Auto Update Client Behavior

  • Thread starter Thread starter Nick
  • Start date Start date
N

Nick

Can anyone confirm or deny that admin users on
workstations part of an AD that have been configured via
Group Policy to schedule automatic updates from an SUS
server...that it actually works? It seems that the
default behavior for the Automatic Updates client when
you are an admin is to wait for user intervention
regardless of what the policy dictates. Admin users get
the balloon message from the systray icon, whereas
regular users do not. Therefore, admin users who stay
logged into the machine overnight and never reboot do not
receive the updates. Is my theory correct or does the
scheduled update occur anyway? In light of the recent
RPC vulnerability, I hope that my theory is wrong.

Thanks in advance for your responses.
 
I am reasonably sure that whoever is logged in will be logged out and the
computer rebooted (if necessary to install the patches), whether they are
admin or not. I haven't tested this in a long time, so I might not remember
correctly. The obvious solution if you are concerned, is to scan your
network to make sure there are no vulnerable machines. Microsoft recently
released a program that will scan your network for KB823980-vulnerable
machines.

\\ MadDHatteR
 
Back
Top