Jump to content

Recommended Posts

Posted

https://www.ghacks.net/2018/03/08/report-forced-windows-10-version-1709-upgrades-that-bypass-windows-update

 

 

Reports are coming in that Windows 10 systems running an earlier feature version of the operating system are upgraded to Windows 10 version 1709 forcefully in some circumstances.

 

The issue seems to be related to KB4023814, "Some versions of Windows 10 display a notification to install the latest version", which Microsoft updated on March 5, 2018 the last time.

 

It informs customers that notifications may be displayed on devices that run older versions of Windows 10 that state that the devices need to be updated to "have the latest security updates installed".

 

If you're currently running Windows 10 Version 1507, Version 1511, Version 1607 or Version 1703, you can expect to receive a notification that states that your device has to have the latest security updates installed. Windows Update will then try to update your device.

 

Microsoft reveals furthermore that only the latest version of Windows 10 offers protection from the latest threats.

 

Windows 10 version 1607 and version 1703 are not yet at "end of service." However, they must be updated to the latest versions of Windows 10 to ensure protection from the latest security threats.

 

It is unclear what Microsoft means by that. Won't it provide (some) security updates for Windows 10 version 1607 or 1703 despite the fact that these versions are still supported? Or is it merely a reminder that Windows 10 version 1709 includes additional protective features that previous versions don't include?

 

The former would invalidate Microsoft supporting any version of Windows 10 for 18 months while the latter would pose the question why Microsoft enforces upgrades to the new version of Windows 10.

 

Windows 10 version 1607 reaches end of support in April 2018, Windows 10 version 1703 in October 2018.

 

 

The reports indicate that Microsoft ignores user update settings and even installs the update on devices on which Windows Update is turned off.

 

If Windows Update is turned off, Microsoft uses the Update Assistant to deliver the update.

Posted
we are on 1709 all round but have left a couple of laptops out of the WSUS 1709 update group as we were curious as to what would actually happen to the 1607's
Posted
If you have the Do not connect to Internet Locations GPO setting enable. PCs won't get upgraded. But the store in broken. If you don't have it defined or disabled and don't have a WSUS server set they can upgrade. One be honest I'd get GPOS etc ready when 1803 is ready and start testing. If a few get updated via Windows Update its actually saving you a job.
  • 2 weeks later...
Posted (edited)

I have been experiencing this over the past couple of days. We have some old laptops that we need to get running and I'm installing Windows 10 1607 on them (1703 and 1709 won't work due to hardware/driver limitations). So I deployed 1607 via SCCM and MDT and it installs fine. It logs me into the local account and then BAM, there's the upgrade assistant starting to download updates. There is no option to stop or postpone/delay the process, it just does.

 

We manage Windows Updates with SCCM's SUP and have the relevant GPOs configured. I did a little bit of Googling on this and it appears that the important policy to have enabled is:

 

Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Update: Do not connect to any Windows Update Internet locations > Enabled.

 

Now, here's my problem. When we deploy Windows, one of the steps joins it to the domain and plops the machine in a resting OU called 'Deployment'. This OU doesn't have any GPOs applied to it as the idea is that the machines are then manually moved to the correct location.

 

My idea is to find the registry setting that the above GPO changess and put that in the TS.

 

What a ballache.

 

Edit: I think the registry entry is:

Location: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate

Name: DoNotConnectToWindowsUpdateInternetLocations

Type: DWORD

Value: 1

 

I will add that into my TS and see how it goes.

 

Edit 2:

With this step added, Windows did not start upgrading to a newer version. All good!

Edited by CHiLL
  • Thanks 1
Posted
I've just applied this GPO to one of my PC's. I can see that it has created the regkey (as above) fine, but if I manually press the "check for updates" it is still checking for them. Is this right does anyone know?
Posted (edited)

We block all access to the windows update servers except our update servers at the firewall. If we need to go out to them we can add client ip addresses to the firewall on a case by case basis.

 

We do this because GPO’s take time to apply and when we were imaging on mass in the early days we found our connection was getting hammered.

Edited by gaz350b
Posted
I've been reading about this today and its to do with Windows Dual Scanning. I'm going to be doing some testing but there are some new GP's out to help rectify the issues and from 1709 you will be able to completely control updates again like you were able to windows 8 and before.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...