I primarily work in a disconnected environment so I cannot configure
WSUS CM as the majority of you do. I currently have no settings defined for Windows Update in GP. As there's no internet to reach out to I'm not concerned with that aspect and no matter how many times someone clicks "Check for updates" it will always say there are no updates at this time because the WSUS doesn't serve updates in a CM environment. The CM client however will set local policy and at a minimum defines these:
- Specify intranet Microsoft update service location: Enabled (should be setting it to your SUP)
- Do not allow update deferral policies to cause scans against Windows Update: Enabled
- Allow signed updates from an intranet Microsoft update service location: Enabled
It's explicitly stated to not set the first item listed above in GP, it will cause CM to stop serving updates to your systems if you do. You should keep in mind if you converted your WSUS to a SUP it's CM that serves the updates not WSUS. I would recommend using a new clean WSUS as your SUP rather than bring in a pre-configured one that was standalone. Setting other items via GPO probably won't have any affect on CM because for CM's purposes the WUA is only doing the initial "Hi, here's what I am, what I have, what do you have for me?" conversation. More on that later...
Preventing people from accessing Microsoft's Windows Update Server through GPO only stops them from firing it off through that UI, you said they're all admins. What's to stop them from manually browsing the Update Catalog, downloading whatever they like, and executing it? Perhaps a network ACL or IPSec Policy would assist on this. I'm getting off-track though...
Your Automatic Deployment Rule (ADR) should be enabled, with a last error code of 0x0, and deployed to a collection that contains eligible systems.
The ADR should be linked to a deployment package that contains the updates and that package should have it's content distributed to a Distribution Point (DP).
A Software Update Group (SUG) should also contain the deployment information in addition to other stats, it should be enabled.
When a CM managed system runs the Software Updates Scan Cycle it will directly communicate with your SUP and carry on a normal WUA conversation but the SUP won't send it anything directly. After this completes information about that system will be updated in the SUG... somehow.. by either the client or through MP <-> SUP conversations.. I don't really have this part nailed down and never get around to looking into it.
When the system runs the Software Updates Deployment Evaluation Cycle it will evaluate any SUG's deployed to it and pull down updates from the DP as required.