When Forefront Ignores BITS settings for WSUS Updates
For those who like to keep their network links from hitting 100% utilization need to keep the following in mind:
Forefront clients normal run in background mode for updates from a WSUS server, so it will use the BITS settings, which you hopefully have applied by a GPO to all your machines. Background Mode , using BITS, is a slow, controlled, steady stream of data.
That is unless you do the following which puts Forefront/WSUS into Foreground Mode.
Foreground Mode uses all available bandwidth to download the updates.
1) Hitting the Scan Now button in the Forefront Console
2) Hitting the check for Updates button in the Forefront Client
3) Selecting Check for Updates before Scanning in the Forefront Console GPO setting
Why is this bad?
Forefront clients normally download a delta file which is between 500kb and 1 Mb. This keeps the definitions up to date. However, once the definitions get out of date, which is anything up to two to three weeks old, the Forefront client will download the entire definition file of 30MB
Across a LAN , who cares? But across the WAN? Planning your WSUS and OU infrastructure with GPO policy and placement suddenly becomes a lot more important, especially if you have a large fleet of laptops at remote sites with poor bandwidth.

Leave a Reply