We are decommissioning WSUS for Windows patching and using the K1000 going forward.  I'm trying to figure out the most sure-fire way of stopping our PCs from grabbing updates from either the WSUS server -or- directly from Microsoft.  It seems like the logical thing to do is to disable the Windows Update service (wuauserv).  Does KACE rely on it at all?  It doesn't seem to in my testing, but I thought I'd ask the community!  Also, are there any other negative impacts that anyone can think of?

Answer Summary:
0 Comments   [ + ] Show Comments


Please log in to comment

Answer Chosen by the Author

No. The K1000 does not interact or rely upon WSUS in any way. 
Answered 06/28/2014 by: bkelly
Red Belt

Please log in to comment

Community Chosen Answer

We used GPO to disable Windows Update from automatically checking for updates. Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Updates > set Configure Automatic Updates to Disabled. This will still allow you to use Windows Update to manually check for updates if needed (which is still useful) but updates will not automatically be snagged from your WSUS server or MS.
Answered 06/27/2014 by: jegolf
Red Belt

  • There is also a script, built into the Configuration Policy tab, that can disable the user-interactive portion of Windows Updates.

    Ron Colson
    KACE Koach
Please log in to comment


That's great news!  Thanks, everyone!

Answered 06/30/2014 by: awingren
Eighth Degree Black Belt

Please log in to comment
Answer this question or Comment on this question for clarity