Configure The Group Policy To Enable Third-party Updates
Maybe your like
- SolarWinds uses cookies on its websites to make your online experience easier and better. By using our website, you consent to our use of cookies. For more information on cookies, see our Cookie Policy. Continue
- Academy
- SOLARWINDS ACADEMY
- CLASSES
- ELEARNING
- CERTIFICATION
- See What's Offered
- Virtual Classrooms Calendar
- View Product Trainers
- Quick Byte Videos
- eLearning Video Index
- SolarWinds Certified Professional Program
- View all Classes
- View Product Trainers
- General Office Hours
- Quick Byte Videos
- Orion Platform
- Network Performance Monitor
- View the Calendar
- NetFlow Traffic Analyzer
- IP Address Manager
- Network Configuration Manager
- Server & Application Monitor
- Virtualization Manager
- See All Videos
- Upgrading Isn't as Daunting as You May Think
- Upgrading Your Orion Platform Deployment Using Microsoft Azure
- Upgrading From the Orion Platform 2016.1 to 2019.4
- Don't Let the Gotchas Get You
- How to Install NPM and Other Orion Platform Products
- Upgrading the Orion Platform
- See All Videos
- Navigating the Web Console
- Prepare a SAM Installation
- Installing Server & Application Monitor
- How to Install SEM on VMware
- Customer Success with the SolarWinds Support Community
- New job, New to SolarWinds?
- Learn More
- Access Rights Manager
- Architecture and Design
- Database Performance Analyzer
- Diagnostics and Troubleshooting
- NetFlow Traffic Analyzer
- Network Configuration Manager
- Network Performance Monitor
- Server & Application Monitor
- Security Event Manager
SOLARWINDS ACADEMY
The SolarWinds Academy offers education resources to learn more about your product. The curriculum provides a comprehensive understanding of our portfolio of products through virtual classrooms, eLearning videos, and professional certification.AVAILABLE RESOURCES
VIRTUAL CLASSROOMS
Attend virtual classes on your product and a wide array of topics with live instructor sessions or watch on-demand videos to help you get the most out of your purchase.Open Sessions and Popular Classes
ELEARNING VIDEOS
On-demand videos on installation, optimization, and troubleshooting.Popular Videos
SOLARWINDS CERTIFIED PROFESSIONAL PROGRAM
Become a SolarWinds Certified Professional to demonstrate you have the technical expertise to effectively set up, use, and maintain SolarWinds’ products.STUDY AIDS
- ONBOARDING & UPGRADING
- NEW TO SOLARWINDS
- UPGRADE RESOURCE CENTER
- ONBOARDING
- Learn More
- Visit the Upgrade Resource Center
- Self-Led Onboarding
- Deployment Services
NEW TO SOLARWINDS
You just bought your first product. Now what? Find out more about how to get the most out of your purchase. From installation and configuration to training and support, we've got you covered.UPGRADE RESOURCE CENTER
See helpful resources, answers to frequently asked questions, available assistance options, and product-specific details to make your upgrade go quickly and smoothly.ONBOARDING
SolarWinds Onboarding programs are designed to help walk you through product installations, and more to deliver immediate value on your product experience. We offer self-led and assisted options, so you can choose the one that best fits your business needs and schedule.AVAILABLE DEPLOYMENT SERVICES PROGRAMS
- Support Offerings
- PREMIUM SUPPORT OFFERINGS
- FEDERAL SUPPORT OFFERINGS
- WORKING WITH SUPPORT
- Learn More
- Professional Support
- Advanced Support
- Premium Support Level 1
- Premium Support Level 2
