Preventing Auto Update of Office 2019 in Domain Environment

Tarek Halloun 36 Reputation points
2022-06-07T15:07:46.283+00:00

hello
i have active directory , wsus and office 2021
how can i disable all updates and connection to microsoft via gpo ?

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
13,664 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Rita Hu -MSFT 9,646 Reputation points
    2022-06-08T02:20:02.827+00:00

    @Tarek Halloun
    Thanks for your posting on Q&A.

    It is recommended to check the DefaultAUService by the following PowerShell script:

    $MUSM = New-Object -ComObject "Microsoft.Update.ServiceManager"  
       
    $MUSM.Services | select Name, IsDefaultAUService  
    

    Reference screenshot in my lab:
    209249-6.png

    The picture indicate that the DefaultAUService is WSUS. The device will try to scan updates from WSUS first.

    The following Group Policies may be helpful:
    Do not connect to any Windows Update Internet locations
    As we all know, we could point to devices to the WSUS Server to get updates by configure the Specify Intranet Microsoft update service location group policy. Specify Intranet Microsoft update service location allows admins to point devices to an internal Microsoft update service location(like WSUS), while Do not connect to any Windows Update Internet locations gives them the option to restrict devices to just that internal update service.
    209267-4.png

    Turn off access to all Windows Update features
    If you enable this policy setting, all Windows Update features are removed. This includes blocking access to the Windows Update website at http://windowsupdate.microsoft.com, from the Windows Update hyperlink on the Start menu, and also on the Tools menu in Internet Explorer. Windows automatic updating is also disabled; you will neither be notified about nor will you receive critical updates from Windows Update. This policy setting also prevents Device Manager from automatically installing driver updates from the Windows Update website.
    209256-7.png

    Please learn more detail about the both group policies and we could choose one of the two according to your environment.

    Hope the above will be helpful.

    Best regards,
    Rita


    If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.