WUA checks group policy settings before doing it's thing?

    If I made a change to the group policy for Windows Update related stuff,
    would I have to force a gpupdate on all machines so that the WUA
    responds with the the settings I made in GP?

    To be safe, I disabled IIS on my WSUS server temporarily, then ran my
    script to gpupdate all machines.

    But ... is this necessary? Does the WUA actually check/verify "current"
    GP settings before it does it's thing?
  2. No. The group policy settings are automatically refreshed periodically. By
    default, they are refreshed every 60 minutes (plus or minus 30 minutes).
    Disabling IIS is unnecessary. Running gpupdate will expedite the refresh of
    the policy, but is not necessary.
    No, actually, it does not. However, unless you're executing detections more
    frequently than every 2 hours (and on WSUS v2 you shouldn't be), then the
    policy will almost always refresh before the next detection occurs. In less
    than 10% of cases, would it be likely that another detection would occur
    before the policy was refreshed. In addition, a policy refresh will trigger
    a new detection, if the policy change affects how/when/where a detection

    Lawrence Garvin, M.S., MVP-Software Distribution
    Everything you need for WSUS is at
    And, everything else is at
    Lawrence Garvin \(MVP\), Sep 13, 2006
