DalekSec Posted January 8, 2018 Posted January 8, 2018 We have a fleet of Surface pro 4's for staff. We've noticed over the last few months Surfaces have updated themselves to 1709 (They should be on 1607) when away from the school network for a period of time. First noticed this first with my Surface, i was off work for 2 weeks, in that time my surface was at home in my bag off. I got into work and it downloaded and installed 1709 itself, i didn't manually check for any updates. Now after the Xmas break we've had several staff come in asking for bitlocker keys as their Surface has also updated to 1709. Is there a policy in SCCM/WSUS that sets a time limit to check for updates directly from microsoft? 1
JamboD Posted January 9, 2018 Posted January 9, 2018 Is there a policy in SCCM/WSUS that sets a time limit to check for updates directly from microsoft? Unfortunately I don't think there's a policy available in GP or SCCM which can do that. Which version of Windows 10 is installed on the Surfaces? I could be completely wrong but I don't think that Education/Enterprise releases can get those kinds of upgrades via regular Windows Update, I remember trying to update Education when a new version was released to the general public but there was a 2 week delay getting the new ISO on to the VLSC. I tried to update via WU but nothing showed up so I tried to force it with the update tool and I got an error basically saying that the IT department would have to update it and there was nothing I could do, I think I may also have hit a brick wall downloading and manually running the update package. With that said, it was a while ago and may have changed, 1709 didn't have the same delay 1
DalekSec Posted January 9, 2018 Author Posted January 9, 2018 Education 1607 is the default one for our Surfaces I did check through GP settings for Windows Update and can't see anything that could cause this problem. Had another one today that is on 1607 and is pending restart to install 1709 Yet to spot any problems with being on 1709 on our network which is a slight plus....
JamboD Posted January 9, 2018 Posted January 9, 2018 The only thing close to that which I've found in GP is: Computer Config > Policies > Admin Templates > Windows Components > Windows Update > Windows Update for Business > Select when Preview Builds and Feature Updates are received If you put it on Semi-Annual Channel that will delay the update for up to 4 months after release to general public but that's not going to be much use
Koldov Posted January 9, 2018 Posted January 9, 2018 Did you get any firther with this @DalekSec ? I am presuming you wish to stop clients updating to the latest (greatest) version of Windows 10 and that is controlled by WSUS whilst laptops are on-site, but when taken off site/home, they check WU and download/install it anyway. I am very interested in this (although I have decided to go LTSB) as I'm sure I will forget to check if a new version is released. Anyway, if that IS what you are asking, most people here will be doing this somehow, as nobody wants an untested OS version update installing itself...
JamboD Posted January 9, 2018 Posted January 9, 2018 The only thing close to that which I've found in GP is: Computer Config > Policies > Admin Templates > Windows Components > Windows Update > Windows Update for Business > Select when Preview Builds and Feature Updates are received If you put it on Semi-Annual Channel that will delay the update for up to 4 months after release to general public but that's not going to be much use Just spotted "Do not connect to any Windows Update Internet locations" but that can cause issues with the Windows Store which may or may not be a problem...
DalekSec Posted January 9, 2018 Author Posted January 9, 2018 (edited) Did you get any firther with this @DalekSec ? I am presuming you wish to stop clients updating to the latest (greatest) version of Windows 10 and that is controlled by WSUS whilst laptops are on-site, but when taken off site/home, they check WU and download/install it anyway. I am very interested in this (although I have decided to go LTSB) as I'm sure I will forget to check if a new version is released. Anyway, if that IS what you are asking, most people here will be doing this somehow, as nobody wants an untested OS version update installing itself... I haven't got any further with it, been checking every group policy group, registry keys etc. etc. but nothing that is enabled to allow them to update themselves! Just spotted "Do not connect to any Windows Update Internet locations" but that can cause issues with the Windows Store which may or may not be a problem... The only GP enabled for windows update that i can find is 'Specify intranet microsoft update service location' which is pointing to our SCCM server and 'Do not allow update deferral policies to cause scans against windows update' which is enabled. Must be a setting somewhere that's causing it.... Edited January 9, 2018 by DalekSec
psydii Posted January 9, 2018 Posted January 9, 2018 (edited) You must have got dual scan enabled. To fix this ensure that no WUfB policies are set. Indeed probably don't set any WU policies. Then SCCM will handle everything (actually it will leverage the WUClient for parts of the work, but the WU Policy settings won't then get in the way) If you set any WUfB settings then WUfB is enabled and the machine will dual scan and update according to those settings and be outside of full control of WSUS / SCCM. https://blogs.technet.microsoft.com/windowsserver/2017/01/09/why-wsus-and-sccm-managed-clients-are-reaching-out-to-microsoft-online/ See scenario 2: Ensure that the registry HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate doesn’t reflect any of these values. DeferFeatureUpdate DeferFeatureUpdatePeriodInDays DeferQualityUpdate DeferQualityUpdatePeriodInDays PauseFeatureUpdate PauseQualityUpdate DeferUpgrade ExcludeWUDriversInQualityUpdate https://home.configmgrftw.com/windows-10-servicing-configmgr-confusion/ Covers additional sources of confusion gives some additional background and has some interesting posts in the comments from the SCCM team. Edited January 9, 2018 by psydii 1
DalekSec Posted January 9, 2018 Author Posted January 9, 2018 I can't see any of these settings having been set, unless i'm looking in the wrong place or doing something wrong!
