Jump to content

Recommended Posts

Posted

I've been advised a PC has shutdown in the middle of an exam and was told this was because it was doing an update!

 

Can you sanity check the image of my WSUS GPO and confirm these would not cause a PC to restart just because a pending update was applied in the background whilst a user was working.


Ta.

WSUS.jpg

Posted

I think "allow users to receive prompts" might been the route taken for this incident. The user may have been prompted, and they clicked without considering the implications. It's not an automatic reboot (which you have disabled) if the user opted into it.

 

When we used GPO for managing this, I think we set the equivalent of don't automatically, install and don't prompt on devices within the exam set, for the duration of the exam period.   These days we keep exam devices off the network, in part, to reduce this risk. If one does need to be connected, our SOP is to keep it out of circulation until we have manually triggered a windows update scan and install so we're sure there's nothing lurking.

 

 

  • Like 1
Posted

I've checked event viewer on the computer for Event Viewer → Windows Logs → System

 

Does this suggest the PC did just restart on it's own?

 

The process C:\WINDOWS\servicing\TrustedInstaller.exe (EXTCLR-2019-07) has initiated the restart of computer EXTCLR-2019-07 on behalf of user NT AUTHORITY\SYSTEM for the following reason: Operating System: Upgrade (Planned) Reason Code: 0x80020003 Shut-down Type: restart

 

 

Posted

I wonder if another GPO policy is in place as these are Exam accounts that somehow has suppressed the ability to click the pop-up to delay the reboot 😕

Posted
56 minutes ago, kennysarmy said:

I've checked event viewer on the computer for Event Viewer → Windows Logs → System

 

Does this suggest the PC did just restart on it's own?

 

The process C:\WINDOWS\servicing\TrustedInstaller.exe (EXTCLR-2019-07) has initiated the restart of computer EXTCLR-2019-07 on behalf of user NT AUTHORITY\SYSTEM for the following reason: Operating System: Upgrade (Planned) Reason Code: 0x80020003 Shut-down Type: restart

 

 

Not looked into it for a while, so I'm not sure what the logs would look like if it had paused for the user to consent or manually restart, but that does read to me as though any consent for the reboot had already been given before the update started, (or "please delay reboot" wasn't clicked if/when prompted) Whether this happened via policy, or user interaction I don't know.

Posted

We have four trolleys of laptops here. We book one solidly for the sole purpose of exams throughout the exam period. We don't apply any Windows Updates to that trolley for the duration. If an essential one came out, we'd manually apply it to all of them outside school hours.

 

GPO looks fine.

  • Like 1
Posted
7 minutes ago, Jawloms said:

We have four trolleys of laptops here. We book one solidly for the sole purpose of exams throughout the exam period. We don't apply any Windows Updates to that trolley for the duration. If an essential one came out, we'd manually apply it to all of them outside school hours.

 

GPO looks fine.

 

If only we had that luxury - we have students sitting exams in the main hall on laptops from various departments that can spare them and other students in offices all over the school on desktop PC's.

 

Posted

if you do NOT exclude drivers, this can include FIRMWARE updates and the possibility of an impatient pupil bricking a device. 

 

 

Posted
Just now, chazzy2501 said:

if you do NOT exclude drivers, this can include FIRMWARE updates and the possibility of an impatient pupil bricking a device. 

 

 

 

Cheers - yes Drivers are not updated or upgraded via WSUS

Posted

Another PC restarted yesterday with no user intervention. 

 

Details from the System Event Log are:

 

The process C:\WINDOWS\uus\packages\preview\AMD64\MoUsoCoreWorker.exe (6A700-2021-03) has initiated the restart of computer 6A700-2021-03 on behalf of user NT AUTHORITY\SYSTEM for the following reason: Operating System: Service pack (Planned)
 Reason Code: 0x80020010
 Shut-down Type: restart
 Comment: 

 

 

This was with a user logged on.

 

We have this Computer Group Policy set:

 

No auto-restart with logged on users for scheduled automatic updates installations - ENABLED

 

Computer Configuration/Administrative Templates/Windows Components/Windows Update/Legacy Policies Supported On: Windows XP Professional Service Pack 1 or At least Windows 2000 Service Pack 3 Explanation Specifies that to complete a scheduled installation, Automatic Updates will wait for the computer to be restarted by any user who is logged on, instead of causing the computer to restart automatically. If the status is set to Enabled, Automatic Updates will not restart a computer automatically during a scheduled installation if a user is logged in to the computer. Instead, Automatic Updates will notify the user to restart the computer. Be aware that the computer needs to be restarted for the updates to take effect. If the status is set to Disabled or Not Configured, Automatic Updates will notify the user that the computer will automatically restart in 5 minutes to complete the installation. Note: This policy applies only when Automatic Updates is configured to perform scheduled installations of updates. If the "Configure Automatic Updates" policy is disabled, this policy has no effect.

 

 

 

I just don't see how computers are restarting on their own :(

 

Anecdotal evidence from the incident yesterday was that a pop-up came up asking for the computer to be restarted following a Windows update, but it was supressed and then within 5 minutes the computer just restarted with no one near it!

 

 

Posted

In addition, I also have 

"Turn off auto-restart for updates during active hours" enabled.

 

Active hours specified as 8AM - 5PM in our case.

 

I can't see if you have that set as it would be truncated in your screenshot.

 

 

 

Posted
2 minutes ago, sigma said:

In addition, I also have 

"Turn off auto-restart for updates during active hours" enabled.

 

Active hours specified as 8AM - 5PM in our case.

 

I can't see if you have that set as it would be truncated in your screenshot.

 

 

 

 

Hi, yes I have that set too.

Posted

Just above that in the policy, do you have deadlines and grace periods set? If so, How long are they?

Posted

...while this is probably a config error (because keeping tabs on where and how all the settings interact seems to be a Sisyphean task).... I have a ( paranoid? unfounded? cynical?) suspicion that Microsoft might be ignoring some "don't restart in business hours/without user consent" settings in order to get machines up to date before the secure boot certificate expirey next month. 

This May, we've seen 50% more devices  come completely up to date than is usual by this time in the month, even some previously extremely recalcitrant devices have cleared update errors and made it up to 8457 / 7079 / 7291 

Posted

14 days and 7 days for the Deadline & Grace periods - just added them to my WSUS GPO this morning to see if that makes any difference.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...