
Computers Continue to Use an Existing WSUS Server
If Configuration Manager 2007 clients continue to download software updates from an existing WSUS server rather than install them using Configuration Manager, examine the resultant set of policies for the clients using a tool such as the Resultant Set of Policy (RSoP) or the Microsoft Group Policy Management Console (GPMC).
If these clients have an Active Directory Group Policy object assigned to them that specifies a WSUS server that is not their active software update point (using the correct name format and port), it will override the local Group Policy setting configured by the Configuration Manager software updates feature.
The Group Policy setting used is Specify intranet Microsoft update service location and it is located in Computer Configuration / Administrative Templates / Windows Components / Windows Update.
When an Active Directory Group Policy setting overrides the local Group Policy setting, the following entries appear in the software updates log file WUAHandler.log:
[Group policy settings were overwritten by a higher authority (Domain Controller) to: Server http://server and Policy ENABLED]LOG
Solution
Reconfigure Active Directory Group Policy such that Configuration Manager clients are not assigned an Active Directory Group Policy object that specifies a WSUS server other than their active software update point. For example, reconfigure the Active Directory Group Policy setting to Not Configured, or move computers to an organizational unit (OU) that does not have this Group Policy setting applied.