How do I configure GP to allow Windows Updates for users?

S

Sheldon Wolf

We have a 2003 domain and end users are part of the Users
local group on their XP SP1 Pro PC's. I've deployed the
latest version of SUS, configured the correct properties
for GP to push the reg. settings to the clients, allowing
their PC to get updates from the SUS server. However,
unless I add the users to the local Administrators group
on their PC, they aren't even prompted that updates have
been downloaded and are ready to install. What is the most
restrictive way I can configure their PC permissions and
GP settings but still allow them to download and install
Windows Updates? I've disabled "Prohibit Patching" and
enabled "Enable users to patch elevated products" in GP,
but they still don't get a prompt unless added to local
Administrators group on their PC.

Please let me know what I'm missing. Thanks.
 
B

Barry

They aren't supposed to be prompted that they've been downloaded and are
ready to install unless they are admin. Suggest forcing install at a
specific time of the day, which will then prompt the user to reboot.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top