Sus works great, a real time saver....
When you setup SUS, create a group in "active directory users and computers", "users" with a name such as "SUS group", add all workstations as member(not servers); unless you trust Microsoft, I prefer to update servers manually. Create an OU such as "SUS Machines", add the group "SUS group" to the OU. Edit the group policy of the OU "SUS machines" for the SUS settings. Make sure you apply the policy to disable automatically reboot. One of the policies is to choose the time the patches are applied to the involved machine, I general have it occur at 4:00 pm, at most clients.. pick the least network activity period of the day.