This is fine if you only have few computers but once you star managing many hundreds or thousands of computers this quickly becomes impractical.One of the options you can set using Group Policy is called “Specify intranet Microsoft update service location” which allows you to specify the WSUS Server name.Even thought this setting can be controlled via Group Policy and thus can be changed in about 2 hours, I still strongly recommend that you create a DNS Alias.

I also believe that even if you have bought and implemented System Center Configuration Manager in your environment then you are probably still better off using WSUS for manage you updates for your Microsoft software.

The reason why I still normally recommend that people using WSUS over SCCM is that the product overall is much easier to use and its just human nature for people to want to do the easier tool where possible…

You would use the following Target Group Structure…

You might also notice in the above image I also have “Terminal Servers” and “Servers” at the top level of the WSUS Structure.

However there are a couple of reason why I think SCCM should still be used over WSUS and they are: Below are a collecting of configuration recommendations and tips that help you get the most our of your WSUS infrastructure in your environment.

These are in no particular order of importance and you might chose to implement only some of these setting depending on your environment.

Another great thing about WSUS is that the Automatic Update agent, which is the software the client uses to connect to the server, is included out of the box in every single copy of Windows Since XP.

This means that there is no additional software agents that need to be deployed to the computers to get starting using WSUS. You can set a policy at the very top level of your domain using the “Specify intranet Microsoft update service location” setting to configure every computer on your domain to point to the WSUS servers.

Generally I recommend in most environments these are the only top three WSUS groups you will need.