Approving WSUS updates for one computer group at a time

We have a WSUS server, and four computer groups (Alpha, Beta, Production, Workstations). Our patching process has us approve all "Not Approved" patches for the Alpha group, right after they're released by Microsoft. One week later, we approve all
of the updates from the previous week, for the Beta group. One week later, we do the same for Production. 
I'm writing a script (which I can't test until next week), and wonder if there's a better way to get the list of updates that are approved for Alpha. Here is the code: 
$updateScope = New-Object Microsoft.UpdateServices.Administration.UpdateScope
$updateScope.ApprovedStates = [Microsoft.UpdateServices.Administration.ApprovedStates]::LatestRevisionApproved
$updateScope.FromArrivalDAte = (Get-Date).AddMonths(-1)
$wsusGroup = $wsus.GetComputerTargetGroups() | Where {$_.Name -eq "$PatchingGroup"}
$updateScope
$updateScope.getType()
$updateScope.count
$updateScope.ApprovedComputerTargetGroups.add($wsusGroup)
$wsus.GetUpdates($updateScope)
$Updates = $wsus.GetUpdates($updateScope)
I assume I can take the $Updates variable and do the following for the Beta and Production groups: 
Foreach ($update in $updates) {
$update.Approve(“Install”,$PatchingGroup)
Is this going to work, and is there a better way?

For WSUS Scripts see this: http://poshwsus.codeplex.com/
¯\_(ツ)_/¯

Similar Messages

  • How to ignore an update for a computer?

    It appears that KB2862330 and its USB driver changes has created a problem with a USB-connected scanner, so I would like on this client to Uncheck the update and Hide it so as not to be bothered with it again.
    This leaves WSUS to report that the updates for this computer are not complete, which is a distraction I do not want. I have tried moving this computer into a new computer group ("Exceptions") and then removing the Approval for this group, but
    this has not worked i.e. WSUS still reports this computer as "needing an update".
    Is there any way to have WSUS not report this computer as needing this update?

    It appears that KB2862330 and its USB driver changes has created a problem with a USB-connected scanner
    So, first question: is this the *fixed* KB2862330 that was revised on 1/14/2014, or is this the original KB2862330 from October that has a large number of identified defects?
    I would like on this client to Uncheck the update and Hide it so as not to be bothered with it again.
    That's one possible approach.
    This leaves WSUS to report that the updates for this computer are not complete, which is a distraction I do not want.
    Correct. But it's a fact. If you don't install the update, the update is not installed, and nothing is ever going to change that fact.
    Is there any way to have WSUS not report this computer as needing this update?
    So, essentially, you're saying you want WSUS to lie about a reality that exists?
    No, there's no way to have the Windows Update Agent report the status on an update any different than it actually is.
    However, once you have installed KB2862330 every place else you plan to install it, you could DECLINE that update, which will prevent this client (and of course all the others) from reporting ANY state information about that update at all. Downside: You'll
    have no way of knowing (via WSUS) where the update is or is not installed... AND... none of that prevents an unhelpful user of that system from subsequently installing that update anyway.
    Lawrence Garvin, M.S., MCSA, MCITP:EA, MCDBA
    SolarWinds Head Geek
    Microsoft MVP - Software Packaging, Deployment & Servicing (2005-2014)
    My MVP Profile: http://mvp.microsoft.com/en-us/mvp/Lawrence%20R%20Garvin-32101
    http://www.solarwinds.com/gotmicrosoft
    The views expressed on this post are mine and do not necessarily reflect the views of SolarWinds.

  • How to Make installer for one Computer ?

    Hello All,
    I want to make application installer only for one computer, like single license copy how it is possible in LabWindows/CVI ?
    Is there any LabWindows build-in option or how it will possible ?
    Regards
    Umer
    Solved!
    Go to Solution.

