I'm no security expert, so I pose this question to all of you.
It seems to work well to have a self service item that runs
/System/Library/CoreServices/Software Update.app/Contents/MacOS/Software
Update. This just brings up the GUI softwareupdate.app. Since it's running
from self service, it runs as admin/root, which therefore does not require
admin credentials to install updates. This works for all users, admin or
not. We control the updates available though SUS and therefore control what
they can get.
Is this an acceptable and secure solution to software updates?
