How to exclude a computer from the wsus gpo?

Hello, Gentlemen!
Immediately I confess that in group policies I am a layman, therefore ask for a detailed explanation.
The problem: I need several computers with Windows 10 have received the updates from WSUS not from the local network, and directly from Windows Update. How to do it?
Through group policy, ALL computers on the network receive the address of the local WSUS server.
Please explain how to exclude from Group Policy to the desired computers?
If you can, step by step and in detail, or give a link to the article.
You need to exclude multiple computers!
Thanks in advance!
March 23rd 20 at 19:19
2 answers
March 23rd 20 at 19:21
Domain group policy linked to an OU, so you need to go to Active Directory Users and computers to move the computers to another OU to which the policy action applies to. To view the configurations of policies (including a reference to the OU) is possible through the snap-in "group policy Management".
March 23rd 20 at 19:23
Choose the policy that is responsible for WSUS. The Delegation tab, then the bottom right "Advanced". You will open the "Security" tab. It added the desired user (or PC), select it and tick "Deny apply policy"


Find more questions by tags Windows ServerGroup policy