I prefer to have all updates on my servers to be manually controlled. We don't currently use a centralized process for this, so we simply disable the Windows Update GPO setting: Configure Automatic Updates.
As per the description of this setting:
If the status for this policy is set to Disabled, any updates that are available on Windows Update must be downloaded and installed manually. To do this, search for Windows Update using Start.
This is exactly what I want; to manually install updates. However, disabling this AU setting has the undesired effect of completely disabling the option to Check for updates for other Microsoft Products. I still want to include other MS products when I'm performing manual updates.
Why does disabling AU remove other MS products from the update process entirely? Is there a way around this?
I cannot imagine this is a desired effect from Microsoft. I imagine if they are going to give people the option to manually update, they would include updates for all MS products, not just Windows.