Jump to content

How do you force users to install Windows Updates...?


Recommended Posts

Posted

TL;DR - just wondered if you force updates and how/when?

 

Currently running WSUS and sitting here looking at the console with a large proportion of laptops with the following status:

 

"1 update waiting for the computer to be restarted to complete installation"

 

This is the June CU (released 14/06/2022)...

 

I have tried forcing the installation at a certain time through GPO but this was hit and miss and was met with a fair amount of resistance from SLT for a variety of reasons (T&L disruption, end of day meetings, training, etc.), once or twice they have even reached the install time limit and just restarted at an inappropriate time... anyway I secretly stuck to my guns and they 'should' install at 15:30.... but this obviously isn't happening.

 

Reasons for this I presume is that laptops are either being used at the time and then being put into standby (set to sleep on closing the lid) and they are obviously just doing this at the end of the day and running for the door instead of shutting them down (not that I blame them for that, but it really doesn't take that long - although I was 15 minutes late leaving yesterday waiting for an old spinning rust laptop to finish its updates - an old spare, 'just in case' from the cupboard that I cloned and stole the SSD from).

 

I am thinking of setting a power config via GPO to shutdown on lid close and reminding them that by putting the laptop into standby it doesn't need Bitlocker to get right back into the login page.... and that WUs are for the security of the network and the data we hold and usually address vulnerabilities etc...

 

Obviously there are a few TA laptops/spares/special use ones that are only used for an hour or so a day/week and they will always be a special case as they sometimes don't even have time to download or install the updates.

Posted

I manage them in different groups/policies.

 

Pupil desktops via WOL at 1.00am. Any teaching or staff desktops get a forced shutdown on a Friday night, and they get the WOL treatment over the weekend. Staff latops get reboot reminders and then a forced reboot. Pupils laptops get an update every couple of days until they are all installed. These seem to work. My struggle is laptops that teachers take home and might bring back once a year under sufferance.

 

The ones that are rarely used are also a problem and getting A/V updates seems to be an issue as well. They are slow on startup because they are rarely used and need updates, and are often rarely used because they are slow on startup.

 

I drip updates out in the month after release unless there's anything really urgent, so I won't release the June updates to my test group before 1st July, and have had an update change freeze on any laptops that might have been used for GCSE's during the exam period.

 

(Faststart is disabled across the domain).

  • Thanks 2
Posted

If you specify an install time, that won't have much bearing at all on the time of day that any required restarts will take place. What governs when a forced restart will occur is the deadline set by any automatic approval rules in WSUS.

 

If you're automatically approving updates in WSUS, include in the rule(s) a deadline for X days after the approval at hh:mm. So even if a CU update is set to install at 15:30 on a Friday, you would also need a deadline being set in WSUS for that category of update in order to ensure that the reboots required to complete the installation do actually take place. Otherwise you're waiting on users indefinitely, which is not how you want to live these days.

 

Our deadlines are all 7 days after approval at 3am. More likely to impact users at the start of their day, rather than during lessons, but only after they've had the best part of a week of notifications to elect to reboot.

  • Thanks 3
Guest Guest
Posted
We force a restart after updates have been installed via SCCM (we don't use maintenance windows), however, we give a 12 hour grace period before the restart is forced
Posted

I guess for 1:1 you should have a compliance policy which prevents access to organisational data unless Windows is up to date.

 

Shared devices should wake at night and update.

  • Thanks 2
Posted
If you specify an install time, that won't have much bearing at all on the time of day that any required restarts will take place. What governs when a forced restart will occur is the deadline set by any automatic approval rules in WSUS.

 

If you're automatically approving updates in WSUS, include in the rule(s) a deadline for X days after the approval at hh:mm. So even if a CU update is set to install at 15:30 on a Friday, you would also need a deadline being set in WSUS for that category of update in order to ensure that the reboots required to complete the installation do actually take place. Otherwise you're waiting on users indefinitely, which is not how you want to live these days.

 

Our deadlines are all 7 days after approval at 3am. More likely to impact users at the start of their day, rather than during lessons, but only after they've had the best part of a week of notifications to elect to reboot.

 

This may be why it seems a little hit and miss as I've confused myself and been trying to use the GPO settings to do the heavy lifting, but I'm still trying to get my head around the reboot part... Does an install that requires a reboot actually force a reboot just with WSUS settings? I thought only the GPO could 'force' a restart, but the deadline in WSUS forced the install...?

 

I don't have automatic approvals set up for anything other than Defender (because the mess MS made of the last few CUs) but I think you can set one on approval anyway? The default rule is there too but it only looks at critical and MS seem to change the categories a particular type of update is in - I have a Critical section that hasn't seen a Windows update since 2018, but now Office updates seem to be in there... CUs seem to have gone from Critical to Security since 2018 too.

