Getting Microsoft Deployment Toolkit 2008 to install updates from WSUS


Microsoft Deployment Toolkit contains a script named ZTIWindowsUpdate.wsf that can be enabled to run during Lite Touch OS deployments.  By default, it will talk to the Microsoft Update site on the internet to get the latest updates needed for your Windows OS and Microsoft applications like Office.  But you might not want all of the machines you deploy doing that.  So with MDT 2008, we added the ability to install updates from a WSUS server.  The “Toolkit Reference” document describes the basic process:

MDT 2008 can also configure WUA to collect updates from computers on the corporate network that are running WSUS instead of connecting to Microsoft Updates over the Internet. MDT 2008 can optionally configure WUA to use a specific computer running WSUS using the WSUSServer property.

But the actual description of the WSUSServer property, and a sample of how to set it, was accidentally left out of the documentation.  This needs to be configured via CustomSettings.ini by adding an entry that looks like this:

WSUSServer=http://mywsusservername

With that set, the ZTIWindowsUpdate.wsf script will automatically configure the Windows Update Agent to talk to this WSUS server instead of using Microsoft Update.

One other note: the new OS being deployed to the machine must be running a supported version of the Windows Update Agent (WUA).  Windows XP and Windows Server 2003 don’t contain that needed version, so they need to be upgraded.  This will be done automatically by the script, downloading the files from the internet if necessary.  But it would be more efficient for you to download them in advance and place them where the script can find them.  Again from the documentation:

For additional information and for WUA deployment instructions, go to http://technet.microsoft.com/en-us/library/bb932139.aspx.

You can obtain the latest version of the WUA stand-alone installer for:

Windows Vista and Windows Server 2008 include the most recent version of WUA, so no upgrade is necessary for these operating systems. In Windows XP and Windows Server 2003, one of the following will occur:

  • If the WUA 3.0 stand-alone installer files are in the TOOLS\architecture folder (where architecture is either x86 or x64) on the deployment point, MDT 2008 will automatically install WUA on the target computer.

    When downloading the WUA 3.0 stand-alone installer files, save them in the distribution\TOOLS\architecture folder (where distribution is the folder where the distribution point is created).
  • If the WUA 3.0 stand-alone installer files are not in the TOOLS\architecture folder on the deployment point and if the existing version of WUA is configured for a WSUS server, then WUA will attempt to update itself from a WSUS server. If the existing version of WUA is not configured for a WSUS server, then MDT 2008 will attempt to download and install WUA 3.0 from the Microsoft Update site. In this case, Internet access is required for the target computer.

So if you set WSUSServer and download the updated stand-alone installers, then the ZTIWindowsUpdate.wsf script will be able to update your computer without access the internet to do so.


Comments (12)
  1. I suppose it could, but the built-in ConfigMgr install updates pretty much does the same thing already (with ConfigMgr managing and controlling the WSUS server).

    -Michael

  2. That should do it.  Can you e-mail me the BDD.LOG from a deployment to see what it did?  (Make sure you really are running MDT 2008 Update 1 or later.)

    -Michael

  3. Anonymous says:

    Michael,

    When it connects to WSUS, does it only install the required updates, or does it try to install everything, including updates already installed?

  4. Anonymous says:

    But in case of the configmgr isntall updates, you need to enable and configure Software Updates in SCCM and create software update packages etc?

  5. Anonymous says:

    I am having a heck of a time figuring out why the WUA will not automatically install from my deployment point. The BDD log state the agent is about to install, gives the correct share name and platform exe. Then just sits tight there, not actually installing. As a test, I connected to the share name and manually installed the agent, restarted and it picked right up. Any ideas?

  6. Anonymous says:

    Ok…question, i’m trying to enable WSUS updates to be installed via MDT deployment.  I enable it in the task sequence, and make sure i’ve updated my customsettings.ini file with the following

    [Settings]

    Priority=Default

    WSUSServer=http://myservername_omitedforsecurity

    but when it runs, it pulls from the interent.  Upon investigating, i notice its because its not adding the registry entries to make it pull from my WSUS Server

    so, is there anything else i have to do, after I edit my customsettings.ini file and then update the WinPE boot image?  Anything else i need to do?  Any help would be great!  thanks

  7. Anonymous says:

    Mike,

    As we discussed yesterday, you mentioned there were some bugs with the WindowsUpdate script. I thought i might bring up something i found, and the solution i found as well.

