Jump to content

Recommended Posts

Posted

We have a fleet of Surface pro 4's for staff.

 

We've noticed over the last few months Surfaces have updated themselves to 1709 (They should be on 1607) when away from the school network for a period of time.

 

First noticed this first with my Surface, i was off work for 2 weeks, in that time my surface was at home in my bag off. I got into work and it downloaded and installed 1709 itself, i didn't manually check for any updates.

 

Now after the Xmas break we've had several staff come in asking for bitlocker keys as their Surface has also updated to 1709.

 

Is there a policy in SCCM/WSUS that sets a time limit to check for updates directly from microsoft?

  • Thanks 1
Posted
Is there a policy in SCCM/WSUS that sets a time limit to check for updates directly from microsoft?

 

Unfortunately I don't think there's a policy available in GP or SCCM which can do that. Which version of Windows 10 is installed on the Surfaces? I could be completely wrong but I don't think that Education/Enterprise releases can get those kinds of upgrades via regular Windows Update, I remember trying to update Education when a new version was released to the general public but there was a 2 week delay getting the new ISO on to the VLSC. I tried to update via WU but nothing showed up so I tried to force it with the update tool and I got an error basically saying that the IT department would have to update it and there was nothing I could do, I think I may also have hit a brick wall downloading and manually running the update package.

 

With that said, it was a while ago and may have changed, 1709 didn't have the same delay :)

  • Thanks 1
Posted

Education 1607 is the default one for our Surfaces

 

I did check through GP settings for Windows Update and can't see anything that could cause this problem.

 

Had another one today that is on 1607 and is pending restart to install 1709 :( Yet to spot any problems with being on 1709 on our network which is a slight plus....

Posted

The only thing close to that which I've found in GP is:

 

Computer Config > Policies > Admin Templates > Windows Components > Windows Update > Windows Update for Business > Select when Preview Builds and Feature Updates are received

 

If you put it on Semi-Annual Channel that will delay the update for up to 4 months after release to general public but that's not going to be much use :(

Posted

Did you get any firther with this @DalekSec ?

 

I am presuming you wish to stop clients updating to the latest (greatest) version of Windows 10 and that is controlled by WSUS whilst laptops are on-site, but when taken off site/home, they check WU and download/install it anyway.

 

I am very interested in this (although I have decided to go LTSB) as I'm sure I will forget to check if a new version is released.

 

Anyway, if that IS what you are asking, most people here will be doing this somehow, as nobody wants an untested OS version update installing itself...

Posted
The only thing close to that which I've found in GP is:

 

Computer Config > Policies > Admin Templates > Windows Components > Windows Update > Windows Update for Business > Select when Preview Builds and Feature Updates are received

 

If you put it on Semi-Annual Channel that will delay the update for up to 4 months after release to general public but that's not going to be much use :(

 

Just spotted "Do not connect to any Windows Update Internet locations" but that can cause issues with the Windows Store which may or may not be a problem...

Posted (edited)
Did you get any firther with this @DalekSec ?

 

I am presuming you wish to stop clients updating to the latest (greatest) version of Windows 10 and that is controlled by WSUS whilst laptops are on-site, but when taken off site/home, they check WU and download/install it anyway.

 

I am very interested in this (although I have decided to go LTSB) as I'm sure I will forget to check if a new version is released.

 

Anyway, if that IS what you are asking, most people here will be doing this somehow, as nobody wants an untested OS version update installing itself...

 

I haven't got any further with it, been checking every group policy group, registry keys etc. etc. but nothing that is enabled to allow them to update themselves!

 

Just spotted "Do not connect to any Windows Update Internet locations" but that can cause issues with the Windows Store which may or may not be a problem...

 

The only GP enabled for windows update that i can find is 'Specify intranet microsoft update service location' which is pointing to our SCCM server and 'Do not allow update deferral policies to cause scans against windows update' which is enabled. Must be a setting somewhere that's causing it....

Edited by DalekSec
Posted (edited)

You must have got dual scan enabled. To fix this ensure that no WUfB policies are set. Indeed probably don't set any WU policies.

 

Then SCCM will handle everything (actually it will leverage the WUClient for parts of the work, but the WU Policy settings won't then get in the way)

 

 

If you set any WUfB settings then WUfB is enabled and the machine will dual scan and update according to those settings and be outside of full control of WSUS / SCCM.

