WSUS has lost control of my Windows 10 workstations

The Network Company 116 Reputation points
2020-10-21T00:09:28.693+00:00

Just today, many systems are installing the Windows 10 Feature update 20H2 without permission. My WSUS server has lost control of my workstations.

I don't even find KB4562830 on the Microsoft Update Catalog nor do I find it in my WSUS.

Why is 20H2 installing without my permission?

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
11,097 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,536 questions
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. Adam J. Marshall 9,116 Reputation points MVP
    2020-10-21T00:25:50.883+00:00
    0 comments No comments

  2. The Network Company 116 Reputation points
    2020-10-21T01:21:24.097+00:00

    Thank you for that information.

    I found no suspect dual-scan policies applied:

    egrep 'BranchReadinessLevel|DeferFeatureUpdatesPeriodInDays|DeferQualityUpdatesPeriodInDays|DeferUpdatePeriod|DeferUpgradePeriod|ExcludeWUDriversInQualityUpdate|PauseDeferrals|PauseFeatureUpdates|PauseQualityUpdates|DeferFeatureUpdates|WindowsUpdate|DeferFeatureUpdatesPeriodInDays|PauseFeatureUpdates|PauseFeatureUpdatesStartDate|DeferQualityUpdates|DeferQualityUpdatesPeriodInDays|PauseQualityUpdates|PauseQualityUpdatesStartTime|BranchReadinessLevel|DeferUpgrade|DeferFeatureUpdatesPeriodInDays|DeferQualityUpdatesPeriodInDays|ExcludeWUDriversInQualityUpdate|ExcludeWUDriversInQualityUpdate' gpresult.htm
    

    I also saw your recommendations here: https://www.ajtek.ca/wsus/how-to-setup-manage-and-maintain-wsus-part-4-creating-your-gpos-for-an-inheritance-setup/

    A location policy was present with the recommended items. Delivery optimization was LAN. The workstation and server policies are similar in design

    I am still looking for the reason but I did find a workaround setting this gpo to 2004 prevents 20H2 from installing:
    Windows Components/Windows Update/Windows Update for Business/Target Version for Feature Updates

    0 comments No comments

  3. Rita Hu -MSFT 9,626 Reputation points
    2020-10-21T01:40:59.85+00:00

    Hi TheNetworkCompany-0419,

    Thanks for your posting on this forum.

    Please try to apply the following policy on the client to prevent 20H2 from installing:
    Policy: Do not allow update deferral policies to cause scans against Windows Update

    33855-1.png

    This policy is helpful in preventing from dual scan.

    If there are any updates about this issue, please keep us in touch.

    Regards,
    Rita


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  4. Adam J. Marshall 9,116 Reputation points MVP
    2020-10-21T02:42:31.163+00:00

    egreping for the result may not work due to how the html file is built. Those terms are the registry side names, not the GPO side names. You would have to cross reference the ADMX/ADML files for the actual names of the verbage that is outputted into the GPO.htm file, and that's more work than actually just looking through a gpo.htm file example and reading /looking for items that relate to Windows Update For Business

    0 comments No comments