- Premium Support Level 3
- Federal Premium Support
- Federal Deployment Services
- Learn More
PREMIUM SUPPORT OFFERINGS
Our paid Customer Support plans provide assistance with Solarwinds product questions, troubleshooting, and product-related issues. Choose what best fits your environment and organization, and let us help you get the most out of your purchase. We support all of our products, 24/7/365.AVAILABLE PROGRAMS
- FEDERAL SUPPORT OFFERINGS
AVAILABLE PROGRAMS
WORKING WITH SUPPORT
A glossary of support availability, tips, contact info, and customer success resources. We're here to help. - PRODUCTS
- MONITORING & OBSERVABILITY
- NETWORK MANAGEMENT
- SYSTEMS MANAGEMENT
- DATABASE MANAGEMENT
- IT SECURITY
- IT SERVICE MANAGEMENT
- APPLICATION MANAGEMENT
- DOCUMENTATION
- Product Support Page
- SolarWinds Observability (formerly known as Hybrid Cloud Observability) Technical Documentation
- SolarWinds Observability (formerly known as Hybrid Cloud Observability) Product Details
- SolarWinds Observability SaaS (formerly known as SolarWinds Observability) Technical Documentation
- SolarWinds Observability SaaS (formerly known as SolarWinds Observability) Product Details
- Network Performance Monitor
- NetFlow Traffic Analyzer
- IP Address Manager
- Network Configuration Manager
- Engineer's Toolset
- Network Topology Mapper
- View All Network Management Products
- User Device Tracker
- VoIP Network Quality Manager
- Log Analyzer
- Enterprise Operations Console
- Kiwi CatTools
- Kiwi Syslog Server NG
- Server & Application Monitor
- Virtualization Manager
- Storage Resource Monitor
- Serv-U Managed File Transfer
- Serv-U Secured FTP
- View All Systems Management Products
- Server Configuration Monitor
- Log Analyzer
- Access Rights Manager
- Web Performance Monitor
- Database Performance Analyzer
- SQL Sentry
- View All Database Management Products
- Security Event Manager
- Access Rights Manager
- Serv-U Managed File Transfer Server
- Serv-U FTP Server
- Patch Manager
- View All IT Security Products
- Dameware Remote Everywhere
- Dameware Remote Support
- Dameware Mini Remote Control
- Service Desk
- Web Help Desk
- View All IT Service Management Products
- Server & Application Monitor
- Loggly
- Log Analyzer
- View All Application Management Products
- Papertrail
- Pingdom
- Web Performance Monitor
MONITORING AND OBSERVABILITY
SolarWinds Observability is a full-stack, AI-powered solution that offers two deployment options: Self-hosted and SaaS. With the continued expansion of network and infrastructure capabilities in the SaaS option and the continued expansion of cloud capabilities in the self-hosted option, both offerings can provide end-to-end hybrid visibility. They also include overlapping capabilities and interconnectivity, giving IT teams and the organizations they support the flexibility to observe complex environments however they want.USEFUL RESOURCES
NETWORK MANAGEMENT
Award-winning, instructor-led classes, eLearning videos, and certifications.
Find a ClassSYSTEMS MANAGEMENT
Award-winning, instructor-led classes, eLearning videos, and certifications.
Find a ClassDATABASE MANAGEMENT
Award-winning, instructor-led classes, eLearning videos, and certifications.
Find a ClassIT SECURITY
Award-winning, instructor-led classes, eLearning videos, and certifications.
Find a ClassIT SERVICE MANAGEMENT
Award-winning, instructor-led classes, eLearning videos, and certifications.
Find a ClassAPPLICATION MANAGEMENT
Award-winning, instructor-led classes, eLearning videos, and certifications.
