Dear colleagues.
I have a question for you. Despite setting the wsus configuration GPO policy not which machines are downloading updates bypassing WSUS. It is possible to force manual search for patches from the Internet but that would be strange. From proxy logs more than 500 machines are downloading packages directly from microsoft sites. Is it possible to verify this or how to check why machines are not using wsus?

2 Spice ups

Show us your WSUS GPO policies. A screenshot will do

Typically you have to hide the Windows Update screen from users too (or at least disable the buttons (in my experience)

2 Spice ups

1 Spice up

Configuration was not changed therefore situation “strange”

1 Spice up

to use WSUS you need to use option 4 (Auto Download and Schedule not option 3 Auto Download ans notify

3 Spice ups

Thank you

1 Spice up