Connectez-vous au serveur WSUS et copiez wuau.adm dans C:\Windows\System32\GroupPolicy\Adm.
Collez-le sur un dossier partagé avec le contrôleur de domaine.
Connectez-vous au contrôleur de domaine.
Copiez ensuite le fichier partagé dans C:\Windows\Inf\ sur le contrôleur de domaine.
Ensuite je me réfère à l'article de Microsoft lisible ici: http://technet.microsoft.com/fr-fr/library/cc720539(WS.10).aspx
If the computer you are using to configure Group Policy does not have the latest version of Wuau.adm, you must first load it by using the following procedure.
To add the WSUS Administrative Template
1.In Group Policy Object Editor, click either of the Administrative Templates nodes.
2.On the Action menu, click Add/Remove Templates.
3.Click Add.
4.In the Policy Templates dialog box, select Wuau.adm, and then click Open.
5.In the Add/Remove Templates dialog box, click Close.
Configure Automatic Updates
The settings for this policy enable you to configure how Automatic Updates works. You must specify that Automatic Updates download updates from the WSUS server rather than from Windows Update.
To configure the behavior of Automatic Updates
1.In Group Policy Object Editor, expand Computer Configuration, expand Administrative Templates, expand Windows Components, and then click Windows Update.
2.In the details pane, click Configure Automatic Updates.
3.Click Enabled and select one of the following options:
Notify for download and notify for install. This option notifies a logged-on administrative user prior to the download and prior to the installation of the updates.
Auto download and notify for install. This option automatically begins downloading updates and then notifies a logged-on administrative user prior to installing the updates.
Auto download and schedule the install. If Automatic Updates is configured to perform a scheduled installation, you must also set the day and time for the recurring scheduled installation.
Allow local admin to choose setting. With this option, the local administrators are allowed to use Automatic Updates in Control Panel to select a configuration option of their choice. For example, they can choose their own scheduled installation time. Local administrators are not allowed to disable Automatic Updates.
4.Click OK.
Enable Client-side Targeting
This policy enables client computers to self-populate computer groups that exist on the WSUS server.
If the status is set to Enabled, the specified computer group information is sent to WSUS, which uses it to determine which updates should be deployed to this computer. This setting is only capable of indicating to the WSUS server which group the client computer should use. You must actually create the group on the WSUS server.
If the status is set to Disabled or Not Configured, no computer group information will be sent to WSUS.
Ensuite, patience. Les ordinateurs allumés mettront entre 1h et 1h30 à récupérer la stratégie.
Aucun commentaire:
Enregistrer un commentaire
Commentaires bienvenus !