Jump to content

Anniversary Edition on Domain machine automatically... how?!


Recommended Posts

Posted

Hi,

 

So I logged into a machine for an unrelated reason and noticed it had the 'Anniversary Edition' update applied. I haven't deployed this using SCCM and it seems to be the only one thus far. Is there any way of me finding out how exactly this has occurred? maybe in the event log?

 

I didn't think it would apply automatically.

Posted (edited)

Is the machine getting updates directly from windows update?

 

Unless it goes direct or you approve in sccm I can't see how it would get it.

Edited by sparkeh
Posted
all versions of 10 will upgrade on release except for The long term service branch.

Not true. Depends on where the machine is set to get its updates from and whether it's Current Branch or Current Branch for Business.

Posted
In theory, it should only receive updates from SCCM and not Windows Update directly, no other machines have updated. Not entirely sure how I would check the source of the update?
Posted
In theory, it should only receive updates from SCCM and not Windows Update directly, no other machines have updated. Not entirely sure how I would check the source of the update?

Check on the machine whether the 'check for updates from Microsoft' box is ticked. I haven't looked extensively at this but on our machines it appears that users can tick this, need to look at how to disable that.

Posted

Do you have the GPO set to fully disable Windows Update?

 

Do you have WSUS inside SCCM set to download Windows 10 upgrades with auto approval?

 

The second one is what got me on a couple of machines. Although Windows Update was completely disabled, WSUS SCCM auto approved the upgrade and pushed it out to a few PCs.

 

If you are on the current branch of SCCM (1606) you can set a Windows 10 plan and specify how long PCs will wait until they auto upgrade. If at all.

Posted
...Although Windows Update was completely disabled, WSUS SCCM auto approved the upgrade and pushed it out to a few PCs.

 

If you are on the current branch of SCCM (1606) you can set a Windows 10 plan and specify how long PCs will wait until they auto upgrade. If at all.

 

We hadn't got around to building a service plan when 1607 was first released to SCCM - and found SCCM decided it was one of those updates we had allowed SCCM to auto-approve and deploy so had it not been for a swift bit of "remove this from the update package" intervention, we would have had the whole school trying to update itself to 1607.

 

Service plan created, but now won't deploy to our test machines. I have done something wrong... somewhere!

Posted
I have found it rather hit and miss. Especially on laptops that are taken off site. I have decided to kill of service plans for the moment. I am looking at custom WIMS for Windows 10 (Some modern apps removed, some reg tweaks to default profile, start layout built in, "Other User" text changed, cumulative updates slipstreamed) so the auto upgrade would break all of this. So I am completely disabling auto upgrade and will use custom upgrade task sequences so I can control it.
Posted
Do you have the GPO set to fully disable Windows Update?

 

Do you have WSUS inside SCCM set to download Windows 10 upgrades with auto approval?

 

The second one is what got me on a couple of machines. Although Windows Update was completely disabled, WSUS SCCM auto approved the upgrade and pushed it out to a few PCs.

 

If you are on the current branch of SCCM (1606) you can set a Windows 10 plan and specify how long PCs will wait until they auto upgrade. If at all.

 

I have found it rather hit and miss. Especially on laptops that are taken off site. I have decided to kill of service plans for the moment. I am looking at custom WIMS for Windows 10 (Some modern apps removed, some reg tweaks to default profile, start layout built in, "Other User" text changed, cumulative updates slipstreamed) so the auto upgrade would break all of this. So I am completely disabling auto upgrade and will use custom upgrade task sequences so I can control it.

 

Perhaps I am misunderstanding, but if you are using wsus\sccm to update, just don't sync the 'upgrades' category and you won't get v1607 coming down to you?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...