Then just tell the clients not to download from any of the DP's. Leave the box checked to go to MS. Im assuming then you have M/S split tunneled in your VPN environment, otherwise they will go through your concentrators to get the updates "directly from MS. Which will be twice the load on your network. Remember, unlike apps and packages, updates will immediately start downloading and wait to deploy. (apps & packages wont download until the deadline or user starts it). At least that is the way it was. Even if you didnt make the update available right away)