Blocking Windows Update via Router


Recommended Posts

Hi guys,

We've got a bit of an issue at the moment, we're using DeepFreeze to lock down our PCs on the call floor, the issue is that they're all redownloading Windows Updates automatically every morning. Now I'm going to go around and disable this so we can manually do it once every few months but immediately we need to have Windows Update blocked as our internet connection is barely functioning right now.

Can anyone tell me what Domains / Ports etc Windows Update on Windows XP uses?

Thanks

Chris

Link to comment
https://www.neowin.net/forum/topic/984862-blocking-windows-update-via-router/
Share on other sites

i believe update.microsoft.com is the hostname of the windows update servers, not sure about the port though, leme see if i can track it down (Y)

edit: windows update services use port 80 and 443, lol

http://technet.microsoft.com/en-us/library/bb490846.aspx

Windows update uses the following DNS for updates;

update.microsoft.com

windowsupdate.microsoft.com

you could block these at the firewall if your router supports DNS blocking that would be the simple option i guess.

If you have a Windows Server you could implement a group policy?

EDIT: Riggers beat me to it

Hey guys,

Blocking those two hostnames seams to have done the job for now, well enough at least. I'll update these PCs manually in a few weeks then disable Windows Update on them.

Which group policy are you guys talking about?

They're hooked up to a Server 2008 R2 Domain Controller.

Through Group policy you can control Windows Update, ideally you would do this with WSUS (free) to give you a centralized control of updates allowing you to control what does and what does not get installed

Then when you want to apply an update you OK it in WSUS and all the machines will download it per the scheduling you have already laid out

  On 24/03/2011 at 14:23, Teebor said:

Through Group policy you can control Windows Update, ideally you would do this with WSUS (free) to give you a centralized control of updates allowing you to control what does and what does not get installed

Then when you want to apply an update you OK it in WSUS and all the machines will download it per the scheduling you have already laid out

This, also you can have deepfreeze thaw during a scheduled time period so that updates can be applied. Say between 3am to 5am on thrusdays for example (a time that usually no one is working).

Yeah, controlling Windows Update via Group Policy isn't really worth it, nor is WSUS, When we move to a Windows Multipoint Server base or move from XP to 7 then I'll worry about such things. These machines are used for a basic Java app and nothing else, so updates are barely important, they're even firewalled off from 99.9% of the web.

I'll just let them be and disable automatic updates soon as I get time.

Spending time fixing up PCs from the dark ages isn't my concern, ensuring it doesn't affect the productivity of the office is my concern. lol.

  On 24/03/2011 at 15:59, Vegetunks said:

Yeah, controlling Windows Update via Group Policy isn't really worth it, nor is WSUS, When we move to a Windows Multipoint Server base or move from XP to 7 then I'll worry about such things. These machines are used for a basic Java app and nothing else, so updates are barely important, they're even firewalled off from 99.9% of the web.

I'll just let them be and disable automatic updates soon as I get time.

Spending time fixing up PCs from the dark ages isn't my concern, ensuring it doesn't affect the productivity of the office is my concern. lol.

30 min gets you wsus and the appropriate group policies in place (even to disable windows updates for those specific machines, this would take 5 min if you have a domain). Dunno how it isnt worth it. Dunno how WSUS isn't worth free.

computer configuration

admin templates

windows components

windows update

Configure automatic updates

"If the status is set to Disabled, any updates that are available on Windows Update must be downloaded and installed manually. To do this, go to http://windowsupdate.microsoft.com or click Start, click Programs (or click All Programs), and then click Windows Update."

This is a computer setting so it applies only to computers, add the computers that you want to apply this gpo to not the users within the group policy management console in active directory.

On the Domain Controller, Start, Administrative tools, Group Policy Management Console.

Make a new group policy under the main domain name, edit the policy. I will provide screen shots in my next post, I will start getting them done now.

when you are in the group policy management console, you single click on the policy on right it displays scope tab, at the bottom of the scope tab there is security filtering. add computers in there. You will have to modify the object type to include computers to be able to add them.

then on a computer that is going to be effected by the group policy you can force it to apply by going to a command prompt and typing in:

gpupdate

to verify that this has been applied you can either use the gpresults command or going to start run rsop.msc and navigating to the windows update section. All pcs will follow suit within 15-45 min, you may want to schedule a one time thaw so that these updates can take place and be in there always, even after a reboot.

Very powerful the group policies are, I would suggest making group policies as granular as possible. They can really lock down a computer. The computer configuration section applies to computers, the user configuration section applies to users. If you change something to the computer configuration and try to apply that to users it will will not apply and if you change something in the user configuration and have that apply to computers it will not apply.

You can make groups and apply policies to groups (you can put computers in a group).

