fix(updates): notify before installing downloaded updates (#5105)

* fix(windows update): prevent sudden restart

Microsoft has documented that the `NoAutoRebootWithLoggedOnUsers` registry
key is unreliable and does not work as described in newer versions of Windows.

To effectively prevent unexpected restarts in modern configurations,
this PR updates the `Recommended` settings workflow on the `Updates` tab.

Changes
- Modify `AUOptions` to 3: automatic download and manual installation.
- Remove the obsolete registry key.
- Keep the removal of the registry key in functions that reset Windows Update to default.
- Update UI text and documentation.
- Update Pester tests.

Microsoft documentation:
https://learn.microsoft.com/en-us/windows/deployment/update/waas-restart

Resolves #5093

* Clarify update installation notification behavior

---------

Co-authored-by: Chris Titus <contact@christitus.com>
This commit is contained in:
eduardodepaiva
2026-09-29 11:18:47 -05:00
committed by GitHub
co-authored by Chris Titus
parent fc03af421b
commit 4d4e219562
4 changed files with 17 additions and 16 deletions
@@ -8,7 +8,7 @@ function Invoke-WPFUpdatessecurity {
1. Disables driver offering through Windows Update
2. Defers feature updates for 365 days
3. Defers quality updates for 4 days
4. Prevents automatic restarts while a user is signed in
4. Configures automatic updates to notify when downloaded updates are ready to install
#>
@@ -67,13 +67,16 @@ function Invoke-WPFUpdatessecurity {
Remove-ItemProperty -Path $legacySettingsPath -Name $legacyValue -ErrorAction SilentlyContinue
}
Write-Host "Preventing automatic restarts while users are signed in..."
Write-WinUtilLog -Component "Updates" -Message "Configuring scheduled automatic updates without restarting while users are signed in."
Write-Host "Configuring automatic updates to download and notify before installation..."
Write-WinUtilLog -Component "Updates" -Message "Configuring automatic updates to download and notify before installation."
New-Item -Path $automaticUpdatePolicyPath -Force
# NoAutoRebootWithLoggedOnUsers only applies when automatic updates use option 4.
Set-ItemProperty -Path $automaticUpdatePolicyPath -Name "AUOptions" -Type DWord -Value 4
Set-ItemProperty -Path $automaticUpdatePolicyPath -Name "NoAutoRebootWithLoggedOnUsers" -Type DWord -Value 1
# Remove the previous scheduled-install reboot policy when switching to download-and-notify.
Remove-ItemProperty -Path $automaticUpdatePolicyPath -Name "NoAutoRebootWithLoggedOnUsers" -ErrorAction SilentlyContinue
# AUOptions 3 downloads updates and notifies before installation; it does not control restarts.
Set-ItemProperty -Path $automaticUpdatePolicyPath -Name "AUOptions" -Type DWord -Value 3
Set-ItemProperty -Path $automaticUpdatePolicyPath -Name "AUPowerManagement" -Type DWord -Value 0
Write-WinUtilLog -Component "Updates" -Message "Recommended Windows Update settings workflow completed."