    After running WSUS, i tried going to windowsupdate.com but it failed when trying to install the Genuine validation stuff, i looked at the error log and came up with 0x80240fff. So i searched on the internet and came up with the following solution.

    http://www.pcreview.co.uk/forums/thread-2095451.php

    regsvr32 %windir%system32wups2.dll

    That worked for me. Perhaps this is a bug?

  8. Yes, that would be needed.

  9. Anonymous says:

    Could this MDT feature to install all approved updates directly via WSUS (which is a very nice feature!!) also be used in SCCM OSD task sequences(so without Software Updates configured on the SCCM server)?

  10. showbox says:

    Thanks for the great info. I really loved this. I would like to apprentice at the same time as you amend your web site, how could i subscribe for a blog site?
    For more info on showbox please refer below sites:
    http://showboxandroids.com/showbox-apk/
    http://showboxappandroid.com/
    Latest version of Showbox App download for all android smart phones and tablets.
    http://movieboxappdownloads.com/ – It’s just 2 MB file you can easily get it on your android device without much trouble. Showbox app was well designed application for android to watch movies and TV shows, Cartoons and many more such things on your smartphone.
    For showbox on iOS (iPhone/iPad), please read below articles:
    http://showboxappk.com/showbox-for-ipad-download/
    http://showboxappk.com/showbox-for-iphone/
    Showbox for PC articles:
    http://showboxandroids.com/showbox-for-pc/
    http://showboxappandroid.com/showbox-for-pc-download/
    http://showboxforpcs.com/
    There are countless for PC clients as it is essentially easy to understand, simple to introduce, gives continuous administration, effectively reasonable. it is accessible at completely free of expense i.e., there will be no establishment charges and after establishment
    it doesn’t charge cash for watching films and recordings. Not simply watching, it likewise offers alternative to download recordings and motion pictures. The accompanying are the strides that are to be taken after to introduce Showbox application on Android.
    The above all else thing to be done is, go to the Security Settings on your Android telephone, Scroll down and tap on ‘Obscure sources’.

  11. aw says:

    hai, I just want to tell you that I am just very new to blogs and seriously loved this website. More than likely I’m planning to bookmark your blog post .
    You amazingly come with really good posts. Thanks a lot for sharing your blog Microsoft.

    http://www.lokerjobindo.com/search/label/Loker%20Jurusan%20Akunting
    http://www.lokerjobindo.com/search/label/Loker%20Jurusan%20Asuransi
    http://www.lokerjobindo.com/search/label/Loker%20Jurusan%20Teknologi%20Informasi
    http://www.lokerjobindo.com/search/label/Lowongan%20Kerja%20Administrasi
    http://www.lokerjobindo.com/search/label/Lowongan%20Kerja%20Akuntansi
    http://www.lokerjobindo.com/search/label/Lowongan%20Kerja%20Alfamart
    http://www.lokerjobindo.com/search/label/Lowongan%20Kerja%20Arsiparis
    http://www.lokerjobindo.com/search/label/Lowongan%20Kerja%20Artis
    http://www.lokerjobindo.com/search/label/Lowongan%20Kerja%20Astra
    http://www.lokerjobindo.com/search/label/Lowongan%20Kerja%20Asuransi
    http://www.lokerjobindo.com/search/label/Lowongan%20Kerja%20Auditor
    http://www.lokerjobindo.com/search/label/Lowongan%20Kerja%20Bank
    http://www.lokerjobindo.com/search/label/Lowongan%20Kerja%20Bank%20BJB
    http://www.lokerjobindo.com/search/label/Lowongan%20Kerja%20Bank%20BNI%20Syariah
    http://www.lokerjobindo.com/search/label/Lowongan%20Kerja%20Bank%20BRI
    http://www.lokerjobindo.com/search/label/Lowongan%20Kerja%20Bank%20Danamon
    http://www.lokerjobindo.com/search/label/Lowongan%20Kerja%20Bank%20Mandiri
    http://www.lokerjobindo.com/search/label/Lowongan%20Kerja%20Bank%20Indonesia
    http://www.lokerjobindo.com/search/label/Lowongan%20Kerja%20Bank%20BCA
    http://www.lokerjobindo.com/search/label/Lowongan%20Kerja%20Bank%20BTN
    http://www.lokerjobindo.com/search/label/Lowongan%20Kerja%20Bank%20CIMB%20NIAGA

Comments are closed.

Skip to main content