Server 2019 GPO for domain to disable Win11 upgrade

Gabriel 31 Reputation points
2022-01-27T19:06:14.78+00:00

I'm running Server 2019 and do not see the option in GPO editor to push the option to stay on a specific version to the client machines.

I checked User and Computer Configuration > Policies > Admin Templates > Windows Components > Windows Update (and WU for Business) and don't see the option that's referenced on so many sites. How do I get it updated to enable an option to stop people from upgrading to Windows 11?

It doesn't make sense to login to 30 machines to manually change the registry. We have a domain with 3 DC's, 2 DFS servers, 2 RDP boxes, and multiple various other servers and workstations. What would I need to change?

Thank you for your help.

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,815 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,227 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
8,340 questions
{count} votes

Accepted answer
  1. Dave Patrick 426.2K Reputation points MVP
    2022-01-27T19:30:25.537+00:00

    Local Computer Policy\Computer Configuration\Administrative Templates\Windows Components\Windows Update\Manage updates offered from Windows Updates

    Set to Enabled and add one of the following values (ex. 21H2)

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    169196-image.png

    1 person found this answer helpful.

6 additional answers

Sort by: Most helpful
  1. BDSolenia 1 Reputation point
    2022-03-31T18:04:19.233+00:00

    @JHSD

    Edit: I did figure it out by searching elsewhere, but it still didn't work. I got all kinds of errors trying to copy files into the c:\windows\policy definitions folder, so I'm sure some of the files weren't copied over. I totally agree with you. This is a MAJOR cluster and I can't believe this is so complicated. The rest of my clients have Windows 2019 server, and the option is just there in the GPO. That it isn't included in 2016 is beyond me.

    What does you mean by the admx have to be copied to the existing Policy Definitions folder? What policy definitions folder? Where is that located?

    I have a Windows 2016 server that is doing the same thing. I followed your instructions but am stuck at this point.

    Thanks.


  2. Marco Holz 0 Reputation points
    2023-02-24T13:03:39.4166667+00:00

    But the real question is:

    Why is (per default) a simple Domain User able to install a new OS when he does not even have the rights to modify a simple .txt File in ProgramFiles Folder?

    0 comments No comments