The head technichan has an MCSE and he doesnt know how to do it?
That's pretty sad.

The DC isnt the on the same server which the WSUS is on
We have the exact same setup here. We have a DC & an App server (where WSUS runs).

Will this now edit all the workstations GP's when they log in?
So long as you edited the Group Policy on the DC, all the workstations will universally apply those settings.

I have a couple questions. Is your WSUS server using SSL? If so, you'll need to create a certificate. Also, if you want to see if your workstations are applying Group Policy correctly, go to a workstation, start-> run->gpupdate

On the same workstation, go to the control panel, select Windows Updates and see if the selections on this machine match what you have on the DC & that the selections are now greyed out on the workstation.