Score:0

Delegate administration and maintenance of Update Services (WSUS) to User

us flag

We are running Update Services on a Windows Server 2016 server that delivers updates to the systems on the domain. I need to delegate maintenance of this to a non-admin user. The user must be able to run WSUS Server Cleanup Wizard and approve/decline updates. How should this be done?

Bernd Schwanenmeister avatar
au flag
Since WSUS can be used to deliver 3rd party updates (even own scripts) and these are executed with highest privileges throughout the network, it's extremely security critical. Delegate tasks carefully, please. The cleanup process can be automated through scripts, for example https://gist.github.com/andyzib/5ebd5f76ee90703f2bbc681893b8ed6a . To delegate the approval, you should write a script (in my opinion) that asks the user which update to approve and then runs powershell at the server as admin/wsus service account to approve it. I discourage you to let any non-admin RDP into that server.
us flag
Thanks for the guidance Bernd Schwanenmeister
I sit in a Tesla and translated this thread with Ai:

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.