Find a Class - COMMUNITY
- THWACK®
- SOLARWINDS BLOG
- TECHPOD
- Visit THWACK
- SolarWinds User Groups
- THWACK Livecast
- THWACKcamp 2024 On-Demand
THWACK®
Over 200,000 users—get help, be heard, improve your product skillsAVAILABLE PROGRAMS
- Academy Newsroom
- SolarWinds Certified Professional (SCP) Forum
- Classroom Training Forum
SolarWinds Blog
Join us on the road to talk AI, observability, and IT management. We've got real-world insights you just won't hear about anywhere else.- Visit Blog
TECHPOD
Join the brightest SolarWinds minds and IT industry influencers, as they cut through the jargon and give you the tools you need to grow and keep your tech knowledge razor-sharp. Come with questions—leave with actionable steps and practical insights.- Episodes
- NEW TO SOLARWINDS
- SUBMIT A TICKET
- Academy
- SOLARWINDS ACADEMY
- See What's Offered
- Virtual Classrooms Calendar
- View Product Trainers
- Quick Byte Videos
- eLearning Video Index
- SolarWinds Certified Professional Program
- CLASSES
- View all Classes
- View Product Trainers
- General Office Hours
- Quick Byte Videos
- Orion Platform
- Network Performance Monitor
- View the Calendar
- NetFlow Traffic Analyzer
- IP Address Manager
- Network Configuration Manager
- Server & Application Monitor
- Virtualization Manager
- ELEARNING
- See All Videos
- Upgrading Isn't as Daunting as You May Think
- Upgrading Your Orion Platform Deployment Using Microsoft Azure
- Upgrading From the Orion Platform 2016.1 to 2019.4
- Don't Let the Gotchas Get You
- How to Install NPM and Other Orion Platform Products
- Upgrading the Orion Platform
- See All Videos
- Navigating the Web Console
- Prepare a SAM Installation
- Installing Server & Application Monitor
- How to Install SEM on VMware
- Customer Success with the SolarWinds Support Community
- New job, New to SolarWinds?
- CERTIFICATION
- Learn More
- Access Rights Manager
- Architecture and Design
- Database Performance Analyzer
- Diagnostics and Troubleshooting
- NetFlow Traffic Analyzer
- Network Configuration Manager
- Network Performance Monitor
- Server & Application Monitor
- Security Event Manager
- SOLARWINDS ACADEMY
- ONBOARDING & UPGRADING
- NEW TO SOLARWINDS
- Learn More
- UPGRADE RESOURCE CENTER
- Visit the Upgrade Resource Center
- ONBOARDING
- Self-Led Onboarding
- Deployment Services
- NEW TO SOLARWINDS
- Support Offerings
- PREMIUM SUPPORT OFFERINGS
- Learn More
- Professional Support
- Advanced Support
- Premium Support Level 1
- Premium Support Level 2
- Premium Support Level 3
- FEDERAL SUPPORT OFFERINGS
- Federal Premium Support
- Federal Deployment Services
- WORKING WITH SUPPORT
- Learn More
- PREMIUM SUPPORT OFFERINGS
- PRODUCTS
- MONITORING & OBSERVABILITY
- Product Support Page
- SolarWinds Observability Self-Hosted (formerly known as Hybrid Cloud Observability) Technical Documentation
- SolarWinds Observability Self-Hosted (formerly known as Hybrid Cloud Observability) Product Details
- SolarWinds Observability SaaS (formerly known as SolarWinds Observability) Technical Documentation
- SolarWinds Observability SaaS (formerly known as SolarWinds Observability) Product Details
- NETWORK MANAGEMENT
- Network Performance Monitor
- NetFlow Traffic Analyzer
- IP Address Manager
- Network Configuration Manager
- Engineer's Toolset
- Network Topology Mapper
- View All Network Management Products
- User Device Tracker
- VoIP Network Quality Manager
- Log Analyzer
- Enterprise Operations Console
- Kiwi CatTools
- Kiwi Syslog Server NG
- SYSTEMS MANAGEMENT
- Server & Application Monitor
- Virtualization Manager
- Storage Resource Monitor
- Serv-U Managed File Transfer
- Serv-U Secured FTP
- View All Systems Management Products
- Server Configuration Monitor
- Log Analyzer
- Access Rights Manager
- Web Performance Monitor
- DATABASE MANAGEMENT
- Database Performance Analyzer
- SQL Sentry
- View All Database Management Products
- IT SECURITY
- Security Event Manager
- Access Rights Manager
- Serv-U Managed File Transfer Server
- Serv-U FTP Server
- Patch Manager
- View All IT Security Products
- IT SERVICE MANAGEMENT
- Dameware Remote Everywhere
- Dameware Remote Support
- Dameware Mini Remote Control
- Service Desk
- Web Help Desk
- View All IT Service Management Products
- APPLICATION MANAGEMENT
- Server & Application Monitor
- Loggly
- Log Analyzer
- View All Application Management Products
- Papertrail
- Pingdom
- Web Performance Monitor
- DOCUMENTATION
- MONITORING & OBSERVABILITY
- COMMUNITY
- THWACK®
- Visit THWACK
- SolarWinds User Groups
- THWACK Livecast
- THWACKcamp 2024 On-Demand
- Academy Newsroom
- SolarWinds Certified Professional (SCP) Forum
- Classroom Training Forum
- SolarWinds Blog
- Visit Blog
- TECHPOD
- Episodes
- THWACK®
- NEW TO SOLARWINDS
- SUBMIT A TICKET
Perform this procedure only if your organization implements a group policy on all corporate systems.
