Server 2019 GPO for domain to disable Win11 upgrade

Gabriel 31 Reputation points
2022-01-27T19:06:14.78+00:00

I'm running Server 2019 and do not see the option in GPO editor to push the option to stay on a specific version to the client machines.

I checked User and Computer Configuration > Policies > Admin Templates > Windows Components > Windows Update (and WU for Business) and don't see the option that's referenced on so many sites. How do I get it updated to enable an option to stop people from upgrading to Windows 11?

It doesn't make sense to login to 30 machines to manually change the registry. We have a domain with 3 DC's, 2 DFS servers, 2 RDP boxes, and multiple various other servers and workstations. What would I need to change?

Thank you for your help.

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,859 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,299 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
8,441 questions
{count} votes

Accepted answer
  1. Dave Patrick 426.2K Reputation points MVP
    2022-01-27T19:30:25.537+00:00

    Local Computer Policy\Computer Configuration\Administrative Templates\Windows Components\Windows Update\Manage updates offered from Windows Updates

    Set to Enabled and add one of the following values (ex. 21H2)

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    169196-image.png

    1 person found this answer helpful.

6 additional answers

Sort by: Most helpful
  1. Gabriel 31 Reputation points
    2022-01-27T19:23:13.95+00:00

    I figured it out!

    So, edit the registry on your Windows 11 machine. Install the Windows RSAT tools for Group Policy Management. Launch regedit and create a new Key and then DWORD value: Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Group Policy, EnableLocalStoreOverride = 1, reboot.

    Launch Group Policy Management, edit the Default Domain policy or the one you've created just for this. Navigate to Computer Configuration > Policies > Admin Templates > Windows Components > Windows Update > Manage updates offered from Windows Update. Double click "Select the target Feature Update version", set to enabled, put "Windows 10" in the first box and "21H2" in the second.

    Note, later in the year you might need to change from 21H2 to the newer Windows 10 release when those updates are being rolled out.

    2 people found this answer helpful.

  2. Adam J. Marshall 8,886 Reputation points MVP
    2022-02-04T14:20:43.94+00:00

    You don't need to do all of what Gabriel did. Simply load the Windows 11 GPO ADMX Templates into your central store and you'll have the options.

    See the bottom section titled appropriately on:

    https://www.ajtek.ca/wsus/how-to-setup-manage-and-maintain-wsus-part-3-windows-as-a-service-waas-and-group-policy-administrative-templates/

    1 person found this answer helpful.

  3. Dave Patrick 426.2K Reputation points MVP
    2022-01-27T21:31:51.103+00:00

    Where are you looking?

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    169204-image.png


  4. JHSD 1 Reputation point
    2022-03-15T14:52:06.043+00:00

    Thank you for the described steps and screen shots above. But at first this still did not work for a DC in Windows Server 2019.

    I downloaded the admx for both Win10 and Win11 to Windows Server 2019
    I ran the MSI.
    It extracted/placed the files into C:\Program Files (x86)\Microsoft Group Policy\ under a folder with the policy name
    I copied those files and folders to a new folder in central store under \PolicyDefinitions-Win1021h1
    (and also to a new folder \PolicyDefinitions-Win11-21h1 for that set)
    I run gpupdate /force

    I open Group Policy Manager
    I edit the Default Domain Policy object.
    I browse down to Computer Configuration > Policies > Admin Templates > Windows Components > Windows Update >Windows Update for Business

    There was NO entry "Select the target feature update version" under that key.

    The admx files have to be copied into the existing "PolicyDefinitions" folder, over-writing whatever previous ones you have in there (back them up first!). And do it by selecting the files, and copy/paste. Do not over-write the entire folder (such as en-us) because you could be wiping out files you need - not every admx update contains all the same files. It may have 212, but your en-us folder might have 221. Those other 10 extra files you have may still be very important to you, so don't destroy them by just overwriting the folder itself. Same thing for the base folder of PolicyDefinitions - copy/paste the files. You likely have other ones in there you do not want to lose.. so don't rename/delete the PolicyDefinitions folder itself.

    Then run gpupdate and then open the GP editor and the setting should appear.

    But this approach by Microsoft is still stupid. It should not be so broken, and should not require such extra manual processes. This should be delivered to servers as an automatic update that provides a one-click setting to push into GPO's to disable access for end users to run major version upgrades. Sys Admins need time to test, test, and test again before such major things can roll out. To just give it to all end users in corporate networks by default is outrageously dangerous.

    0 comments No comments