    I don't think there is a bult-in capability to create an installer that will run on a single PC, but you can incorporate in your application instructions on some hardware item of the target system and create your own licensing algorithm on them.
    This subject has already been discussed in this forum: you can look at this thread and this other one.
    In the last page, I mention a sample of mine which is available on the Community: I have updated it to retrieve the disk serial number also, as it can be useful to get a unique sign for a specific PC; the sample uses WMI to get system infos: you can find the modified version attached to this message. You need full CVI version to run the sample.
    Proud to use LW/CVI from 3.1 on.
    My contributions to the Developer Zone Community
    If I have helped you, why not giving me a kudos?
    Attachments:
    CallWMI_2.zip ‏11 KB

  • What happened ??? I did the "there are updates for your computer" & now...

    I have a macbook pro I bought 5 mos. ago.... yesterday when I went to shut down my computer I get a pop up thing that says there are updates for my computer and that I would need to restart it when I'm done or something like that... so I did it, and now...... my computer is slower, and everytime you got to load a new page, the address in the address bar has this blue highlight that scrolls from left to right as the page is slowly loading.... what happened?????

    I disagree with the recommendation to try Chrome.Since the last Chrome update I am experiencing the same issues you are.I have also tried Opera which is fairly fast but extremely buggy in my experience.I have used Firefox but dislike it for the same reason I disliked IE.............toolbars!And I want to see more of the page than it displays.My Dad swears by Safari but I find the interface to be less user friendly than either Chrome or Opera.I must confess that I have all 4 of these browsers on my late-2008 MBP and use each one in different situations based on my needs at the time.Try them all and decide which is right for you.The best choices are made with hands-on experience.

  • How do i transfer music for one computer to a laptop via home sharing?

    how do i transfer music for one computer (desktop) to a laptop via home sharing? the home share is switched on but cant see how to transfer music over
    i cant see the little house on the left hand side under where it says genius, 90s music classical music etc, there is also no import or export botton at the bottom of the screen.

    Welcome to the Apple Community.
    Select the content you want to import from the shared library and click the import button at the bottom of the screen.

  • Received notice of an update for one of my apps and when I tried to update the message reads "Account Not in this store"  i must switch to a Canadian store before purchasing

    Received notice of an update for one of my apps and when I tried to update the message reads "Account Not in this store"  i must switch to a Canadian store before purchasing.  I deleted app and tried to download again but still got the message.  Anyone know how to fix?  FYI have had phone for 2 years and this is the first time this has happened.

    The Apple id that you created do you remember if you created with your region sellected as Canada or US. If so you can change Region directly on your device by clicking on App Store icon, Scroll to bottom and tap your app is, click view acct and change region

  • Originating document number not updated for one invoice line item

    Hi,
    We have a invoice document number in which the originating document number is not updated for one of the line items ,this is order related down payment invoice .May be this is due to system inconsistency so is there any SAP note to overcome this problem.
    Best Regards,
    Rohit

    Dear All,
             I found out the problem for not updated in F-04. "While create the receipt document in GL master Open item management maintained box was not checked". It can be found in BSIS table - OI Management'.
             Is there any other way to clear this document.
    Thanks...

  • HT5460 I have an 3 year old mac and would like to update to osx 10.6 or later. when I look for updates, it says that it has no software updates for my computer... help.

    I have an 3 year old mac and would like to update to osx 10.6 or later. when I look for updates, it says that it has no software updates for my computer... help?

    You need to buy it on DVD.
    (96867)

  • My account is good for one computer. Or is it?

    My iTunes setup says that my account is good for one computer. Would that include using the iPod (account) connected and synced to my PC? Do I need to similarily setup the same or different account on my iPod? Please explain. (Note: My iPod already syncs with the CD I added to iTunes in my PC.)
     How many pieces of gear can used in this fashion (ie: iPod, iPad, iPhone, and computer), I'm guessing management on one computer plus another piece of hardware like iPod . . . or am I wrong?   
    I guess to avoid confusion . . . is one account for both sufficient and agreeable to Apple?
    Any advice or help will be appreciated.
    TIA

    Well, I'm getting on since I hit Trafalger when I was 18 (old enough to hit the pubs there but not here). I hung out at the Friend At Hand and drank Watneys (and anything else). Made it to Liverpool, Torquay, and in between. Some of my best memories. Almost had a ideal job at BOAC, but immigration quotas from the far east nixed that.   Still listen to Radio Caroline on this side of the Atlantic.
    Got my connection and account to iTunes working on both the PC and iPod now. Haven't located iTunes radio though on the iPod. Do you know if it is even possible with the older 4.2 version?
    Thanks, again.