The group policy defines the user, security, and networking policies for all computers in the network. To enable the managed computers to receive third-party updates from the WSUS server, export the software publishing certificate from the WSUS server to a certificate file. When you are finished, configure the Group Policy Object (GPO) on the domain controller and import the certificate file and the supporting Windows® Update policies.
Patch Manager signs all third-party packages with the software publishing certificate. This certificate must be installed in the local Trusted Root Certification Authority and Trusted Publishers keystores of each managed computer so they can receive third-party updates.
Export the software publishing certificate from the WSUS server
Export the software publishing certificate so you can add the file to the Group Policy (GPO). When you push the GPO to the managed systems, each system can accept third-party updates from non-Microsoft® sources.
-
Select the WSUS server in the Patch Manager menu.
- In the Actions column, click Software Publishing Certificate.
-
Click [...] in the Publishing Certificate Information window.
-
On the Details tab, select the WSUS publishing certificate.
- Click Copy to File in the Certificate window.
- Click Next in the Certificate Export Wizard.
- Select DER encoded binary X.509 (.CER), and click Next.
- Enter a file name (for example, WSUS Publishing Certificate).
-
Complete the Certificate Export Wizard.
The software publishing certificate is exported to a file.
Configure the GPO for the targeted domain
This procedure configures Windows Update policies to the certificate stores on the managed computers so they accept third-party updates from non-Microsoft sources.
- Log in to the domain controller as an administrator.
- Copy the software publishing certificate to the domain controller desktop or another location on the server.
- Navigate to the control panel and open Group Policy Management.
-
In the Group Policy Management menu, navigate to the domain that contains the GPO for the targeted domain (for example, Default Domain Policy).

If you need to create a GPO, right-click the domain (for example, gir.lab), select Create a GPO in this domain, and link it here. Enter a name for the GPO, and click OK. The domain tree displays the GPO.
-
Double-click the GPO (for example, Default Domain Policy).
-
Review the Group Policy Management Console window text, and click OK.
The Scope tab is displayed.
-
In the Windows Update window, enable:
Allow signed updates from an intranet Microsoft update service location
This setting enables Windows Update on managed computers to accept non-Microsoft updates (or third-party updates) from a Microsoft Update location (or WSUS server) in the corporate network.
- Right-click the GPO and select Edit.
- In the Group Policy Management Editor, expand Computer Configuration > Policies > Administrative Templates > Windows Components.
- Scroll down and select Windows Update.
- Double-click Allow signed updates from an intranet Microsoft update service location in the Windows Update window.
- Select Enabled in the Configure Automatic Updates window.
-
Click OK.
This policy setting is displayed as Enabled in the Windows Update window.
-
Add the WSUS software publishing certificate to the group policy.
This process adds the publishing certificate to the Trusted Root Certification Authority and Trusted Publishers certificate stores in the managed computers, enabling each computer to establish a secure network connection to the WSUS server and receive third-party updates.
