In this tutorial, I will explain how to configure a Group Policy (GPO) to disable updates through Windows Update.
Warning
It is not recommended to disable Windows updates if you do not have a Patch Management solution.
From the Group Policy Management console, right-click on Group Policy Object and click on New 1.
data:image/s3,"s3://crabby-images/59e07/59e07b76eab2bc15f8a51309b82368ff3fca1c56" alt=""
Name the Group Policy 1 and click OK 2 to create the GPO.
data:image/s3,"s3://crabby-images/76b44/76b44987392e075933a96281da2d6e5ed2b3d2fd" alt=""
We will now edit the group policy that we have just created, right-click on it and click on Modify 1.
data:image/s3,"s3://crabby-images/4fe7a/4fe7a08e38c377bb948829605a554cfe2cf4c9c5" alt=""
Depending on the version of your ADMX files, the setting: Automatic Updates service configuration is not in the same location:
- Computer Configuration / Policies / Administrative Templates / Windows Component / Windows Update
- Computer Configuration / Policies / Administrative Templates / Windows Component / Windows Update / Manage the end user experience
data:image/s3,"s3://crabby-images/59414/5941406b393d0a17e0c2a6ad7ec36acc6ef43230" alt=""
data:image/s3,"s3://crabby-images/963dd/963ddd15cf3047925d0bf6fa3ffca0e685bee85a" alt=""
Open the setting: Configuring the Automatic updates service by double-clicking.
To deactivate Windows Update updates, you must change the setting to “Disabled” 1, validate by clicking on Apply 2 then click on the OK button 3.
data:image/s3,"s3://crabby-images/59893/5989351f0787d08e4f1a0a83c8aae9cc91070438" alt=""
On many Group Policy settings, Not Configured or Disabled have the same behavior, but not for configuring updates.
The Automatic Updates Service Configuration setting has been changed to Disabled.
data:image/s3,"s3://crabby-images/4c456/4c45658d23e19402b22ff4bcb6133f942d54bb89" alt=""
data:image/s3,"s3://crabby-images/284dd/284dd9de0d2d1169bd6176bac6e2a00bf156ed81" alt=""
Close the Group Policy Editor.
Here is the overview of the GPO which allows you to disable Windows Update updates.
data:image/s3,"s3://crabby-images/af759/af759699be4b70bf84b0fd219366bb52add17077" alt=""
Now we will link the GPO so that it is applied to the computers, right-click where the GPO should be applied and click on Link an existing GPO 1.
data:image/s3,"s3://crabby-images/c8569/c8569abefa44a1d43bf39374fb7eb61ef8ddddc7" alt=""
Select GPO 1 and click OK 2.
data:image/s3,"s3://crabby-images/ed67d/ed67dbc8d6d31df2fa47710c2da31ff3a4d4b119" alt=""
Group Policy is linked to the Organizational Unit: Computers.
data:image/s3,"s3://crabby-images/a83bd/a83bd896d18505b882cac7b5a10c1fd49fb213b3" alt=""
Wait while the settings are updated on the different computers in the fleet.
You can check its application on computers by looking at the applied configuration:
- Windows 10: Click on Show configured update policies
- Windows 11: Advanced options / Update policy configured.
data:image/s3,"s3://crabby-images/8f2ca/8f2ca19b154ceda4069531cf969a75bf98132f46" alt=""
data:image/s3,"s3://crabby-images/c34e4/c34e46fefed06b12340d13c855d43804a4d47d4d" alt=""
Now you know how to disable Windows Update using Group Policy.
In this tutorial, I took Windows 10 and 11 as an example, but this also applies to Windows Server.
On the Internet, you will also find another alternative, which is to configure updates on a “fake” WSUS service, I find this solution less “clean” than this one.