  • Can I have several itunes libraries on one computer at the same time?

    can I have several itunes libraries on one computer at the same time?

    Thank Niel 
    I have already got a library hosted on another computer and have homeshared my apple id for my home laptop, but I'm not sure what to do there after - any help would be appreciated!  I' worried I make my husband's library disappear......

  • I am trying to download adobe reader for my macbook air but it keeps stopping at 44%. I have downloaded the latest updates for my mac and retried numerous times. Please advise. Thank you

    I am trying to download adobe reader for my macbook air but it keeps stopping at 44%. I have downloaded the latest updates for my mac and retried numerous times. Please advise. Thank you

    As posted about a dozen times every day, try the offline installer from http://get.adobe.com/reader/enterprise/

  • Approval Query to skip for one Vendor Group - Not working

    Dear All,
    I am trying to create an approval query wherein when a user creates a Purchase Order for a Particular Vendor Group then the approval check is not required and for other Vendor Group approval check is required. The query is as under :
    SELECT distinct 'true'  FROM OPOR T0  INNER JOIN OCRD T1 ON T0.CardCode = T1.CardCode INNER JOIN OCRG T2 ON T1.GroupCode = T2.GroupCode WHERE T2.GroupName <> 'Supplier Own Group'
    I don't want that which vendors are in Supplier Own Group check go for an approval process. Means all vendors in this group should get skipped for approval.
    How to achieve this because this query seems not to be working in the approval process because when a user creates a PO whose Vendor group is under Supplier Own Group then also the approval checking is happening.
    Please help how to resolve this issue.
    Regards,
    Depika

    Hi,
    Try this
    SELECT distinct 'true'  FROM OPOR T0  INNER JOIN OCRD T1 ON T0.CardCode = T1.CardCode INNER JOIN OCRG T2 ON T1.GroupCode = T2.GroupCode
    AND T2.GroupName <> 'Supplier Own Group' where T0.CardCode = $[$4.1.0]
    Hope this helps,
    Son.

  • Approving WSUS updates via PowerShell

    Experts,
        Last week patches were auto approved for installation to my test WSUS groups. I would like to use PowerShell to release the same updates to my production machines. I'm not sure if this script would release the same updates.
    Get-WsusUpdate -Classification All
    -Approval Unapproved -Status FailedOrNeeded | Approve-WsusUpdate
    -Action Install -TargetGroupName
    "General".
    Does anyone know of a script that could release the same updates that were auto approved for testing?
    Any assistance would be greatly appreciated.
    Flite23

    Hi,
    unfortunately the native CMDlets are somewhat lacking in functionality (in this case you can't get the approved status for a target group with Get-WSUSUpdate), but Boe Prox has done a lot of really cool stuff around this. He has a series of
    articles over at the scripting guy that might be worth a good starting place.
    Failing that it would be worth giving a look at PoshWSUS, Boe's PowerShell module. Created for WSUS 3.0 SP2, it also works with WSUS 6.x 
    If you find the answer of assistance please "Vote as Helpful"and/or "Mark as Answer" where applicable. This helps others to find solutions for there issues, and recognises contributions made to the community :)

  • More than one iTunes for one computer.

