Microsoft’s recommendation is to have your roaming clients get their updates from an internet facing WSUS server if they normally do not connect to your network. If you have users who are about to depart for an extended period of time, it may be beneficial to have an alternate GPO that changes the WSUS server they are using from the internal WSUS server to one facing the internet in your DMZ. Just make sure they have an opportunity to get the changed GPO before departing. When they return, remove the alternate GPO and let the primary location take over.
http://technet.microsoft.com/en-us/library/cc720525(WS.10).aspx
Comments