 

https://blogs.technet.microsoft.com/windowsserver/2017/01/09/why-wsus-and-sccm-managed-clients-are-reaching-out-to-microsoft-online/ See scenario 2:

Ensure that the registry HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate doesn’t reflect any of these values.

 

DeferFeatureUpdate

DeferFeatureUpdatePeriodInDays

DeferQualityUpdate

DeferQualityUpdatePeriodInDays

PauseFeatureUpdate

PauseQualityUpdate

DeferUpgrade

ExcludeWUDriversInQualityUpdate

 

https://home.configmgrftw.com/windows-10-servicing-configmgr-confusion/ Covers additional sources of confusion gives some additional background and has some interesting posts in the comments from the SCCM team.

Edited by psydii
  • Thanks 1
Posted

Configure Automatic Updates: Disabled

Do not connect to any Windows Update Internet locations: Enabled

Specify intranet Microsoft update service location: Enabled

 

Are the three that should do it. If you're using SCCM no need for the Auto Updates either

 

Steve

  • Thanks 1
Posted
SCCM puts a local policy for Windows updates on machines. I assume it's the same for a Surface device. Thus you shouldn't push any GPO settings for Windows updates if you are using SCCM.
Posted

My understanding is that if you have no GPOs touching WSUS settings what so ever and you have SCCM clients then SCCM will locally manage the local policy of each machine such that you end up with a working config that is talking to the SCCM server for updates (see Picture)

 

sccm gpo.png

Posted
I'm glad I'm not the only one. Our sole Windows 10 Education 1607 updated itself to 1709 as we returned from the Christmas break. However, none of the 1511 or 1703 machines did!?!
Posted
My understanding is that if you have no GPOs touching WSUS settings what so ever and you have SCCM clients then SCCM will locally manage the local policy of each machine such that you end up with a working config that is talking to the SCCM server for updates (see Picture)

 

[ATTACH=CONFIG]47019[/ATTACH]

That's how it's setup :/

 

GP3.PNG

Posted
I'm glad I'm not the only one. Our sole Windows 10 Education 1607 updated itself to 1709 as we returned from the Christmas break. However, none of the 1511 or 1703 machines did!?!

 

Wooo i'm not going crazy!!!!!!

Posted

I caught a few of my laptops (1703) attempting to install the 1709 the other day, and nipped that in the bud, hopefully it hasn't hit anywhere else.

 

We're running our updates through WSUS, and the 1709 update is not in our WSUS, so I don't know how or why they've fetched it, presumably direct from Microsoft Windows update, bypassing my WSUS server.

 

I've just applied the "Do not connect to any Windows Update Internet Locations" policy mentioned above on top of having the other policies already set, hopefully that'll put pay to it. Need to find a way to survey our workstations and see if any 1709 has snuck in, trying an SCCM collection but it keeps falling over :rolleyes:

 

It's so frustrating, why do Microsoft (and it must be said, other vendors) insist on making it so hard to stop major updates from installing without approval! See also, the half a dozen different settings you need to use to stop drivers coming through Windows Update....

  • 2 weeks later...
Posted

Update for anyone still facing or is concerned about this problem....

 

I've just spent the last day or so trying to work out why, again, our clients were going to Windows Update as well as our WSUS server for updates, despite our policies telling it not to. As mentioned by @psydii, this was Dual Scan. Dual Scan is a fun little feature that MS introduced without asking where, under some configs, Windows Update client by design checks both online and local WSUS for updates.

 

Anyway, a good potted summary of Dual Scan and how to combat it here - https://batchpatch.com/dual-scan-difficulties-with-windows-update-on-windows-10-versions-1607-anniversary-update-and-1703-creators-update and also here https://blogs.technet.microsoft.com/ausoemteam/2017/08/07/updates-to-wsuswu-dual-scan-on-windows-10-1607/.

 

It's worth noting, as well as the two WUfB settings mentioned causing Dual Scan to enable, the setting "Do not include drivers with Windows Updates" has also been cited as a culprit.

 

The good news is however, if you update your Admin Templates to the latest, you should get a new Windows Update setting "Do not allow update deferral policies to cause scans against Windows Update" that should turn Dual Scan off, dead. I'm not 100% convinced it works, but definitely worth enabling.

 

Another wonderful "feature" from Microsoft that no-one asked for, and does the opposite of what most people want!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...