    I have a brother and a sister, and we all have iPods, but only one computer. We have a windows XP so, several different accounts. I already have iTunes set up, but my brother and sister don't. Is it possible to have 3 separate iTunes for each of us? If so, how? And if not, what can I do?
    Windows XP   Windows XP Pro  

    There are basically two ways of using multiple iPods on a computer and these involve:
    a) Sharing a single iTunes library and or user account.
    b) Creating multiple user accounts and having separate libraries.
    Sharing a Library and/or User Account
    If you want to share the one library, you can set either or all of the iPods so that they only get updated with only certain playlists (you can update from more than one if you wish):
    Loading songs onto iPod automatically - Windows
    Choosing the update option "Sync Music - Selected playlists" allows you to create a playlist specifically for the iPod and drag the tracks you want into it. If you tire of the list and want to change it, you just add or remove the songs you don't want. The ones you take out out remain in the library to be used some other time if you choose. You can read more about playlists at these links:
    iTunes: Creating playlists of your favorite songs
    How to create a Smart Playlist with iTunes
    Or you can choose to update any or all of the iPods manually and just drag whatever content you want to them: Managing content manually on iPod
    Loading the iPod shuffle differs slightly but it can still be used with the others, for details have a look at this page:
    Loading songs onto iPod shuffle - Windows
    It's also possible to have multiple libraries in a single account. To create or access a second (or more) library, hold down the Option key (or Shift key in Windows) when launching iTunes 7. In the resulting dialogue you will get the option to create a new library or navigate to the other Library.
    Note: You can only have one Library open at a time and iTunes will default to the last library opened if you don't use the keyboard command to choose one. This can prove tricky when using multiple iPods, if you don't use the keyboard command you can risk syncing to the wrong library:
    Using multiple iTunes libraries -Windows
    Separate User Accounts
    Another option is to create a separate User account for each person on your PC or Mac (which it appears you have already done). Different accounts by definition would give you completely separate libraries. Each account utilises the same iTunes program located in the Program Files folder but has it's own iTunes folder, Library and iTunes Music folder and you load it with CDs etc just as you did with your original one. The iPod can be set to update however the owner chooses, sync all, manual or sync specific playlists

  • Setting a GPO for one computer regardless of the user permissons

    I have one computer that needs to be on a different GPO due to it being used for the boardroom meetings and the board of the directors do not like the 15 minute inactivity time that I have set on the Default Domain Policy. They want the computer to never
    lock due to inactivity and then have to sign back in again. But I am having major difficulties with the boardroom computer accepting this and picking the correct policy as the Winning GPO.  
    When I run the gpresults command, under Computer Configuration Summary - it shows that this GPO Was Applied. Under User Configuration Summary - it shows that this GPO was Denied (Security Filtering)....When I scroll down the page, it lists Computer Configuration
    and it has the Default Domain Policy as the Winning GPO on everything except Account Policies/Account Lockout Policy.  
    On the Group Policy Management on the domain controller - In the Scope section and underneath Security Filtering, I have the Boardroom Computer added here. On the Delegation section and underneath Advanced, I have the Read, Write, and Allow Group Policy
    allowed for the Computer Name permission.
    On the Precedence, I have the boardroom GPO as number one and the Default Domain Policy as number two. They are both Link Enabled and I have the boardroom as Enforced and the Default Domain Policy as not enforced.  
    Another issue that I don't know is interfering with this or not is that my primary domain controller is Server 2012 and I can't edit the Group Policys on it because not all of the options are there, so I have been working all of this on my secondary domain
    controller which is Server 2008.
    What do I need to do or check to make this works the way that it needs to? Thank you.

    Hi,
    Okay so the policy setting you have set is a user based policy not a computer based policy, so by targeting the computer it won't work.
    What I have done in the past to target just one computer is this.
    Create a new group policy.
    Set in the group policy the desired inactivity times in the screen saver - for never I think you can just set it to disabled.
    In the computer configuration > admin templates > system > group policy - enable the loopback processing and set it to merge.
    link the policy to your computers OU / the domain level.
    Change the permissions of the GPO and remove authenticated users from the policy permissions.
    Create a security group in AD (maybe call it no screensaver) and then add your computer to the group. You also need to add in domain users into the group, so this will mean that any user logging into the computer will not get the screen saver policy applied.
    Regards,
    Denis Cooper
    MCITP EA - MCT
    Help keep the forums tidy, if this has helped please mark it as an answer
    Blog: http://www.windows-support.co.uk 
    Twitter:   LinkedIn:

Maybe you are looking for