Hello anonymous user,
Thank you for posting here.
To better understand your question, please confirm the following information at your convenience.
1.Is your server in workgroup or domain?
2.Based on the description "the next day all users have access to the network folder that only certain people should access", did you check the shared permissions and NTFS permissions the next day? If so, do the permissions change after windows update?
If permissions on network folder are indeed modified,
did you enable audit policy on the server and on this folder before running windows update?
If so, we can check event ID 4663 and check who changed the permissions on this folder.
If no, you can check who changed the permissions on this folder by rerunning windows update (if rerun windows update can reproduce the issue).
1.Enable audit policy on the server and on the folder based on the steps in the following link.
How to find out who changed the Folder permissions
https://www.manageengine.com/products/active-directory-audit/kb/how-to/how-to-find-out-who-changed-the-folder-permissions.html
2.Ensure the permissions on network folder are correct.
3.Reruning windows update to reproduce the issue and check event ID 4663.
Or remove the windows update installed yesterday and rerun windows update to reproduce the issue and check event ID 4663.
For example:
In my lab, the Administrator change the permission on folder C:\req.
Hope the information above is helpful.
Should you have any question or concern, please feel free to let us know.
Best Regards,
Daisy Zhou
============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.