Windows Software Update Server (WSUS)

To address computer security issues, IST recommends all computers on the Bannatyne and Fort Garry campus:

  • have antivirus software installed and kept up-to-date;
  • operating system patches are applied on a regular basis. 

Operating system patches can be acquired from several sources, including Microsoft's Windows Update site. However, for machines running Windows 2000, Windows XP, and Windows Vista and Windows 7 (see notes following), IST has implemented a Windows System Update Server (WSUS).

WSUS provides software updates for Microsoft Windows operating systems. By using our WSUS Server, administrators are able to fully manage the distribution of updates released through Automatic Updates.

The WSUS server maintains automatic installs of patches and updates that have been approved by IST for our university computers. After a computer has been configured for WSUS, we ask that you never use Windows Update. Even though Windows Update is still available, it may install updates that have not been recommended by the University.

How you benefit from our WSUS Server:

  • minimum 24 hour delay in updates to minimize side effects
  • only IST approved critical and security operating system updates
  • ability to block problematic updates
  • local service from our network

Configuring your machine to acquire updates from the University of Manitoba WSUS

The following instructions will assist you in configuring your computer to obtain Windows updates through the WSUS at The University of Manitoba. Prior to proceeding with these steps, please contact your container administrator, work group manager or departmental computer representative. This individual may have already prepared your machine for receiving updates via the University of Manitoba WSUS server.

  1. Check the operating system running on your computer:
    Click on the My Computer icon using the right mouse button.
    Under the General tab of the System Properties dialogue window, system data will be presented.

  2. The following are the minimum requirements for WSUS:
    • Windows 2000 Service Pack 3 (SP3 or newer)
    • Windows XP with Service Pack 1 (SP1 or newer)
    • Windows Vista
    • Windows 7
  3. If your computer has Windows 2000 with SP2 or Windows XP without SP1 or earlier, you must upgrade before using WSUS. Follow the steps at Microsoft's Automatic Updates page, then proceed to step 4.
  4. A registry change must be made to point the automatic update software toward the University of Manitoba WSUS. The easiest method is to use an update file. The provided update file, umWSUS-inst.reg, configures Windows Automatic Updates so that user involvement is minimal:
    • The client computer will check for new updates once a day.
    • When available, the updates will be downloaded and installed automatically.
    • If a reboot is required, Windows will prompt you before rebooting so that you don't lose any unsaved work.

    To download this update file, right click on the following link and choose Save or Save link as: umWSUS-inst.reg 

    Then choose a location to save this file to and click OK. To start the installation, browse to the location you save the file to and then double click on the file.
    Select Yes when asked if you want the information added to the registry. 

  5. Alternatively you can create this file yourself. Please go to the Manually creating the update file section and create the file yourself.
  6. Restart the client computer to apply these changes.

Acquiring updates

Once your computer has been configured to automatically check for updates. It will check for new updates from the WSUS approximately once every 24 hours and after rebooting.

When your computer requires an update, it will automatically download the updates. Then at the scheduled time, 12pm noon, the update will be installed. If your computer requires a reboot a dialogue window asking whether you would like to postpone rebooting will appear and remain until your preference is given. This dialogue window will reappear approximately every 5 minutes until you do reboot.

For a more detailed discussion of WSUS please visit:
Microsoft's Software Update Services Deployment White Paper


Manually creating the reg file

While not recommended, you can use RegEdit to manually enter the relevant options into the Windows Registry. 

To change the appropriate registry keys, we recommend downloading the file umWSUS-inst.reg as describe above or follow the below steps to create your own:

  1. Copy the text below into Notepad (or any text editor). Please copy the text exactly and be sure to leave the quotes and save the file as a text file.

    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate]
    "WUServer"="http://secureit.cc.umanitoba.ca"
    "WUStatusServer"="http://secureit.cc.umanitoba.ca"
    "TargetGroupEnabled"=dword:00000000
    "ElevateNonAdmins"=dword:00000000

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU]
    "NoAutoUpdate"=dword:00000000
    "AUOptions"=dword:00000004
    "ScheduledInstallDay"=dword:00000000
    "ScheduledInstallTime"=dword:0000000c
    "NoAutoRebootWithLoggedOnUsers"=dword:00000001
    "RescheduleWaitTimeEnabled"=dword:00000001
    "RescheduleWaitTime"=dword:0000003c
    "DetectionFrequencyEnabled"=dword:00000001
    "DetectionFrequency"=dword:00000016
    "AutoInstallMinorUpdates"=dword:00000001
    "RebootWarningTimeoutEnabled"=dword:00000000
    "RebootRelaunchTimeoutEnabled"=dword:00000000
    "UseWUServer"=dword:00000001

  2. Save this as “umWSUS-inst.reg”.

  3. Install the keys by double clicking on the umWSUS-inst.reg file icon. You will be warned that the registry will be modified. Click on Yes to add the information to the registry.

  4. Restart the client computer to apply these changes.
  5. Your computer is now configured and should be contacting the WSUS server for updates.

Key configurationA detailed explanation of what each of the key does now follows.

  • WUServer
    HTTP URL of the WSUS server used by Automatic Updates and (by default) API callers; This points to the UofM's WSUS Server

  • WUStatusServer
    The HTTP URL of the server to which reporting information will be sent for client computers that use the WSUS server configured by the WUServer key; This points to the UofM's WSUS Server

  • TargetGroupEnabled 
    Determines the use of client-side targeting. This is disabled

  • ElevateNonAdmins 
    This is set so that only users in the Administrators user group can approve or disapprove updates.

  • NoAutoUpdate
    This is set to 0; Enable Automatic Updates.

  • AUOptions
    This is set to 4; Automatically download and schedule installation

  • ScheduledInstallDay
    This is set to 0; Every day

  • ScheduledInstallTime
    This is set to 0xC; 12:00pm; Noon

  • NoAutoRebootWithLoggedOnUsers
    This is set to 1; Logged-on user gets to choose whether or not to restart his or her computer. 

  • RescheduleWaitTimeEnabled
    This determines whether or not Automatic Updates should wait at startup before applying updates from a missed scheduled installation time.

  • RescheduleWaitTime
    Time, in minutes, that Automatic Updates should wait at startup before applying updates from a missed scheduled installation time.

  • DetectionFrequencyEnabled
    This determines whether or not DetectionFrequency is enabled and in this case it is.

  • DetectionFrequency
    Time between detection cycles. This is set to 22 hours.

  • AutoInstallMinorUpdates
    This is set to 1; silently install minor updates. This will install updates that do not require a system restart immediately.

  • RebootWarningTimeoutEnabled
    This is set to 0; Disable custom RebootWarningTimeout (the default value of 5 minutes is used).

  • RebootRelaunchTimeoutEnabled
    This is set to 0; Disable custom RebootRelaunchTimeout (the default value of 10 minutes is used).

  • UseWUServer
    This key is set to 1; enabled. The WUServer is not used unless this key is set.



Help & Solutions Centre
(Mon-Fri 8:00am to 8:00pm)*
204-474-8600
123 Fletcher Argue
Map
  
Bannatyne Service Desk
(Mon-Fri 8:30am to 4:30pm)*
204-474-8600
230 NJM Library

Want to stay current with the ongoings of IST? Follow us on:

Facebook Facebook
Twitter Twitter
Blog Blog / RSS Feed
Blog IST-Alerts Mailing List