You will want to make sure that you take the options for manual override
away from the end users and manage the whole Windows Update architecture
through the AD. Remember that this will put the burdon of approving patches
on your or your staff and this must be managed on a regular basis.
In a mission critical environment you will want to look at a tiered approach
where you test patches before applying them to a production environment.
IIRC, you can also set it up so that the clients who fall under the Scope of
Management of this GPO can not access the windowsupdate.microsoft.com page.
This would be a really nice thing to add so that you have a truly 'managed'
environment.
The staged approach is a really good idea, Ryan. Most people do not do
this! And for the most part there is usually not a problem. But, every
once in awhile things go kerplewie!
--
Cary W. Shultz
Roanoke, VA 24012
Microsoft Active Directory MVP