Jump to content

Recommended Posts

Posted

errr, I've seen two staff this morning with Windows 11 on their laptops! I asked how it happened and they said the laptop told them to....

 

How are non-admin users able to update an operating system?!!?!

 

How do I disable this! What GPO is there!

 

ffs Micro$oft

Posted

To me, it sounds to me like your Windows Update policies need tightening up, as devices in domain environments don't generally go directly through the Internet to get updates, they use WSUS/SCCM, etc. For example, we're using SCCM and it's configured so that updates point back to the SCCM server and cannot default/failover to the Internet if the server is unuavailable. Pressing check updates just brings an error message saying it can't contact the server. I haven't tried running the setup/upgrade program manually as a regular member of staff, but I don't think it'd work as a regular user. Although, I don't know if it actually needs admin permissions or not...so I might try that out at some point.

 

If it doesn't require elevated permissions and your update policies are correct - I can only assume that the users have clicked on an Edge/Bing banner/advert to upgrade, where it's downloaded the upgrade tool and they've followed the instructions.

Posted
Going to be honest, same as what @CHiLL said, it's not Microsoft's fault your Update policies aren't correct. Moment Windows 11 was announced I double/triple checked users weren't able to upgrade to it and the relevant settings were in places for us (in our case Intune)
  • Thanks 1
Posted

I have the policies configured! I don't allow driver updates (because firmware), I have a schedule and busy hours. I don't see an option to allow / disallow OS upgrade! if you need admin credentials to install a program why does an entire operating system not?!?

 

These are standard users, they can't install a printer or a program without credentials?!? but the OS. is it considered a rollup update or feature update?!

Posted
It's just Windows 10 22h1 really, so it's a feature update

 

Why don't you allow firmware updates?

 

Firmware updates have the laptop go to black screen a few times, power cycle and flash the keyboard. The potential for the end user to bork the bios through mis understanding during this process is high!

Posted
You need this policy set if you dont already. If you dont specify Windows 10 then users will be prompted to upgrade.

 

[ATTACH=CONFIG]65572[/ATTACH]

 

I don't have this option?! I assume I need some new ADMX files for the policy store, what ADMX files do I need?

Posted

Make sure you have the latest admx files https://www.microsoft.com/en-us/download/details.aspx?id=104042

 

Install locally and copy to your centralstore https://docs.microsoft.com/en-us/archive/blogs/canitpro/step-by-step-managing-windows-10-with-administrative-templates

 

Edit your WU gpo, Select The Target Feature Update Version, put in Windows 10 and 21H2 https://docs.microsoft.com/en-us/windows/release-health/supported-versions-windows-client

Posted
You need this policy set if you dont already. If you dont specify Windows 10 then users will be prompted to upgrade.

 

[ATTACH=CONFIG]65572[/ATTACH]

I didn't even know that was an option and I certainly don't have it set, yet our users aren't prompted to upgrade to a newer OS (which has been the same since we resdesigned the network back in 2015).

Posted
Firmware updates have the laptop go to black screen a few times, power cycle and flash the keyboard. The potential for the end user to bork the bios through mis understanding during this process is high!

 

How many times have they broken it?

Posted
I didn't even know that was an option and I certainly don't have it set, yet our users aren't prompted to upgrade to a newer OS (which has been the same since we resdesigned the network back in 2015).

 

What version of Windows 10 are you running? I run fully on Windows 10 Education and havent been prompted even without this setting in place. Im assuming that OP has some Windows 10 Pro devices.

Posted
How many times have they broken it?

 

Never but I pucker up when doing one and the idea letting staff do these unexpected and unsupervised. urrrgh.

Posted
What version of Windows 10 are you running? I run fully on Windows 10 Education and havent been prompted even without this setting in place. Im assuming that OP has some Windows 10 Pro devices.

 

Fully Education here.. I haven't seen the prompts and I run the same settings as the teachers.

Posted (edited)
Fully Education here.. I haven't seen the prompts and I run the same settings as the teachers.

 

Edit: Sorry completely misread your post. Havent had my coffee yet :confused: Strange.

Edited by tmoon-mint
Posted (edited)
What version of Windows 10 are you running? I run fully on Windows 10 Education and havent been prompted even without this setting in place. Im assuming that OP has some Windows 10 Pro devices.

I'm also using Windows 10 Education. Education is a skew of Enterprise, which is different than Home/Pro, etc.

Edited by CHiLL
Posted (edited)

I've done the ADMX update but the policy isn't appearing, it is under the Windows Update for Business, will this work?

 

updatefb.PNG

 

admxupdated.PNG

Edited by chazzy2501
Posted

How are the devices configured to update? If they update through WSUS or WUfB they shouldn't offer Windows 11 until you set the feature target to Windows 11, as far as I'm aware not setting it at all does not mean that Win 11 will appear.

If the updates are just direct from Windows Update, no management besides the GPOs setting client side settings, then Win 11 will appear when it's ready.

Posted

alright screenshot time, I've run a gp result on a staff laptop as a member of staff and the GPO says no but the laptop says yes!

 

So can I not read and comprehend English?

 

screen shot, with annoy scribbles included!Screenshot (43).png

Posted
alright screenshot time, I've run a gp result on a staff laptop as a member of staff and the GPO says no but the laptop says yes!

 

So can I not read and comprehend English?

 

screen shot, with annoy scribbles included![ATTACH=CONFIG]65578[/ATTACH]

 

The highlighted GPO doesn't stop updates, just removes the button to allow users to manually run a check (which is absent in your screenshot)

Posted (edited)
alright screenshot time, I've run a gp result on a staff laptop as a member of staff and the GPO says no but the laptop says yes!

 

So can I not read and comprehend English?

 

screen shot, with annoy scribbles included![ATTACH=CONFIG]65578[/ATTACH]

Since you have a GPO called "Wsus NO WSUS ITS BRO...", I suspect that your WSUS is broken. If you can fix or redo WSUS, I reckon that'll resolve your issues regarding Windows 11 upgrades.

 

Also, the WSUS settings are located in: Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Updates > Manage updated offered from Windows Server Update Service. If you specify a WSUS location in "Specify intranet Microsoft update service location" (even if the source you enter doesn't exist, such as "serverdoesntexist.fqdn") and also set "Do not connect to any Windows Update Internet locations" to "Enabled", that should prevent your devices connecting to the Internet for updates...then the clients shouldn't be allowed to talk to the Internet.

Edited by CHiLL

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...