Gongalong Posted November 2, 2017 Posted November 2, 2017 Hi folks, We opened up a couple of our 1703 laptops today, ran Windows Update, and within the update screen appeared "Feature update to Windows 10, version 1709"! Without prompt it then started downloading and installing 1709. It does it in the background to begin with, but on the reboot then takes 10-20 minutes to process the update (obviously laptop speed dependent). These first two were done as domain admins, then we tried one with a domain user and it also did it. I did make a change in WSUS at the start of the week, just to add Service Packs and Update Rollups. I definitely didn't add "Feature Updates". Having searched WSUS there is no "feature update" listed, nor anything other than cumulative updates to "1709". Anyone else experiencing this? My main concern is that a user is going to unwittingly get the update, then be inconvenienced when it applies. Thanks
mavhc Posted November 2, 2017 Posted November 2, 2017 So no "Feature update to Windows 10" have been approved, and they're GPO'd to get updates from the server? Odd. 1
Gongalong Posted November 2, 2017 Author Posted November 2, 2017 Yes to both, assuming that the former would be in the WSUS "Feature Packs" category, which isn't enabled. 1
Gongalong Posted November 2, 2017 Author Posted November 2, 2017 Anyone know what the 1709 describes itself as in WSUS?
mavhc Posted November 2, 2017 Posted November 2, 2017 It's in the Upgrades section, if you create a WSUS update view of Upgrades that apply to "Windows 10" then you see them all 2
mavhc Posted November 2, 2017 Posted November 2, 2017 Feature update to Windows 10, version 1709, en-gb 2
Gongalong Posted November 2, 2017 Author Posted November 2, 2017 OK. Upgrades is definitely turned off in WSUS, and that update doesn't list anywhere either. A mystery... Hopefully staff aren't updated!
alfatec Posted November 2, 2017 Posted November 2, 2017 There is a group policy setting in Computer Configuration, Admin Templates, Windows Components, Windows updates. 'Do not connect to any Windows Update Internet locations'. Enable this as we noticed that Windows 10 checks internet updates even though it is getting it from WSUS. 4
computer_expert Posted November 2, 2017 Posted November 2, 2017 Windows 10 1607+ can dual scan windows update and WSUS servers - make sure you don't have any of the windows update for business settings set in GPO (I think they are in Windows COmponents > windows updates > defer windows update folder, not 100% sure on exact location but I think it is this section) https://blogs.technet.microsoft.com/wsus/2017/08/04/improving-dual-scan-on-1607/ 2
Gongalong Posted November 3, 2017 Author Posted November 3, 2017 Yep, that's the correct location. There are two items under there: "Select when Feature Updates are received" and "Select when Quality Updates are received".
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now