chazzy2501 Posted May 25, 2022 Posted May 25, 2022 errr, I've seen two staff this morning with Windows 11 on their laptops! I asked how it happened and they said the laptop told them to.... How are non-admin users able to update an operating system?!!?! How do I disable this! What GPO is there! ffs Micro$oft
chazzy2501 Posted May 25, 2022 Author Posted May 25, 2022 oh my god.... to roll back to windows 10 you need admin credentials........ ((slow clap))
CHiLL Posted May 25, 2022 Posted May 25, 2022 To me, it sounds to me like your Windows Update policies need tightening up, as devices in domain environments don't generally go directly through the Internet to get updates, they use WSUS/SCCM, etc. For example, we're using SCCM and it's configured so that updates point back to the SCCM server and cannot default/failover to the Internet if the server is unuavailable. Pressing check updates just brings an error message saying it can't contact the server. I haven't tried running the setup/upgrade program manually as a regular member of staff, but I don't think it'd work as a regular user. Although, I don't know if it actually needs admin permissions or not...so I might try that out at some point. If it doesn't require elevated permissions and your update policies are correct - I can only assume that the users have clicked on an Edge/Bing banner/advert to upgrade, where it's downloaded the upgrade tool and they've followed the instructions.
DalekSec Posted May 25, 2022 Posted May 25, 2022 Going to be honest, same as what @CHiLL said, it's not Microsoft's fault your Update policies aren't correct. Moment Windows 11 was announced I double/triple checked users weren't able to upgrade to it and the relevant settings were in places for us (in our case Intune) 1
chazzy2501 Posted May 25, 2022 Author Posted May 25, 2022 I have the policies configured! I don't allow driver updates (because firmware), I have a schedule and busy hours. I don't see an option to allow / disallow OS upgrade! if you need admin credentials to install a program why does an entire operating system not?!? These are standard users, they can't install a printer or a program without credentials?!? but the OS. is it considered a rollup update or feature update?!
mavhc Posted May 25, 2022 Posted May 25, 2022 It's just Windows 10 22h1 really, so it's a feature update Why don't you allow firmware updates?
PrimaryNetMan Posted May 25, 2022 Posted May 25, 2022 Same as when Win 10 came, if your update polices allow it and your hardware is compatible , surprise. Meanwhile
tmoon-mint Posted May 25, 2022 Posted May 25, 2022 You need this policy set if you dont already. If you dont specify Windows 10 then users will be prompted to upgrade. 1
chazzy2501 Posted May 25, 2022 Author Posted May 25, 2022 It's just Windows 10 22h1 really, so it's a feature update Why don't you allow firmware updates? Firmware updates have the laptop go to black screen a few times, power cycle and flash the keyboard. The potential for the end user to bork the bios through mis understanding during this process is high!
chazzy2501 Posted May 25, 2022 Author Posted May 25, 2022 You need this policy set if you dont already. If you dont specify Windows 10 then users will be prompted to upgrade. [ATTACH=CONFIG]65572[/ATTACH] I don't have this option?! I assume I need some new ADMX files for the policy store, what ADMX files do I need?
mavhc Posted May 25, 2022 Posted May 25, 2022 Make sure you have the latest admx files https://www.microsoft.com/en-us/download/details.aspx?id=104042 Install locally and copy to your centralstore https://docs.microsoft.com/en-us/archive/blogs/canitpro/step-by-step-managing-windows-10-with-administrative-templates Edit your WU gpo, Select The Target Feature Update Version, put in Windows 10 and 21H2 https://docs.microsoft.com/en-us/windows/release-health/supported-versions-windows-client
CHiLL Posted May 25, 2022 Posted May 25, 2022 You need this policy set if you dont already. If you dont specify Windows 10 then users will be prompted to upgrade. [ATTACH=CONFIG]65572[/ATTACH] I didn't even know that was an option and I certainly don't have it set, yet our users aren't prompted to upgrade to a newer OS (which has been the same since we resdesigned the network back in 2015).
mavhc Posted May 25, 2022 Posted May 25, 2022 Firmware updates have the laptop go to black screen a few times, power cycle and flash the keyboard. The potential for the end user to bork the bios through mis understanding during this process is high! How many times have they broken it?
