Question : Best Practice for WSUS administration

I am quickly ramping up our update program and I'm having trouble producing this scenario, it its simplest form. I would assume I would use groups in AD:
WSUS groups (there are more but for all intents and purposes)
Production servers:40
Core App servers: 2
Workstations: 300

I want to install updates and reboot workstations every night without approval-auto critical
I want to prompt each production server to download but not install
I want to prompt the core app servers for updates are ready for downloading so Applications can take on updates for their precious application servers.

You likely noticed that the syntax above is fairly close to the linguel found in WSUS. What I have trouble with is I can approve each update "same as all computers" but I do not know how to approe/install/reboot on the workstations while only downloading to the Production servers and only detecting on the core apps servers.

Thanks in advance

Carl

Answer : Best Practice for WSUS administration

you need a seperate GPO for each OU - and you need to split your computers/servers into the different OU's...i Have about 6 - for different sites, different update times etc
Random Solutions  
 
programming4us programming4us