Server Update Service in Windows Server 2022

Setup Servers that Come across WSUS Installation Requirements

Before you install WSUS Windows Server 2022 role, you need to ostend that your server meets the requirements. Below are the requirements.

System Requirements for Installing WSUS Part

  • Processor: 1.4 gigahertz (GHz) x64 processor (2Ghz or faster is recommended)
  • Retention: WSUS server requires an boosted 1.5GB of RAM – above and beyond what is required by Windows Server 2022.
  • Available disk space: 10 GB (recommended: 40GB or more)
  • Network adapter: 100 megabits per second (Mbps) or greater

Other WSUS Windows Server 2022 Function Installation Requirements

  • If in that location is a pending restart requirement, restart the server before you enable the Windows Server Update Service server role.
  • Additionally, Microsoft .NET Framework 4.five must be installed on the server.
  • The NT Authority\Network Service account must have Full Control permissions for the post-obit folders:

%windir%\Microsoft.Net\Framework\v4.0.30319\Temporary ASP.Net Files and %windir%\Temp folders. This path might not be prior to installing Cyberspace Data Services (IIS).

  • Finally, the installation account must exist a member of the Local Administrators group

WSUS Windows Server 2022 Database Requirements

At to the lowest degree one of these databases is required:

  • Windows Internal Database (WID)
  • Microsoft SQL Server 2022
  • MS SQL Server 2022
  • Microsoft SQL Server 2022
  • MS SQL Server 2022
  • Microsoft SQL Server 2008 R2

Boosted Installation Requirements

Apart from the requirements listed above, below are further considerations and requirements:

  • You tin install WSUS server role and the database server on dissever computers. However,
  • The Database server cannot be a Domain Controller.
  • Also, the WSUS server cannot run Remote Desktop Services
  • The Database server and the WSUS server must be in the same AD Domain. If in different domains, the domains must have a trust human relationship.
  • Finally, the two servers must be in the aforementioned time zone or be synchronized to the same GMT time source.

Perform WSUS (Windows Server Update Service) Pre-installation Tasks

Before you install Windows Server Update Service role, perform the following tasks:

  • Add together the Domain Admin account equally member of the Local Administrators group on the server you wish to install WSUS role: Open Server Director, and then click Tools and select Calculator Management. On Computer Direction, click Local Users and Groups. Double-click Groups so double-click Administrators group. Finally confirm that the installation account is a member of the local administrators grouping.
WSUS (Windows Server Update Service) - Add the Domain Admin account as member of the Local Administrators group on the server you wish to install WSUS role
  • Ostend that Microsoft .NET Framework 4.five (4.6 on Windows Server 2022) is installed. If not, install it: Open Server Managing director. Then click Add Roles or Features. On the first page click Adjacent. And then select Office-based or Feature-based installation. Click Next until yous become to Features.
WSUS pre-installation tasks - Confirm that Microsoft .NET Framework 4.5 is installed
  • Next, confirm that the Network Service account take Full Control permissions to: %windir%\Microsoft.NET\Framework64. Correct-click Framework64 and select Properties, and then click the Security tab.

Important Tip
To be able to alter the permission of Framework64 yous may need to take ownership of the folder. You may also need to add your account to the local administrators group.

  • Ostend that the server you wish to install WSUS function meet the following requirements: Retention is 1.v GB of RAM – higher up and beyond what is required by Windows Server 2022. Available disk space: 10 GB (40 GB or greater is recommended). Finally, confirm that your network adapter is 100 megabits per second (Mbps) or greater.

Install WSUS Windows Server 2022 Server Role

Install WSUS Windows Server 2022 Server Role

Now you are ready to install WSUS. Follow the steps beneath:

  • Log on to the server and open Server Managing director (should commonly open by default).
  • From Server Director (tiptop right corner), click Manage and so select Add together Roles and Features.
Install WSUS (Windows Server Update Service) - add roles and features
  • On the "Before yous brainstorm" folio, click Next.
  • On the "Select Installation type" select "Office-based or feature-based installation" and click Next.
Windows Server Update Service
  • Next, on the "Select Destination server page", select the server you lot wish to install WSUS (Windows Server Update Service) role and click Next.
  • Next page presents option to select the roles y'all wish to install. Check the boxes beside Windows Server Update Service. A page volition load asking you to confirm additional features to install. Click Add Features. So click Adjacent.
  • The "Select features" folio loads. To go along click Adjacent.
  • Note the information in the Windows Server Update Services page. Then click Next to continue.
  • Review the features checked below. So click Adjacent.
  • Enter a local or remote path to store updates.
  • On the Web Server (IIS) Part information page, read the information and then click Next to proceed.
  • And then review the server roles and features you selected. Click Next.
  • Finally, on the confirmation page, review your selections. Check the box Restart the destination server automatically if required and click Install.
WSUS (Windows Server Update Service) - roles installation confirmation page

