Export (0) Print
Expand All

WSUS: WSUS should be installed on a non-domain controller

Published: April 27, 2010

Updated: July 19, 2011

Applies To: Windows Server 2003 with SP2, Windows Server 2008 R2, Windows Server 2008 R2 with SP1, Windows Server 2012, Windows Server Update Services, Windows Small Business Server 2011 Standard

This topic is intended to address a specific issue identified by a Best Practices Analyzer scan. You should apply the information in this topic only to computers that have had the Windows Server Update Services (WSUS) Best Practices Analyzer run against them and are experiencing the issue addressed by this topic. For more information about Best Practices Analyzer and scans, see Best Practices Analyzer on Microsoft TechNet.


Operating System

Windows Server® 2008 R2, Windows Server 2012


Windows Server Update Services 3.0 SP2 (WSUS 3.0 SP2)





WSUS is installed on a domain controller.

If WSUS is installed a domain controller, this will cause database access issues due to how the database is configured.

Installing WSUS on a domain controller can also cause problems upgrading or installing WSUS in the future.

Uninstall WSUS from the domain controller, demote the server to a non-domain controller, and reinstall WSUS.

Alternately, you can install WSUS on a different non-domain controller machine.

For detailed instructions about how to remove WSUS 3.0 SP2, see the Removal section in the Microsoft Support Article 972455: Description of Windows Server Update Services 3.0 Service Pack 2.

Was this page helpful?
(1500 characters remaining)
Thank you for your feedback

Community Additions

© 2015 Microsoft