1.2.3.2.2/1.2.3.2.4 Configure 'Specify intranet Microsoft update service location'

Information

This policy setting allows you to specify an intranet server to host updates from the Microsoft Update Web site. You can then use this update service location to automatically update computers on your network. The Automatic Updates client will search this service for updates that apply to the computers on your network. To use the Specify intranet Microsoft update service location setting, you must set two server name values: the server from which the Automatic Updates client detects and downloads updates, and the server to which updated workstations upload statistics. You can set both values to be the same server. If you enable the Specify intranet Microsoft update service location setting, the Automatic Updates client will connect to the specified intranet Microsoft update service server (instead of Windows Update) to search for and download updates. This configuration allows end users in your organization to avoid firewall issues, and provides you with an opportunity to test updates before you deploy them. If you disable or do not configure this policy setting, the Automatic Updates client will connect directly to the Windows Update site on the Internet (if Automatic Updates is not disabled by Group Policy or user preference). By default, Automatic Updates will attempt to download updates from the Microsoft Windows Update Web site. Some organizations want to verify that all new updates are compatible with their particular environment before they are deployed. Also, if you configure an internal Software Update Services (SUS) server you will help reduce the load on perimeter firewalls, routers, and proxy servers, as well as the load on external network links.

Solution

Configure the following Group Policy setting in a manner that is consistent with the security and operational requirements of your organization-

Computer Configuration\Administrative Templates\Windows Components\Windows Update\Specify intranet Microsoft update service location

Impact- Critical updates and service packs will have to be proactively managed by the organization's IT staff.

See Also

https://workbench.cisecurity.org/files/42

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-2(5), CCE|CCE-17311-2

Plugin: Windows

Control ID: d714aa1964b3a08d2f07d8e048de033a667f033bc492cada18e4fdf485ae8067