On the first image you can see the computer groups created on the main site (the upstream WSUS server), and on the second one those groups were synchronized on the replica servers.
If you go to the main office WSUS, which is our upstream server, and click the Downstream Servers object, you can see all downstream WSUS servers and in which mode they are running.
After the installation is done the WSUS Service Configuration Wizard should pop-up.
When you get to the Choose Upstream Server page select the second option Synchronize from another Windows Server Updates Services server, then type the WSUS server name from the main site in the Server name box.
In case you want to use SSL, first you need to configure the upstream WSUS server for SSL, than come back here and continue the wizard by checking the Use SSL while synchronizing update information box.
If you don’t want your downstream replica servers to download updates from an upstream WSUS server, and download them from Microsoft, leave the first option enabled and just check the box This is a replica of the upstream server.
However for this lab I will choose to use and upstream WSUS server to download updates from.
To configure this WSUS server with the upstream server (WSUS from HQ) click the Start Connecting button.
Once you approve the required updates, they will be downloaded locally on the WSUS server (if set so).This is also done from the upstream server, and after synchronization, the groups will appear on the replica servers. those groups will be present on all the WSUS servers, but this is just the way it works.Go ahead and create your computer groups, then let the synchronization do its magic.This is great, but in those branch offices there is no administrator you can delegate to maintain the WSUS servers, approve updates, take care of the client errors that might pop-up or don’t update.If this is the case, the best option is deploy WSUS downstream replica servers because they inherit all the settings and approved updates from a main WSUS server; which can be the WSUS server from the main site.