The default settings in Windows Server allow user who are not an administrator to scan for and apply Windows Updates. Administrators may want to change this setting to limit access to Windows Updates, especially in Remote Desktop Services Host deployments.
To change this setting, use the Group Policy "Remove access to use all Windows update features." The full path to this Group Policy is:
Computer Configuration\Administrative Templates\Windows Components\Windows update\Remove access to use all Windows update features