Posted
Does an install that requires a reboot actually force a reboot just with WSUS settings? I thought only the GPO could 'force' a restart, but the deadline in WSUS forced the install...?

 

This is my understanding of it. Happy to be corrected if I've got this wrong.

 

The deadline in WSUS is for completion of a update, which is a subtly different thing from installation of an update. You'd use Group Policy to schedule when computers check for updates and also when they'd then download and install them. There are then other GPO settings around how long a reboot will wait for, whether it will hold off if a user is signed in, etc. My understanding is that the deadline in WSUS for completion will trump all of that by forcing a reboot in order to complete an update that may have been installed several days prior.

 

So, say an update is approved in WSUS on a Monday, and has a 7-day deadline associated with it. A computer checks for and finds it on the Tuesday, so it has until the following Monday to get it all done. GPO tells that computer to automatically download updates and then schedule them for installation at 3am. It won't then install the update until Wednesday morning when it's next powered up. The update is installed on the Wednesday but needs a reboot (if it doesn't need a reboot, all is good). If other GPO settings tell the computer to hold off restarting if a user is signed in, it'll be waiting the whole of the rest of the week whilst also asking the user to restart, up until that deadline arrives on the following Monday, at which point the computer will restart regardless (ideally just before delivery of an assembly).

  • Thanks 2
Posted

use the WUFB gpos to Nag the user, then enforce an install if they dont make an informed choice to press install when they leave for the day.

 

Will be some kickback initially but people learn to do them when its convenient or deal with it when the comptuer decides its time

  • Thanks 1
Posted

Not really got any further, but just had my suspicions confirmed....

 

Two teachers (one yesterday and one today) came to me with battery issues.

 

Checked them and found both set to 'sleep on lid close', so no prizes for guessing what they do at the end of the day.

Posted
Checked them and found both set to 'sleep on lid close', so no prizes for guessing what they do at the end of the day.

 

Unfortunately, they probably pick this up from every film and TV show where no-one ever shuts down a computer properly.

 

I've often considered "shutdown on lid close" or a scheduled task to shutdown, but can hear the wailing and gnashing of teach already.

Posted

If you've got the deployment toolkit you can run ZTIWindowsUpdate.wsf with Impero :)

 

cscript "\\srv-mdt01\deploymentshare$\scripts\ZTIWindowsUpdate.wsf" >> \\srv-mdt01\remote_scripts$\winupdatelogs\%computername%.txt

Posted

Mandatory reboots to complete updates are only going to happen once a month, so I'm happy for people to habitually sleep their laptops at the end of each day. They get opportunities to perfom those mandatory reboots at their convenience.

 

If you're bringing in forced restarts, you may want to begin emailing your staff whenever patch Tuesday comes around, to advise them that their computers will soon ask them to restart when convenient.

Posted
I'm happy for people to habitually sleep their laptops at the end of each day. They get opportunities to perfom those mandatory reboots at their convenience.

 

IME they rarely take that opportunity :(.

Posted
If the alternative is a forced restart, might they begin to? At the moment it sounds like their choice is either to elect to restart, or to just not bother and carry on indefinitely.
Posted
They get opportunities to perform those mandatory reboots at their convenience.

 

Yeah, but the thing is they don't... because, well... teachers!

 

It probably goes like this (for the teachers that actually do shut down every night, the others just go straight to 30),

 

10 Just about to leave, go to shutdown...

20 uh-oh... 'Install Updates and shutdown' that could take a while...

30 I'll just close the lid and ignore it...

40 goto 10

 

Then after a week of doing this, it restarts in the middle of training/meeting/Zoom call with parents... and I get the blame.

 

It just doesn't seem that they can make the connection, like they should just be able to ignore it forever!

Posted
If the alternative is a forced restart, might they begin to? At the moment it sounds like their choice is either to elect to restart, or to just not bother and carry on indefinitely.

 

Unfortunately when I've floated the idea SMT won't go along with it :(.

Posted

Sounds like a pain. You can't really win, so you may as well set your deadlines?

Windows does rather stick out these days with it's bothersome updates. Newer OSs are a bit more streamlined in that regard, so that's increasingly what people have come to expect.

Posted
Unfortunately when I've floated the idea SMT won't go along with it :(.

 

do it anyway, if something goes bad because "you never installed an update" you'll be in the firing line for it.

 

They will only ignore it once.

Posted

Have a scheduled task that forces a reboot at the end of a day. Have the task perform at next opportunity if missed. Advise staff on inset that this is going to happen. Advise SLT that this is to install essential security updates (might as well enforce 2FA while you are at it). If you get kick back from SLT then advise this is to help combat ransomware crypto and all the horrors that will have. Make sure you have a paper trail for someone telling you not to do it.

 

I simply showed our SLT reports of what happens to companies that have their staff account passwords guessed and ransomware on the shared resources etc. That changed their minds and 2FA, compulsory reboots on patch days was mandated.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...