Bemrosesteve Posted April 25, 2016 Posted April 25, 2016 (edited) We have windows 10 installed on around 150 computers in the school since this time our internet speeds have been really low we have found out about windows 10 delivery options and turned this off through group policy but still getting high bandwidth usage from windows 10 computers on the network. It is like we have not made any changes to the system to how windows 10 gets updates but we have. We use a wsus server for our updates and updates appear as managed by your system administrator on the windows 10 pcs BUT smoothwall shows the traffic as high from windows updates on the windows 10 machine. Any ideas?? Edited April 25, 2016 by Bemrosesteve
KevSmith97 Posted September 12, 2016 Posted September 12, 2016 We are suffering with exactly the same issue..... Anyone got any ideas?
AdamK Posted September 13, 2016 Posted September 13, 2016 Hi, I'm experiencing the same problem. I have managed to half the bandwidth usage over the past day by monitoring the proxy and finding which sites the data is being pulled from then researching based on that. I have so far found that disabling spotlight makes a big difference. From the looks of things spotlight is trying to download content but due to lockdown restrictions is unable to save or install the content, so it therefore tries again. Only problem is that some of the content seems to be rather large. Multiply that by how ever many computers are trying to do the same thing and you end up with very crap internet... In group policy, go to User Configuration -> Administrative Templates -> Windows Components -> Cloud Content Set Configure Windows Spotlight on Lock Screen to Disabled Set Do not suggest third-part content in Windows spotlight to enabled Set Turn off all Windows spotlight features to enabled I also disabled the lock screen too through Computer Configuration -> Administrative Templates -> Control Panel -> Personalization -> Do not display the lock screen If anyone else has been able to resolve this completely, I'd love to know what you did. Since doing the above, we are getting a load of traffic to the following addresses: microsoftaik.azure.net h6.msn.com store-images.s-microsoft.com store-images.microsoft.com
lmrogers Posted September 13, 2016 Posted September 13, 2016 Looking at traffic reports on my system the majority of traffic is to h6.msn.com too.
KevSmith97 Posted September 13, 2016 Posted September 13, 2016 I have done similar with the sites you suggest. We have a smoothwall here, so I have set Bandwidth limits on those particular sites for the time being. If that doesn't solve it, then I will block access entirely.
lmrogers Posted September 13, 2016 Posted September 13, 2016 I have just added h6.msn.com to our deny list and am going to see if that makes any difference.
Michael Posted September 13, 2016 Posted September 13, 2016 This article addresses all, so it should be relatively easy to control. I can't get my head around why Microsoft thinks any Enterprise would want this switched on by default!? 1
AdamK Posted September 13, 2016 Posted September 13, 2016 The above article only resolves half of the problem. Spotlight doesn't seem to be connecting to the following sites: microsoftaik.azure.net h6.msn.com store-images.s-microsoft.com store-images.microsoft.com
Michael Posted September 13, 2016 Posted September 13, 2016 Just a thought, is there a Windows Spotlight service or words to that effect? Haven't got a 1607 workstation to hand. If there is, you could easily disable it via GPO.
Michael Posted September 13, 2016 Posted September 13, 2016 Also (out of curiosity) are you people enabling these policies afterwards or before the device(s) were commissioned to the domain?
AdamK Posted September 13, 2016 Posted September 13, 2016 I couldn't see any service related to Spotlight, but I'm pretty sure I've disabled spotlight and that another service is now causing the high bandwidth... The policies are pushed out via group policy, so are therefore applied after being added to the domain and moved to the correct container.
lmrogers Posted September 14, 2016 Posted September 14, 2016 Just a thought, could the high bandwidth usage be because of the live tiles on the start menu? Because surely they would go out to a Microsoft server, possible the h6.msn.com domain to update things like the news. Might be worth enabling the policy to turn off tile notifications and see if that makes a difference.
AdamK Posted September 14, 2016 Posted September 14, 2016 HI, I've added them policies in now and will see how it goes. I've also found this article on the Microsoft website, so I've gone through applying some of the policies mentioned in that: https://technet.microsoft.com/en-gb/itpro/windows/manage/manage-connections-from-windows-operating-system-components-to-microsoft-services
never-ending-troubles Posted September 14, 2016 Posted September 14, 2016 I've had this problem last yr, the only way I found to reduce traffic was to install WSUS, all bandwidth limiting/blocking lead to other issues, office becoming unresponsive, app crashing.