tmoon-mint Posted May 25, 2022 Posted May 25, 2022 I didn't even know that was an option and I certainly don't have it set, yet our users aren't prompted to upgrade to a newer OS (which has been the same since we resdesigned the network back in 2015). What version of Windows 10 are you running? I run fully on Windows 10 Education and havent been prompted even without this setting in place. Im assuming that OP has some Windows 10 Pro devices.
chazzy2501 Posted May 25, 2022 Author Posted May 25, 2022 How many times have they broken it? Never but I pucker up when doing one and the idea letting staff do these unexpected and unsupervised. urrrgh.
chazzy2501 Posted May 25, 2022 Author Posted May 25, 2022 What version of Windows 10 are you running? I run fully on Windows 10 Education and havent been prompted even without this setting in place. Im assuming that OP has some Windows 10 Pro devices. Fully Education here.. I haven't seen the prompts and I run the same settings as the teachers.
tmoon-mint Posted May 25, 2022 Posted May 25, 2022 (edited) Fully Education here.. I haven't seen the prompts and I run the same settings as the teachers. Edit: Sorry completely misread your post. Havent had my coffee yet Strange. Edited May 25, 2022 by tmoon-mint
CHiLL Posted May 25, 2022 Posted May 25, 2022 (edited) What version of Windows 10 are you running? I run fully on Windows 10 Education and havent been prompted even without this setting in place. Im assuming that OP has some Windows 10 Pro devices. I'm also using Windows 10 Education. Education is a skew of Enterprise, which is different than Home/Pro, etc. Edited May 25, 2022 by CHiLL
chazzy2501 Posted May 25, 2022 Author Posted May 25, 2022 (edited) I've done the ADMX update but the policy isn't appearing, it is under the Windows Update for Business, will this work? Edited May 25, 2022 by chazzy2501
Katy Posted May 25, 2022 Posted May 25, 2022 How are the devices configured to update? If they update through WSUS or WUfB they shouldn't offer Windows 11 until you set the feature target to Windows 11, as far as I'm aware not setting it at all does not mean that Win 11 will appear. If the updates are just direct from Windows Update, no management besides the GPOs setting client side settings, then Win 11 will appear when it's ready.
PotNoodleTech Posted May 25, 2022 Posted May 25, 2022 You need this policy set if you dont already. If you dont specify Windows 10 then users will be prompted to upgrade. [ATTACH=CONFIG]65572[/ATTACH] Thats a usefull tip thanks!!
chazzy2501 Posted May 25, 2022 Author Posted May 25, 2022 alright screenshot time, I've run a gp result on a staff laptop as a member of staff and the GPO says no but the laptop says yes! So can I not read and comprehend English? screen shot, with annoy scribbles included!
ThatBoringBloke Posted May 25, 2022 Posted May 25, 2022 I'm just impressed that you have the hardware to run it on. 2
bald_pig Posted May 25, 2022 Posted May 25, 2022 alright screenshot time, I've run a gp result on a staff laptop as a member of staff and the GPO says no but the laptop says yes! So can I not read and comprehend English? screen shot, with annoy scribbles included![ATTACH=CONFIG]65578[/ATTACH] The highlighted GPO doesn't stop updates, just removes the button to allow users to manually run a check (which is absent in your screenshot)
CHiLL Posted May 25, 2022 Posted May 25, 2022 (edited) alright screenshot time, I've run a gp result on a staff laptop as a member of staff and the GPO says no but the laptop says yes! So can I not read and comprehend English? screen shot, with annoy scribbles included![ATTACH=CONFIG]65578[/ATTACH] Since you have a GPO called "Wsus NO WSUS ITS BRO...", I suspect that your WSUS is broken. If you can fix or redo WSUS, I reckon that'll resolve your issues regarding Windows 11 upgrades. Also, the WSUS settings are located in: Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Updates > Manage updated offered from Windows Server Update Service. If you specify a WSUS location in "Specify intranet Microsoft update service location" (even if the source you enter doesn't exist, such as "serverdoesntexist.fqdn") and also set "Do not connect to any Windows Update Internet locations" to "Enabled", that should prevent your devices connecting to the Internet for updates...then the clients shouldn't be allowed to talk to the Internet. Edited May 25, 2022 by CHiLL
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now