Do I really need WSUS and if I disable WSUS will the workstation automatically pickup windows updates?

Do I really need WSUS?

No. You can configure computers to pull updates directly from Microsoft, in which case you will not need WSUS.

Any easy instruction to disable WSUS?

  1. Remove the WSUS Server role (in Server Manager)
  2. Check C:\WSUS\ for leftover content/packages, and delete if needed. Leave the database folders intact to avoid SQL issues.
  3. This may leave metadata/database files behind, but those are usually relatively small.

Will the 6 workstations automatically go out to get Windows updates after I disable WSUS?

Generally, no. Clients (including the Windows Update client on the server itself) are configured to use a given WSUS server by Group Policy Object (GPO). The GPO(s) will need to be modified.

  1. Open GPMC (Group Policy Management Console)
  2. Check/edit the appropriate GPO(s)
  3. Computer Policies -> Administrative Templates -> Windows Components -> Windows Update
  4. Change the "Set the intranet ..." items (there are two) to Unconfigured
  5. If desired, adjust other items, such as update install schedule/frequency

Be sure to follow-up and check workstations, and make sure they are properly getting updates. Continue checking periodically. Falling behind on updates often leads to security compromise (virus, worm, ransomware, etc.).

References:

  • https://blogs.technet.microsoft.com/sbs/2009/09/23/how-to-move-wsus-content-and-database-files-to-a-different-volume/
  • https://slice2.com/2016/11/11/howto-delete-the-wsus-wid-on-windows-2012r2/