Jump to content

Recommended Posts

Posted

Hello,

Our 8.1 devices build in MDT with 3 passes of updates so imagine my surprise when they asked for 160 updates when completed. I injected every spare update I could get from WSUS-Offline and now that number has gone down to 80. Looking into it further I noticed all the updates the laptop is trying to install are non critical or not security based so believe it must be talking to Windows Update directly.

 

I have set the "specify intranet Microsoft update service location" correctly (we have been using the same one for years) but apart from the other settings like telling it to delay restarts etc... there is not much else set. Is there anything I am missing in group policy to insist it does not talk to anything other than WSUS onsite?

 

Thank you

Posted

Are the windows update steps before or after the domain join (recover from domain) step in the MDT task sequence?

 

If they are before, then the machine will reach out to MS (unless you have configured the WSUS settings in MDT's customsettings.ini). If it is after the join step, is the 'do not connect to any windows update internet locations' GPO setting enabled in your policy?

Posted
Also if it's doing windows update post-domain it would be worth making sure there's a reboot in the TS before the update steps so that GPO has fully applied

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...