The downloaded updates are saved to C:\Windows\Software Distribution\Download.

Assigning clients to different target WSUS groups is based on labels on the client itself (labels are set by a GPO or a direct registry modification).

This kind of client association to the WSUS groups is called client side targeting.

This article will tell how to disable the use of external USB-drives, prevent writing to them or run executable files using group policies (GPO).

We are going to restrict the use of USB-drives for all computers in a certain container (OU).

After the updates are installed, the PCs are restarted automatically (having notified the user in 5 minutes). To let the computers in the company have all available patches installed, both policies can be configured so that the update service (wuauserv) is forced to start on the client.