robjduk Posted October 9, 2015 Posted October 9, 2015 Hello, Our 8.1 devices build in MDT with 3 passes of updates so imagine my surprise when they asked for 160 updates when completed. I injected every spare update I could get from WSUS-Offline and now that number has gone down to 80. Looking into it further I noticed all the updates the laptop is trying to install are non critical or not security based so believe it must be talking to Windows Update directly. I have set the "specify intranet Microsoft update service location" correctly (we have been using the same one for years) but apart from the other settings like telling it to delay restarts etc... there is not much else set. Is there anything I am missing in group policy to insist it does not talk to anything other than WSUS onsite? Thank you
computer_expert Posted October 9, 2015 Posted October 9, 2015 Are the windows update steps before or after the domain join (recover from domain) step in the MDT task sequence? If they are before, then the machine will reach out to MS (unless you have configured the WSUS settings in MDT's customsettings.ini). If it is after the join step, is the 'do not connect to any windows update internet locations' GPO setting enabled in your policy?
Homer Posted October 10, 2015 Posted October 10, 2015 Also if it's doing windows update post-domain it would be worth making sure there's a reboot in the TS before the update steps so that GPO has fully applied
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now