Suponho que você esteja implantando configurações usando a Política de Grupo? Nesse caso, acredito que esta página contém as informações que você procura:
Especificamente, a configuração:
Remove Links and Access to Windows Update
If this setting is enabled, Automatic Updates receives updates from the WSUS server. Users who have this policy set cannot get updates from a Windows Update Web site that you have not approved. If this policy is not enabled, the Windows Update icon remains on the Start menu for local administrators to visit the Windows Update Web site. Local administrative users can use it to install unapproved software from the public Windows Update Web site. This happens even if you have specified that Automatic Updates must get approved updates from your WSUS server.