How to Configure Client Side Targeting in WSUS

49164

In the previous posts we have seen Installation, Configuration, Managing and troubleshooting the WSUS server. In this post we will see how to configure client side targeting in WSUS. When you configure the Group Policy settings for WSUS, use a Group Policy object (GPO) linked to an Active Directory container. The container contains the computers for which the updates are to be deployed. In Client side targeting you use Group Policy objects (GPOs) to add computers to computer groups. Client side targeting is required when you might have multiple GPOs linked to several organizational units (OUs), which enables you to have different WSUS policy settings applied to different types of computers.

On the Domain Controller we will create a OU called Workstations. We will move a client computer called CLIENT into the OU.

How to Configure Client Side Targeting in WSUS Snap 1

Login to the WSUS server. Launch the WSUS Console.

How to Configure Client Side Targeting in WSUS Snap 2

Click on Computers. A new windows pops up, under General Tab choose “Use Group Policy or registry settings on computers“. Click Apply and OK.

How to Configure Client Side Targeting in WSUS Snap 3

Now we will enable the client side targeting through the group policy. Right click the domain and create a policy called WSUS Update Policy. Right click the WSUS Update Policy, click Edit.

Note – You can create multiple¬† GPO’s if required. In case you have several OU’s and you want to apply different WSUS settings, you will need to create separate GPO’s for each, define the windows update settings and apply the policies on desired OU’s.

How to Configure Client Side Targeting in WSUS Snap 4

 

On the Group policy management editor, click on Computer Configuration, Policies, Administrative templates, Windows Component, Windows Update.

How to Configure Client Side Targeting in WSUS Snap 5

Double Click Configure Automatic Updates. Click Enabled to enable the policy. Under Options, for Configure automatic updating – select option 4 – Auto download and schedule the install. Set Schedule install day as Everyday and Schedule install time as 10:00. Click Apply and OK.

How to Configure Client Side Targeting in WSUS Snap 6

Double the policy Specify intranet Microsoft Update service location and specify the name of WSUS server (http://wsus.prajwal.local) for both intranet update service for detecting updates and intranet statistics server. click Apply and OK.

How to Configure Client Side Targeting in WSUS Snap 7

Right click Enable Client-side targeting and click Edit.

How to Configure Client Side Targeting in WSUS Snap 8

On the Enable Client-side targeting page, Click on Enabled to enable the policy. For the Target group name for this computer, type the name of the OU that you have created in Active Directory. click Apply and OU.

How to Configure Client Side Targeting in WSUS Snap 9

By default, Group Policy refreshes in the background every 90 minutes, with a random offset of 0 to 30 minutes. If you want to refresh Group Policy sooner, you can go to a command prompt on the client computer and type: gpupdate /force.

12 COMMENTS

  1. Hi! Nice article you have here. But I have a question though. How do I configure my Windows client to download updates from WSUS instead of from the internet?

  2. Hi Prajwal

    I suspect that you might be mistaken,According to your article you just have to Specify the OU group name and it will add it to the Target group which is not true. You have to manually create Target groups In WSUS , AD OU’s and Target Group’s are completely independent.

    Love your site! Great work.

  3. Hi Prajwal, Nice blog….but I have a question…Are you sure that the name we give in ‘Enable Client-side targeting page’ is the OU name. Or is it the Computer group name that we give in WSUS ?

  4. Hello, It’s not necessary that the “target group name” matches the the OU name! I have a system working without this requirement. What i think it’s necessary is that teh “target group name” matches the Wsus Computer Group

  5. How to set up gpo to have client machines to report wsus server if I set to store update files remotely on Microsoft servers? Just gpo about client-side targeting does not help.

  6. Hi Prajwal,
    Love your posts. They are easy to understand as you provide step by step instructions with the pictures.
    Keep up the great work.

    Atul

LEAVE A REPLY

Please enter your comment!
Please enter your name here