WSUS role may also be installed by running the PowerShell command below:

Install-WindowsFeature -Name UpdateServices -IncludeManagementTools

Configure WSUS Windows Server 2022 Using the WSUS Configuration Magician

Configure WSUS Windows Server 2022 Using the WSUS Configuration Wizard

Afterwards installing WSUS Windows Server 2022, the side by side footstep is configuration. To configure the role:

  • Open Server Manager and click the yellowish amber triangle. Then select Launch Mail service-installation tasks. Wait for the post-installation chore to complete. Then proceed to the next step.
  • Still on Server Managing director, click Tools and then select Windows Server Update Services.
  • Read the data on the "Before y'all brainstorm" page, then click Next to proceed.
WSUS (Windows Server Update Service) - configuration
  • Next, decide whether y'all wish to join the Microsoft Update Improvement Plan or not. Click Next.
  • The next stage is very critical as this is where you lot decide the WSUS Server that connects to Microsoft Updates Server. Select Synchronize from Microsoft Update. And then to go on click Next.
  • If y'all require a proxy server to connect to the internet, configure it here.
  • Read the relevant information on the Connect to Upstream Server page and so click Start Connecting.
WSUS (Windows Server Update Service) - connect to Microsoft Update server

Important Tip
The previous footstep may take sometime to complete depending on your internet connexion.

  • In one case the connection chore is completed, click Next.
  • Select the languages to download then click Side by side. I am downloading simply English.
  • Cull the products y'all wish to download updates for. If you are in a production environs, download updates for all products in your environment.
  • Decide updates nomenclature to download. In well-nigh cases the defaults are okay.
WSUS (Windows Server Update Service) - Decide updates clarification to download
  • Determine how yous wish to synchronize your WSUS server with Microsoft Updates server. In a production environment, this has a lot of implications. Consider the number of updates to download, and your internet bandwidth.
  • On the End page, check Begin initial synchronization and click Next. Then click Finish.
WSUS (Windows Server Update Service) - Begin initial synchronization

Configure Downstream Servers for WSUS Windows Server 2022

In a product environment with computers in unlike locations, a downstream server may be required. The downstream server volition download updates from your upstream server and distribute the updates to computers in its local network. This way, you avert updates installing over WAN links.

The steps below will walk you through how to configure a downstream WSUS Windows Server 2022 server.

Of import Tip
To perform this chore you would have installed Windows Server Update Service role on the downstream server. Moreover, you should likewise perform post-installation task.

  • Log on to the second WSUS server. From Server Director click Tools then Select Windows Server Update Services.
  • On the Before you begin page, click Next.
  • Determine whether to bring together the Microsoft Update improvement program or not. Click Next to go on.
  • On the Choose Upstream Server page, enter the name of your upstream WSUS server. And so check the boxes Use SSL when synchronizing update information and This is a replica of the upstream server. To go along click Side by side.
WSUS (Windows Server Update Service)

Important Tip
Depending on your environment, y'all may decide non to configure the downstream server as a replica of the upstream. However, it is strongly recommended to use SSL.

  • On the Specify Proxy Server page, click Adjacent.
  • Finally, to synchronize with the upstream WSUS server, click Showtime Connecting.
WSUS (Windows Server Update Service)

Important Tip
If you lot receive HTTP fault, check that your upstream server is configured to take SSL connection. Alternatively, y'all could go back and uncheck Employ SSL when synchronizing update informationorth.

Continue with Downstream Server Configuration

In the terminal job when you click Commencement Connecting, it may take sometime for the wizard to procedure your request.

  • When the Next button becomes available, click it to proceed.
WSUS (Windows Server Update Service)
  • Compared to the same screen when we configured the upstream server, the simply available linguistic communication is English. Click Side by side to proceed.
WSUS (Windows Server Update Service) -
  • Earlier in the tutorial we configured sync schedule for the upstream server. Exercise the aforementioned beneath. If y'all are working in a production surround, be sure to set the time below to happen later on the upstream server has synced.
  • Finally, cheque Brainstorm initial synchronization box and then click End.

Configure Group Policies for WSUS Windows Server 2022 Updates

The next step is to apply group policy settings to automatically configure WSUS.

Important Tip
In a complex production environment, you tin create different Group Policy Objects (GPOs) and link them to different Organizational Units (OUs). For this tutorial, I will link a unmarried GPO to the meridian of the domain.

  • To begin, login to the Domain Controller. Open up Server Managing director, click Tools then select Group Policy Direction.

Important Tip
To become to the Domain, yous may need to expand the Forest container then expand the Domain container.

