Allow to update windows without allow accessing the internet.
I have created this URL Category too, and added to the policy:
Look at my policy in the photo please
Looks good so far. The biggest issue I have found with windows updates is that Microsoft utilizes Akamai for content delivery. This often causes failures in a system attempting to get updates. However the client usually does get the updates, etc. Just keep an eye on the traffic that is getting blocked and see if you need to tune the policy you already have.
Do not decrypt this traffic as it will break. Also remember that users will be able to put www.microsoft.com into a browser and get to the site (this is unavoidable). Also here is a list I have for MS update URLS:
Yes some could be outdated.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!