WSUS Updates on 2012/2016 with Lockdown


we have installed last week the Lockdown for our windows 2012 & 2016 server.

Now we can't installed any updates from our WSUS Server like Defender Updates.

What exactly we need to do that Updates from WSUS are allowed?

Many thank's


  • Of Course i could be a design Problem by MS but a note in the documentation of Sophos whoud be very good in that case because a DC is a very sensitive system.

    With Roles i meen evething what a DC can have like DHCP, DNS, ADDS ect. after update of MS-Patch all that didn't come up!