  • Adjacent, make a copy of the Default Domain Policy GPO. To exercise this expand the Group Policy Objects container. So Drag the Default Domain Policy GPO into the Group Policy Objects container.
  • Then, on the Copy GPO dialogue box, accept the default permission and click Ok. The GPO will be copied. Click Ok on the re-create dialogue box.
  • A new GPO, Copy of Default Domain Policy is created.
  • It is a proficient idea to rename the copied GPO to a more memorable name. I called mine "WSUS GPO". To rename the GPO right-click it then select Rename. In the next step, you will edit the GPO and configure WSUS settings
WSUS (Windows Server Update Service) - navigate to Windows Update GPO

Configure GPO for WSUS Windows Server 2022

Now that you take created a GPO for WSUS Windows Server 2022, adjacent step is to configure the GPO settings.

  • To begin, right-click the new GPO and select Edit. The Grouping Policy Management Editor opens.
WSUS (Windows Server Update Service)
  • Beneath the Computer Configuration container, expand Policies. So navigate to \Administrative Templates\Windows Components. Click Windows Update. Finally, beneath the window select the Standard tab.
  • In the details pane, double-click Configure Automated Updates. On the GPO settings, select Enabled, then configure automatic updates settings. Read the help page (right) to assist yous make a choice to encounter your requirement. When yous finish click Ok to save your changes.
WSUS (Windows Server Update Service)
  • Back to the Grouping Policy Management Editor double-click the Specify intranet Microsoft update service location policy.
  • Click the Enable option. Then on the Set the intranet update service for detecting updates and Gear up the intranet statistics server boxes, enter the WSUS server name y'all wish to use. Enter in the format shown. Finally, click Ok to apply your changes.

Important Tip
If you used a unlike port number, remember to include it hither. Also as important is the SSL selection. If your server is configured for SSL, use https, otherwise utilize http.

  • Earlier you close Group Policy Management Editor ostend that the two policy settings (highlighted in red beneath) are Enabled. And then close the editor and proceed to the next step.

Link the WSUS Windows Server 2022 GPO to a Container

Equally I said earlier, you can link your WSUS GPO to OUs or directly on the domain. All-time exercise is to link the GPO to OUs containing your Computers. For this tutorial though, I will be linking the GPO to the domain.

  • To link the WSUS GPO to a container, drag it to the container. Mine is linked to the domain. You will be prompted to confirm the link. Click Yes.
  • The GPO is now linked to the domain!

Terminal Notes Regarding WSUS (Windows Server Update Service) GPO

Computers in the container are expected to accept the configuration in the GPO. When a reckoner updates the GPO information technology should appear in the WSUS (Windows Server Update Services) panel.

Computers may take up to thirty minutes to show upwards in WSUS console. To strength GPO update on a calculator, run the command below from the reckoner:

gpupdate /force

To force a computer to exist detected immediately by the WSUS server, execute the control below:

wuauclt.exe /detectnow

Configure Client-Side Targeting for WSUS Windows Server 2022

Customer-side targeting, configured via Group Policy is used to add computers to WSUS groups. The WSUS grouping a computer belongs determines the updates that will exist practical to information technology.

When customer-side targeting is enabled, client computers identifies WSUS estimator groups they should be added to. The information is sent to the server when the customer communicates with the server. The WSUS server so uses the data received from the client to determine which updates are deployed to the client figurer.

The steps below volition walk you through enabling customer-side targeting via group policy.

  • Log on to the Domain Controller and open Group Policy Management (via Server Director).
  • Next, right-click the GPO yous created earlier and select Edit. Group Policy Management Editor opens. Navigate to \Administrative Templates\Windows Components. Click Windows Update
  • In the details pane, double-click Enable Client-side targeting Policy.
WSUS (Windows Server Update Service)
  • Enable the policy. Then on the Target grouping name for this computer, enter the name of the WSUS group. Click Ok to salvage your changes.

Important Tip
The name of the grouping entered above must exist created under the All Computers container in WSUS.

There you lot have it – WSUS installation and configuration! I promise you found this Itechguide helpful.

If you have any questions or comments, kindly use the "Leave a Reply" course beneath.

Other Helpful Guides

  • Agile Directory Concepts & Administration
  • Active Directory Domain Services: Installation & Configuration
  • What is Agile Directory (Top l Advertisement Questions Answered)

Additional Resources and References

  • Windows Server 2022: A cheat sheet
  • Was this postal service helpful?
  • Yes (one)No (0)

Source: https://www.itechguides.com/wsus-windows-server-2016/

Posted by: ullrichdarpre.blogspot.com

0 Response to "How To Install Wsus Server 2016"

Post a Comment

Iklan Atas Artikel

Iklan Tengah Artikel 1

Iklan Tengah Artikel 2

Iklan Bawah Artikel