Latest posts by Michael Pietroforte (see all)
- Results of the 4sysops member and author competition in 2018 - Tue, Jan 8 2019
- Why Microsoft is using Windows customers as guinea pigs - Reply to Tim Warner - Tue, Dec 18 2018
- PowerShell remoting with SSH public key authentication - Thu, May 3 2018
If Windows ever rebooted your PC during your lunch break while an important task was still running or you forgot to save data in an open application, then you understand the full extent of this problem. Modern applications are able to prevent Windows from rebooting, but this doesn't always work.
In my view, a computer should never ever automatically restart without explicit confirmation from the user. If security measures can destroy the work of users, then the bad guys have already won. No Windows update is important enough to delete a whole morning's work of your boss.
And if a new dangerous computer worm is really threatening your PCs, then network-wide restarts have to be managed and controlled by humans, not computers.
There are two ways to turn off automatic Windows Update reboots. You can let users choose when to install updates or you can disable auto-restarts.
Let users choose when to install Windows updates ^
You can configure Automatic Updates to only automatically download the latest update but let users choose when to install them. This configuration can be set through the Control Panel applet Windows Update (type Windows Update at the Start Search prompt) or through Group Policy (Computer Configuration\Administrative Templates\Windows Components\Windows Update\Configure Automatic Updates).
Windows will then inform users about new available updates. If a user doesn't install them right away, Windows will do so when the user shuts down the computer. The disadvantage of this method is that this also prevents the installation of updates that don't require a restart if the user ignores the message from Windows Update.
However, there is a Group Policy setting for allowing the installation of these unproblematic updates: Computer Configuration\Administrative Templates\Windows Components\Windows Update\Allow Automatic Updates immediate installation. If this setting is enabled, Windows Updates automatically installs updates that neither interrupt Windows services nor restart Windows.
Turn off automatic reboots ^
But the best option is simply to turn off automatic reboots with this Group Policy setting: Computer Configuration\Administrative Templates\Windows Components\Windows Update\No auto-restart with logged on users for scheduled automatic update installations. I recommend using this setting network-wide because it will reduce the number of angry help desk calls significantly.
I only covered the three Windows Update settings that I consider most important. I recommend also having a look at the other Group Policy settings at Computer Configuration\Administrative Templates\Windows Components\Windows Update. You might find something that is worthwhile configuring in your environment.