AdamK Posted September 14, 2016 Posted September 14, 2016 We've set group policy to set updates to be manually downloaded and installed by an administrator. The traffic logs don't show continuous connections to windows update. We tested this by updating a machine to see what address it connects to and it's definitely not the addresses that are swamping the network.
m25man Posted September 14, 2016 Posted September 14, 2016 (edited) Your problem is WUDO. Whilst the concept is good Microsoft have once again let loose a half baked idea with no proper way of controlling it. Win 10 is ignoring WUS and the policies meant to control WUDO are flawed. Even though the policy elements are available to manage it they don't work as expected and your internet connections will be gridlocked as a result. As a result it appears that 1607 is now being propagated through what is in effect an MS incarnation of BitTorrent (P2P) and if you've not tamed this service on your lan or even worse on your guest networks you've got fun and games ahead. I will let you work the rest out for yourselves, as I have to make a living there's only so much we can give away for free. Had to fix this at 3 sites so far this week who's networks had ground to a standstill. This thread from last week is relevant , Windows 10 WSUS Not applying http://www.edugeek.net/showthread.php?t=174100 Edited September 14, 2016 by m25man
AdamK Posted September 14, 2016 Posted September 14, 2016 I actually disabled WUDO the other day and although it made a difference, it didn't completely resolve the issue as it's not the only service that likes to automatically update in the background. I think I have finally resolved the issue but I'm giving it 24 hours to make sure. I have however seen all activity to h6.msn.com disappear and speed tests went from 0.5 Mbs to 90Mbs. Don't worry though guys, I'm not here to make a living from my fellow colleagues. I'll let you guys know what I've discovered tomorrow or Friday.
AdamK Posted September 14, 2016 Posted September 14, 2016 Your problem is WUDO. I will let you work the rest out for yourselves, as I have to make a living there's only so much we can give away for free. Had to fix this at 3 sites so far this week who's networks had ground to a standstill. This thread from last week is relevant , Windows 10 WSUS Not applying Windows 10 WSUS Not applying Just noticed the edit where you added the relevant post that I'm assuming helped point you in the right direction to fixing the 3 sites you had problems at this week. So, am I right in assuming you are happy to use information from this community to help make you a living, but unwilling to share vital information with this community that might completely solve someones problem? 1
AdamK Posted September 16, 2016 Posted September 16, 2016 Hi All, I’ve not quite figured out which settings completely resolved the problem in the end but I am reluctant to start taking settings out at the moment. To begin with, most of the traffic we saw was going to the following two addresses: Sci1-1.am.microsoft.com Sci2-1.am.microsoft.com This pretty much disappeared after disabling Spotlight and the lock screen. This took our traffic down to pretty much half. After that, we started seeing a lot of traffic to h6.msn.com. I think enabling the “Restrict Internet communication” setting or enabling the Map policies below killed traffic to that site. Here is a pretty graph: Here are the policies I applied. Computer Configuration Administrative Templates Control Panel/Personalization Do not display the lock screen – Enabled Windows Components/Maps Turn off Automatic Download and Update of Map Data – Enabled Turn off unsolicited network traffic on the Offline Maps settings page – Enabled Windows Components/Store Disable all apps from Windows Store – Enabled Turn off Automatic Download and Install of updates – Enabled Turn off the offer to update to the latest version of Windows – Enabled Turn off the Store application – Enabled User Configuration Administrative Templates One Drive (I downloaded an ADMX for One Drive for Business) Configure machine to receive updates after consumer production – Disabled Start Menu and Taskbar/Notifications Turn off notifications network usage – Enabled Turn off tile notifications – Enabled System/Internet Communication Management Restrict Internet communication – Enabled (This automatically enables the settings in Internet Communication settings) System/Internet Communication Management/Internet Communication settings Turn off access to the Store – Enabled Turn off downloading of print drivers over HTTP – Enabled Turn off handwriting personalization data sharing – Enabled Turn off handwriting recognition error reporting – Enabled Turn off Help Experience Improvement Program – Enabled Turn off Help Ratings – Enabled Turn off Internet download for Web publishing and online ordering wizards – Enabled Turn off Internet File Association service – Enabled Turn off printing over HTTP – Enabled Turn off the "Order Prints" picture task – Enabled Turn off the "Publish to Web" task for files and folders – Enabled Turn off the Windows Messenger Customer Experience Improvement Program – Enabled Turn off Windows Movie Maker automatic codec downloads – Enabled Turn off Windows Movie Maker online Web links – Enabled Turn off Windows Movie Maker saving to online video hosting provider – Enabled Turn off Windows Online – Enabled Windows Components/Cloud Content (Disabling Spotlight made a big difference) Configure Windows spotlight on lock screen – Disabled Do not suggest third-party content in Windows spotlight – Enabled Turn off all Windows spotlight features – Enabled Windows Components/Store Turn off the offer to update to the latest version of Windows – Enabled Turn off the Store application – Enabled I've also noticed that Windows 10 doesn't always apply the policies properly and I've had to manually do a gpupdate on several computers a couple times for them to kick in. Once the last few policies started to kick in I did notice the traffic to h6.msn.com go down quite a bit. I hope this helps you guys. Regards, Adam 1
m25man Posted September 16, 2016 Posted September 16, 2016 URLs to block are: sci1-1.am.microsoft.com sci1-2.am.microsoft.com sci2-1.am.microsoft.com sci2-2.am.microsoft.com
ITJS2015 Posted September 19, 2016 Posted September 19, 2016 Do you go through proxy ? We had problems loading webpages within windows 10 and downloading windows updates as it uses a system proxy to get round this open administrator command prompt type in netsh winhttp set proxy 12.34.56.78:port
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now