- In the Group Policy Management Editor, click Policies > Windows Settings > Security Settings > Public Key Policies > Trusted Root Certification Authorities.
- Right-click Trusted Root Certification Authorities and select Import.
-
Complete the Certificate Import Wizard.
When you are finished, the WSUS certificate is imported into the Trusted Root Certification Authority directory. This directory includes SolarWinds certificates, Microsoft certificates, and all certificates in the Third-Party Root Certification Authorities keystore.
- Navigate to the Public Key Policies directory.
- Expand the directory, right-click Trusted Publishers, and select Import.
-
Complete the Certificate Import wizard.
When you are finished, the certificate is imported into the Trusted Publishers directory. This directory includes certificates from trusted Certificate Authorities.
The WSUS software publishing certificate is added to the group policy.
- Enable and configure the Configure Automatic Updates policy setting so the managed computers can automatically check the WSUS server for Windows and third-party updates each day or once a week at a scheduled time.
- Double-click Configure Automatic Updates in the Windows Update window.
- Select Enabled in the Configure Automatic Updates window.
Click the Configure automatic updating drop-down menu and select an update method for the managed computers.
The following table provides descriptions for each setting. Accept Auto download and notify for install (default setting) or select the setting that meets the deployment requirements.
Setting Description Notify before downloading and installing updates Patch Manager notifies you when updates are ready to download. Auto download and notify for install Patch Manager automatically downloads the updates and notifies the system administrator when they are ready to be installed. Automatically download updates and install them on the schedule specified below. Patch Manager automatically downloads the updates and installs them every day or on a specific day (such as Sunday) at a specific time. Allow local administrators to select the configuration mode that Automatic Updates should notify and install updates. Patch Manager allows only the system administrator to use the Windows Update control panel to select a configuration option (for example, Not Configured, Enabled, or Disabled). Local administrators cannot disable the Automatic Updates configuration. - Schedule a date and time for the installations.
Click OK.
The policy setting is displayed as Enabled in the Windows Update window.

-
Enable the Specify Intranet Microsoft Update service location policy setting in the group policy. This setting enables the managed computers to identify the Microsoft Update service location (or WSUS server location) where they can receive Microsoft updates from the WSUS server.
This setting is required to enable a WSUS server in the network.
- Double-click Specify intranet Microsoft update service location in the Windows Update window.
- Select Enabled in the window.
-
Enter the IP address of the WSUS server in both Options box fields.
If you do not have an intranet statistics server in the deployment, enter the WSUS server IP address in both fields.
Use the information in the table below to complete the Options box fields.
WSUS Server OS SSL Enabled? Enter this IP address Windows Server 2012
Windows Server 2012 R2
Windows Server 2016
Yes https://<ip_address>:8531 No http://<ip_address>:8530 Windows Server 2008 Yes http://<ip_address>:443 No http://<ip_address> Windows Server 2008 systems use port 80 by default
-
Click OK.
The policy setting is displayed as Enabled in the Windows Update window.
The GPO is configured on the targeted domain.
Tag » Add Computer To Wsus With Group Policy
-
Deploy Windows Client Updates Using Windows Server Update ...
-
Step 2 - Configure WSUS | Microsoft Docs
-
Configure Group Policy Settings For WSUS In Windows Sever 2019
-
Group Policy Settings For WSUS - ITPro Today
-
WSUS Group Policy Settings To Deploy Updates - Windows OS Hub
-
How To Configure Client Side Targeting In WSUS - Prajwal Desai
-
Install And Configure WSUS On Windows Server 2019 - Prajwal Desai
-
WSUS, "Specify How To Assign Computers To Groups"?
-
8. How To Configure Client Side Targeting In WSUS Server 2019
-
Configure The Client Systems To Download WSUS Server Updates
-
Managing Computer Groups - Windows Server Update Services
-
Create Computer Groups For WSUS - RootUsers
-
55. How Create Group Policy For WSUS And How To Add Machine In ...
-
LAB GUIDE:63 Configure Computer Groups In WSUS Server 2019