Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Update Services > Re: Can the Update Services runas another account

Reply
Thread Tools Display Modes

Re: Can the Update Services runas another account

 
 
Lawrence Garvin [MVP]
Guest
Posts: n/a

 
      02-19-2010
"Jordan" <> wrote in message
news:...


> we don't want anyone to use the servers for downloading,


I would suggest that you should block this in the *firewall* using IP
Addresses, not using domain credentials!
Given that nobody should be browsing the web, or accessing the Internet,
from a server under any conditions, this is a fairly easy implementation.

> Can I change Update Services from running as "Network Service" to a new
> admin account so I can just allow that account to download from the
> Microsoft?


NO.

Note.. it's not the Update Service that performs the download, anyway; it's
the Background Intelligent Transfer Service, and that account runs under the
Local System context, and must do so because it requires the ability to
write to restricted areas of the filesystem (e.g.
%windir%\SoftwareDistribution\Download).

And it wouldn't matter anyway... the downloads from Microsoft to WSUS
Server,
just as the downloads from WSUS USS to WSUS DSS,
just as the downloads from WSUS to WUAgent
are all done ANONYMOUSLY.

As noted... the correct way to achieve your objective is to block WEB access
at the firewall.
Leave your Internet Filter for use by real domain users on workstation
systems where you need to do complex content-level filtering.

--
Lawrence Garvin, M.S., MCITP:EA, MCDBA, MCSA
Principal/CTO, Onsite Technology Solutions, Houston, Texas
Microsoft MVP - Software Distribution (2005-2010)

My Blog: http://onsitechsolutions.spaces.live.com
Microsoft WSUS Website: http://www.microsoft.com/wsus
My MVP Profile: http://mvp.support.microsoft.com/pro...awrence.Garvin

 
Reply With Quote
 
 
 
 
Lawrence Garvin [MVP]
Guest
Posts: n/a

 
      02-22-2010
"Jordan" <> wrote in message
news:...
> If I block the server's IP address at the firewall it would not be able
> grab the Windows Updates no matter what account the service run under.


All but one of your servers has a WSUS server it should be getting updates
from, so there's no need for servers to access Windows Update.

The =WSUS Server= needs to have access through the firewall on port 80 and
443, of course,
but it doesn't need Internet Explorer.

For that matter, blocking the execution of iexplore.exe on servers via Group
Policy is also an alternative solution that's much more effective.


--
Lawrence Garvin, M.S., MCITP:EA, MCDBA, MCSA
Principal/CTO, Onsite Technology Solutions, Houston, Texas
Microsoft MVP - Software Distribution (2005-2010)

My Blog: http://onsitechsolutions.spaces.live.com
Microsoft WSUS Website: http://www.microsoft.com/wsus
My MVP Profile: http://mvp.support.microsoft.com/pro...awrence.Garvin

 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Updates were unable to be successfully installed wjousts Windows Update 6 01-30-2010 04:01 PM
Security Update KB971486 is trying to install over and over 2harts4ever Windows Update 29 01-24-2010 06:05 PM
Windows Update error code 8007065E Martin R Windows Update 7 01-14-2010 01:33 PM
Unable to add computer to domain Nik Active Directory 5 12-18-2009 08:29 PM
Renamed Guest Account - Yikes! Jerry L Windows Vista Administration 13 04-20-2007 11:36 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59