Windows 10 22H2 Enablement

rjkr-9284 0 Reputation points
2024-07-24T17:16:25.4133333+00:00

Hello I support a customer who has two labs without external connectivity. I know normally that to get to 22h2 in Domain/work environment or at home that you receive the 22H2 Enablement via WSUS, SCCM, or Windows Update.

To my knowledge and according to KB5040427 this msu/Enablement is not being made available on the Microsoft Update Catalog website. There is an msu there for that KB but it does not bring the build to 22H2.

This would mean without this update that the only path forward would be via a 22H2 ISO with an in place upgrade which leaves me with questions. In place upgrades are almost like laying down the whole OS again and I am wondering what that would do to any hardening done on these machines.

The reason for going to 22h2 is for compliance reasons as 21H2 is now considered end of life.

Normally I am able to airgap updates using Microsoft's wsusscn2.cab file however because MS treats 22H2 differently that does not come down with normal updates.

July 9th 2024 KB5040427

https://support.microsoft.com/en-us/topic/july-9-2024-kb5040427-os-builds-19044-4651-and-19045-4651-78458e76-9404-41b4-91b2-6d3cdcf4a530

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
5,822 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Hania Lian - MSFT 22,706 Reputation points Microsoft External Staff
    2024-07-25T01:41:04.56+00:00

    Hello,

    Regarding your concerns about in-place upgrades and system hardening:

    Preservation of Settings: In-place upgrades are designed to retain your applications, settings, and data. However, it’s always a good practice to back up critical data before proceeding.

    Hardening Configurations: Most hardening configurations should remain intact after an in-place upgrade. However, some settings might revert to their defaults, especially if they are not supported in the new version. It’s advisable to review and reapply hardening policies post-upgrade.

    Testing: Before performing the upgrade on all machines, consider testing the process to identify any potential issues with hardening or other configurations.

    Best Regards,

    Hania Lian

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments

  2. Adam J. Marshall 9,786 Reputation points MVP
    2024-07-25T03:06:12.83+00:00

    Question: Do you have WSUS within your Disconnected Environment? This is the proper way to do it (export metadata from online WSUS, copy data to media, sneakernet data to disconnected network, copy data to disconnected WSUS, import the metadata to the disconnected WSUS). Then your devices in the disconnected network check WSUS for updates and find the enablement package and will update using it.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.