"gbkhor" <> wrote in message
news:...
> I have some site (about 5 PC only) having low bandwidth when link back to
> HQ but having high bandwidth when link to internet (as they have local
> internet link), therefore it make sense to get the windows update from
> internet directly rather then from HQ WSUS.
>
> I plan to allow those site PC (about 5 PC) to get the windows update
> directly from Microsoft web site and all the user is holding non-admin
> privilege, my question is, how to configure via GPO?
This not a GPO-based configuration; it is a server configuration.
In order to have client machines obtain updates directly from microsoft.com,
you need to set up the WSUS Server to not contain a local content store.
This is actually a very common deployment question. The functional solution
to this issue is two servers, quite possibly the second running as a VM on
the same box as the primary WSUS Server. The second server is configured as
a replica with no local content store. The remote clients detect from the
replica server which causes them to download direct from microsoft.com; the
corporate clients detect from the primary server which contains a local
content store.
--
Lawrence Garvin, M.S., MCITP:EA, MCDBA
Principal/CTO, Onsite Technology Solutions, Houston, Texas
Microsoft MVP - Software Distribution (2005-2009)
MS WSUS Website:
http://www.microsoft.com/wsus
My Websites:
http://www.onsitechsolutions.com;
http://wsusinfo.onsitechsolutions.com
My MVP Profile:
http://mvp.support.microsoft.com/pro...awrence.Garvin