Allow to update windows

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Allow to update windows

L0 Member

Allow to update windows without allow accessing the internet.

 

I have created this URL Category too, and added to the policy:

 

windowsupdate.microsoft.com/

*.windowsupdate.microsoft.com/

update.microsoft.com/

*.update.microsoft.com/

*.windowsupdate.com/

*.download.windowsupdate.com/

download.microsoft.com/

*.download.microsoft.com/

wustat.windows.com/

ntservicepack.microsoft.com/

stats.microsoft.com/

amupdatedl.microsoft.com/

*.events.data.microsoft.com/

*.data.microsoft.com/

smartscreen-prod.microsoft.com/

 

 

Look at my policy in the photo please

 

01.jpg

1 REPLY 1

Cyber Elite
Cyber Elite

Hello,

Looks good so far. The biggest issue I have found with windows updates is that Microsoft utilizes Akamai for content delivery. This often causes failures in a system attempting to get updates. However the client usually does get the updates, etc. Just keep an eye on the traffic that is getting blocked and see if you need to tune the policy you already have. 

Do not decrypt this traffic as it will break. Also remember that users will be able to put www.microsoft.com into a browser and get to the site (this is unavoidable). Also here is a list I have for MS update URLS:

*.download.windowsupdate.com
*.manage.microsoft.com
*.officecdn.microsoft.com
*.update.microsoft.com
*.windowsupdate.com
*.windowsupdate.microsoft.com
blob.core.windows.net
bspmts.mp.microsoft.com
config.office.com
definitionupdates.microsoft.com
dl.delivery.mp.microsoft.com
download.microsoft.com
download.windowsupdate.com
go.microsoft.com
ntservicepack.microsoft.com
officecdn.microsoft.com
sccmconnected-a01.cloudapp.net
silverlight.dlservice.microsoft.com
test.stats.update.microsoft.com
windowsupdate.microsoft.com
wustat.windows.com
*.do.dsp.mp.microsoft.com
*.delivery.mp.microsoft.com
*.prod.do.dsp.mp.microsoft.com
*.wdcp.microsoft.com
*.wdcpalt.microsoft.com
*.wd.microsoft.com
*.download.microsoft.com
*.akamaiedge.net
*.akamaitechnologies.com
*.blob.core.windows.net
configmgrbits.azureedge.net
urs.microsoft.com
login.microsoftonline.us
download.visualstudio.microsoft.com
*.events.data.microsoft.com
aka.ms

 

Yes some could be outdated.

 

Regards,

  • 6280 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!