- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-14-2023 10:19 AM
Allow to update windows without allow accessing the internet.
I have created this URL Category too, and added to the policy:
windowsupdate.microsoft.com/
*.windowsupdate.microsoft.com/
update.microsoft.com/
*.update.microsoft.com/
*.windowsupdate.com/
*.download.windowsupdate.com/
download.microsoft.com/
*.download.microsoft.com/
wustat.windows.com/
ntservicepack.microsoft.com/
stats.microsoft.com/
amupdatedl.microsoft.com/
*.events.data.microsoft.com/
*.data.microsoft.com/
smartscreen-prod.microsoft.com/
Look at my policy in the photo please
09-15-2023 02:14 PM - edited 09-15-2023 02:15 PM
Hello,
Looks good so far. The biggest issue I have found with windows updates is that Microsoft utilizes Akamai for content delivery. This often causes failures in a system attempting to get updates. However the client usually does get the updates, etc. Just keep an eye on the traffic that is getting blocked and see if you need to tune the policy you already have.
Do not decrypt this traffic as it will break. Also remember that users will be able to put www.microsoft.com into a browser and get to the site (this is unavoidable). Also here is a list I have for MS update URLS:
*.download.windowsupdate.com
*.manage.microsoft.com
*.officecdn.microsoft.com
*.update.microsoft.com
*.windowsupdate.com
*.windowsupdate.microsoft.com
blob.core.windows.net
bspmts.mp.microsoft.com
config.office.com
definitionupdates.microsoft.com
dl.delivery.mp.microsoft.com
download.microsoft.com
download.windowsupdate.com
go.microsoft.com
ntservicepack.microsoft.com
officecdn.microsoft.com
sccmconnected-a01.cloudapp.net
silverlight.dlservice.microsoft.com
test.stats.update.microsoft.com
windowsupdate.microsoft.com
wustat.windows.com
*.do.dsp.mp.microsoft.com
*.delivery.mp.microsoft.com
*.prod.do.dsp.mp.microsoft.com
*.wdcp.microsoft.com
*.wdcpalt.microsoft.com
*.wd.microsoft.com
*.download.microsoft.com
*.akamaiedge.net
*.akamaitechnologies.com
*.blob.core.windows.net
configmgrbits.azureedge.net
urs.microsoft.com
login.microsoftonline.us
download.visualstudio.microsoft.com
*.events.data.microsoft.com
aka.ms
Yes some could be outdated.
Regards,
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!