Re: Newbie - SUS - How to Make Exception for Particular Servers

From: Roger Abell (mvpNOSpam_at_asu.edu)
Date: 05/15/05


Date: Sun, 15 May 2005 08:55:50 -0700

You best solution is the one you specifically say you do not
want to do - defining an OU structure that fits your admin model.

First, you called the Computers container an OU, which it is not.
It is just a container object and does not have the properties of an
OU, such as being able to have GPOs linked to it.

If you insist on using only GPOs linked at the Domain in order to
do this, then you will need to set the SUS adm policies in a GPO
that uses security group filtering in order to control which machines
in the domain are in that GPO's scope of management. Generally,
I would recommend using OU structuring in favor of security group
filtering - especially since you are not using any OU structure for
machine objects at this time.

-- 
Roger Abell
Microsoft MVP (Windows  Security)
MCSE (W2k3,W2k,Nt4)  MCDBA
"Ronin" <Ronin@discussions.microsoft.com> wrote in message
news:59270F8F-38DE-4843-8410-8997E88954F9@microsoft.com...
> Hi All,
>
> I just have installed a Windows 2003-based SUS SP1 Server.
> Using GPO, I want computers within my domain to be configured and pointed
to
> this SUS Server, except for several application servers, since we just
want
> to update these application server quite manually.
> Unfortunately all computers within my domain are in the default Computer
OU
> in AD.
> How can i make exception to these application servers, so that they will
not
> be configured or use or pointed to the SUS server?
> I also dont want creating a special OU for these application servers.
> Please Help. Thanks.
>
>


Relevant Pages

  • RE: New Update for #70-299
    ... > Segment A contains a single server named TestKing1. ... > Segment B contains all other computers, ... > TestKing?s written security policy states that Segment B ... > Updates on all computers in Segment B to use ...
    (microsoft.public.cert.exam.mcse)
  • Re: Help with 070-217
    ... The network contains 25,000 computers. ... > single Windows 2000 domain named research.contoso.com. ... > Server computers that are configured as domain controllers. ...
    (microsoft.public.cert.exam.mcse)
  • RE: Help with 070-217
    ... The network contains 25,000 computers. ... > single Windows 2000 domain named research.contoso.com. ... > Server computers that are configured as domain controllers. ...
    (microsoft.public.cert.exam.mcse)
  • Re: Cannot browse or open shared printers or server on sbs 2003 from client pc
    ... i think the network problem has taken a different turn. ... meanwhile if i access the mapped drives to the server which we setup in the ... my thought now is what is the update mechanism for the printers from the ... I understand the issue to be: client computers can ...
    (microsoft.public.windows.server.sbs)
  • Help with 070-217
    ... The network contains 25,000 computers. ... single Windows 2000 domain named research.contoso.com. ... Server computers that are configured as domain controllers. ...
    (microsoft.public.cert.exam.mcse)