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • MSI's 32-inch 4K QD-OLED gaming monitor gets a big price cut for UK gamers and professionals by Paul Hill If you’re a gamer in the UK and looking for a monitor to upgrade to then check out the MSI MPG 321URX QD-OLED 31.5 Inch 4K UHD Gaming Monitor which you can now pick up for just 75% of its recommended retail price. The RRP of this monitor is £1,199, but thanks to this deal, you can get it for just £898.99 for a limited time (purchase link down below). With its 4K display, 240Hz refresh rate, and 0.03ms GTG, you’ll have the edge over other gamers by avoiding lag. At 31.5-inches, it’s the ideal monitor size if you’re sitting up close to it at a desk, you don’t want it too big at such a short range, but you also want to be able to see all the image details so 31.5-inches is a good balance. What makes QD-OLED stand out? There are loads of terms used to describe displays such as AMOLED, OLED, LED, and it can all get a bit confusing. This monitor adds yet another acronym called QD-OLED, which stands for Quantum Dot OLED. For you as a buyer, this means your new monitor has self-emitting pixels that deliver great black levels. It also features an enhanced sub-pixel arrangement for extra sharpness. The 31.5-inch 4K UHD monitor has a 3,840 x 2,160 pixel resolution making it ideal for playing games, but also watching movies in the best quality. Other important features worth mentioning are the 1.07 billion colors (10-bit) that the monitor can produce, its 99% DCI-P3 support, and DisplayHDR True Black 400 certification. All of these things make the monitor produce more accurate colours, potentially making it a good choice for professionals editing videos and photos too. Obviously, games will look good too. MSI has also packed in a fanless graphene heatsink which should help to increase the durability of the monitor long-term. This could extend the time until you need to buy a new monitor, further justifying its almost £900 price tag. Gaming and productivity features It’s not just the hardware that makes this monitor excel for gaming, it also comes with great software enhancements and connectivity options. On the software side, you get the following features: Smart Crosshair: Projects a customizable crosshair onto the screen to improve hip-fire accuracy and iron sights in first-person shooter games. Optix Scope: Gives you a built-in aim magnifier with multi-stage zooming and shortcut keys to quickly switch magnification levels. AI Vision: This automatically enhances brightness and colour saturation, particularly in dark areas of the screen, making it easier to see enemies hiding in shadows or dark corners. If you have two separate systems you want to connect to the monitor at once, you can do so with this monitor thanks to KVM support. You can view both sources with Picture-in-Picture and Picture-by-Picture modes. The MSI MPG 321URX QD-OLED 31.5 Inch 4K UHD Gaming Monitor also supports next-gen consoles with features like HDMI CEC Profile Sync, HDMI Variable Refresh Rate (VRR), and 4K:4K downscaling. In terms of connectivity and ergonomics, you get DisplayPort 1.4a, 2x HDMI 2.1 (CEC), USB Type-C with 90W power delivery, and a USB hub. The monitor uses a tilt-, swivel- & height-adjustable stand that is VESA compatible. Should you buy this monitor? The MSI MPG 321URX QD-OLED 31.5 Inch 4K UHD Gaming Monitor is definitely a product for serious gamers looking for top-tier visual fidelity and performance or content creators who need accurate colours and high resolution. Even with the significant discount, it’s still at a premium price and definitely not for everyone. If you are in one of the groups mentioned, then you should give serious consideration to buying the MSI MPG 321URX QD-OLED 31.5 Inch 4K UHD Gaming Monitor as it's the lowest price the monitor has been at on Amazon to date. MSI MPG 321URX QD-OLED 31.5 Inch 4K Gaming Monitor: £898.99 (Amazon UK) / RRP £1,199 This Amazon deal is U.K. specific, and not available in other regions unless specified. If you don't like it or want to look at more options, check out the Amazon UK deals page here. Get Prime, Prime Video, Music Unlimited, Audible or Kindle Unlimited, free for the first 30 days As an Amazon Associate we earn from qualifying purchases.
    • So they went from bloody awful, to still bloody awful? Pass...
    • Hmm, I have been setting folder colors in Teams as we got more and more clients, but they never synced to File Explorer on my Surface Pro 7+. So, all this while, thought the feature wasn't available yet. Guess it'll need to be changed via the SharePoint website for it to sync to File Explorer. Thanks for sharing 👍🏼
    • I got it on my s22 about a month ago, Europe
    • A script doesn't care if your book is written by AI or not, so, not sure how that changes anything. They'll just be further advertising your work in such. As for AGI, not sure how using AI in writing a book suddenly equates to me supporting AGI replacing everyone in the workplace. Either way, if such does happen, I'll just carry on with community services, AGI replacing such roles only speeds up the spreading of the message...
  • Recent Achievements

    • Enthusiast
      computerdave91111 went up a rank
      Enthusiast
    • Week One Done
      Falisha Manpower earned a badge
      Week One Done
    • One Month Later
      elsa777 earned a badge
      One Month Later
    • Week One Done
      elsa777 earned a badge
      Week One Done
    • First Post
      K Dorman earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      536
    2. 2
      ATLien_0
      272
    3. 3
      +FloatingFatMan
      201
    4. 4
      +Edouard
      200
    5. 5
      snowy owl
      138
  • Tell a friend

    Love Neowin? Tell a friend!