laptop bypass update policy

IniobongNkanga-8038 631 Reputation points
2024-03-22T00:11:46.15+00:00

Hello 

 

Please i need your help on this issue. 

 

Yes, I have Intune managed devices. The policy bypassed is Windows Update.

 

We do not allow users to update automatically but Window 11 laptops especially Lenovo are doing updates.

 

Below are what i want to achieve: 

 

  1. How can we stop Windows 11 Lenovo Laptops from doing automatic windows updates because it is bypassing the policy. 

 

  1. How to stop the windows 11 Lenovo/Dell laptops from asking for BitLocker key after doing an update. 

 

WE do not have this issue on windows 10 laptops. 

 

Below is the policy. It is user based. Only users added here have permission to run windows Update but windows 11 devices are bypassing.

thumbnail image 1 of blog post titled  laptop bypass update policy Re: laptop bypass update policy

thumbnail image 2 of blog post titled  laptop bypass update policy Re: laptop bypass update policy

thumbnail image 3 of blog post titled  laptop bypass update policy Re: laptop bypass update policy

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
11,585 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
9,624 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,362 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,061 questions
0 comments No comments
{count} votes

Accepted answer
  1. Crystal-MSFT 48,591 Reputation points Microsoft Vendor
    2024-03-22T02:06:48.9+00:00

    @IniobongNkanga-8038, Thanks for posting in Q&A. From your configuration, I notice the Microsoft product updates and Windows drivers are disabled. Quality update and Feature update deferral period (days) are both set 0 days which means Feature update and Quality update will not deferred. That is to say, the device will the updated when it releases. I find we also set to disable upgrading windows 10 to windows 11. Automatic update behavior is set to reset to default, Windows will automatically determine active hours for the device. Using the active hours, Windows then schedules the best time to install updates and restart the system after updates install. For "Option to pause Windows updates" and Option to check for Windows updates, when it is set disable, it means the users are prevented from pausing the installation of an update and accessing the Windows Update scan. for the configuration, it will not stop the device receiving Quality and Feature updates. It can only precent users to choose check updates.

    https://learn.microsoft.com/en-us/mem/intune/protect/windows-update-settings

    If you want to stop the devices to receive any updates, you can turn off auto update in Settings Catalog policy instead of deploying windows update ring policy.

    enter image description here https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-update#allowautoupdate

    Meanwhile, for your question about asking BitLocker key, based on my researching, I find some user also mentioned when install one windows 11 update, it asks for BitLocker key. You can try the suggestions in the following link to see if it can help. However, if the issue still persists after trying these suggestions, you can contact windows support to get help on this.

    https://technclub.com/guides/windows-11-asking-bitlocker-recovery-key-after-update-fix/

    https://windowsreport.com/windows-11-asking-for-bitlocker-recovery-key/

    Note: Non-Microsoft link, just for the reference.

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.