Last night I uninstalled a cumulative update (KB5014697) on my windows 11 machines.
I rebooted after uninstalling.
I went in and Re-downloaded the update.
Here is the event log:
PS C:\Users\user1> Get-EventLog -LogName System -InstanceId 44
Index Time EntryType Source InstanceID Message
33735 Jun 23 16:09 Information Microsoft-Windows... 44 Windows Update started downloading an update.
33734 Jun 23 16:09 Information Microsoft-Windows... 44 Windows Update started downloading an update.
33733 Jun 23 16:09 Information Microsoft-Windows... 44 Windows Update started downloading an update.
33732 Jun 23 16:09 Information Microsoft-Windows... 44 Windows Update started downloading an update.
I then disconnected from my windows 11 system by clicking the "X" in the RDP session.
Here is the event log:
ProviderName: Microsoft-Windows-Security-Auditing
TimeCreated Id LevelDisplayName Message
6/23/2022 3:46:23 PM 4779 Information A session was disconnected from a Window Station.
Subject:
Account Name: user1
Account Domain: DOMAIN
Logon ID: 0x10FF5A
Session:
Session Name: RDP-Tcp#0
Additional Information:
Client Name: COMPUTER1
Client Address: x.x.x.x
This event is generated when a user disconnects from an existing Terminal
Services session, or when a user switches away from an existing desktop
using Fast User Switching.
As you can see my computer decided to reboot outside of active hours.
Log Name: System
Source: User32
Date: 6/23/2022 5:30:01 PM
Event ID: 1074
Task Category: None
Level: Information
Keywords: Classic
User: SYSTEM
Computer: COMPUTER1.domain.com
Description:
The process C:\Windows\uus\AMD64\MoUsoCoreWorker.exe (COMPUTER1) has initiated the restart of computer COMPUTER1 on behalf of user NT AUTHORITY\SYSTEM for the following reason: Operating System: Service pack (Planned)
Reason Code: 0x80020010
Shutdown Type: restart
Comment:
Why is Windows 11 ignoring the NOREBOOTWITHLOGGEDONUSER regkey?