The user will need to be a local administrator to disable the Windows
Firewall or change it's settings. As Malke suggested WSUS would be an option
to look at if for some reason you need to approve and distribute Windows
Updates from a server that could download them from Microsoft. The then
client computers could be setup for Automatic Updates and the end user would
not need to get involved or you could configure the client computers to use
Automatic Updates and then each computer go directly to the internet for the
updates assuming you have the bandwidth. You need a Windows Server operating
system to use WSUS. Microsoft Small Business Server is surprisingly
affordable of you have the need for a server operating system and the built
in Wizards make if fairly easy to setup and maintain.
Steve
http://technet.microsoft.com/en-us/wsus/default.aspx --- Windows Server
Update Services