Steve21 Posted January 9, 2018 Posted January 9, 2018 Configure Automatic Updates: Disabled Do not connect to any Windows Update Internet locations: Enabled Specify intranet Microsoft update service location: Enabled Are the three that should do it. If you're using SCCM no need for the Auto Updates either Steve 1
Geoff Posted January 9, 2018 Posted January 9, 2018 SCCM puts a local policy for Windows updates on machines. I assume it's the same for a Surface device. Thus you shouldn't push any GPO settings for Windows updates if you are using SCCM.
Steve21 Posted January 9, 2018 Posted January 9, 2018 That's not entirely true anymore, They changed that with Delivery Optimisation last year. https://blogs.technet.microsoft.com/windowsserver/2017/01/09/why-wsus-and-sccm-managed-clients-are-reaching-out-to-microsoft-online/ Steve
Geoff Posted January 9, 2018 Posted January 9, 2018 My understanding is that if you have no GPOs touching WSUS settings what so ever and you have SCCM clients then SCCM will locally manage the local policy of each machine such that you end up with a working config that is talking to the SCCM server for updates (see Picture)
jtotheb Posted January 9, 2018 Posted January 9, 2018 I'm glad I'm not the only one. Our sole Windows 10 Education 1607 updated itself to 1709 as we returned from the Christmas break. However, none of the 1511 or 1703 machines did!?!
DalekSec Posted January 9, 2018 Author Posted January 9, 2018 My understanding is that if you have no GPOs touching WSUS settings what so ever and you have SCCM clients then SCCM will locally manage the local policy of each machine such that you end up with a working config that is talking to the SCCM server for updates (see Picture) [ATTACH=CONFIG]47019[/ATTACH] That's how it's setup :/
DalekSec Posted January 9, 2018 Author Posted January 9, 2018 I'm glad I'm not the only one. Our sole Windows 10 Education 1607 updated itself to 1709 as we returned from the Christmas break. However, none of the 1511 or 1703 machines did!?! Wooo i'm not going crazy!!!!!!
DavR Posted January 12, 2018 Posted January 12, 2018 I caught a few of my laptops (1703) attempting to install the 1709 the other day, and nipped that in the bud, hopefully it hasn't hit anywhere else. We're running our updates through WSUS, and the 1709 update is not in our WSUS, so I don't know how or why they've fetched it, presumably direct from Microsoft Windows update, bypassing my WSUS server. I've just applied the "Do not connect to any Windows Update Internet Locations" policy mentioned above on top of having the other policies already set, hopefully that'll put pay to it. Need to find a way to survey our workstations and see if any 1709 has snuck in, trying an SCCM collection but it keeps falling over It's so frustrating, why do Microsoft (and it must be said, other vendors) insist on making it so hard to stop major updates from installing without approval! See also, the half a dozen different settings you need to use to stop drivers coming through Windows Update....
DavR Posted January 25, 2018 Posted January 25, 2018 Update for anyone still facing or is concerned about this problem.... I've just spent the last day or so trying to work out why, again, our clients were going to Windows Update as well as our WSUS server for updates, despite our policies telling it not to. As mentioned by @psydii, this was Dual Scan. Dual Scan is a fun little feature that MS introduced without asking where, under some configs, Windows Update client by design checks both online and local WSUS for updates. Anyway, a good potted summary of Dual Scan and how to combat it here - https://batchpatch.com/dual-scan-difficulties-with-windows-update-on-windows-10-versions-1607-anniversary-update-and-1703-creators-update and also here https://blogs.technet.microsoft.com/ausoemteam/2017/08/07/updates-to-wsuswu-dual-scan-on-windows-10-1607/. It's worth noting, as well as the two WUfB settings mentioned causing Dual Scan to enable, the setting "Do not include drivers with Windows Updates" has also been cited as a culprit. The good news is however, if you update your Admin Templates to the latest, you should get a new Windows Update setting "Do not allow update deferral policies to cause scans against Windows Update" that should turn Dual Scan off, dead. I'm not 100% convinced it works, but definitely worth enabling. Another wonderful "feature" from Microsoft that no-one asked for, and does the opposite of what most people want!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now