How I should control and fine tune updates to systems?
Structure:
- Computers (Clients/Servers) in AD --> WSUS is configured or disabled per different GPOs on different OUs
- Updates on WSUS are approved on every WSUS (using the Patch Manager Console) to Computer groups ("Test", "Server", "Clients") or the group "All Computers"
I have an Update (Java 7u67 x64) which would apply to all 64bit machines but should only be installed on systems in a subgroup of the WSUS-Group "Clients". (so it is configured at the moment)
But now in the other groups the update is shown as needed, not installed and not approved for the 64bit systems of this groups.
Do I only have to decline the update to this groups?