mirror of
https://github.com/ChrisTitusTech/winutil.git
synced 2026-10-08 11:39:10 +11:00
* fix(windows update): prevent sudden restart Microsoft has documented that the `NoAutoRebootWithLoggedOnUsers` registry key is unreliable and does not work as described in newer versions of Windows. To effectively prevent unexpected restarts in modern configurations, this PR updates the `Recommended` settings workflow on the `Updates` tab. Changes - Modify `AUOptions` to 3: automatic download and manual installation. - Remove the obsolete registry key. - Keep the removal of the registry key in functions that reset Windows Update to default. - Update UI text and documentation. - Update Pester tests. Microsoft documentation: https://learn.microsoft.com/en-us/windows/deployment/update/waas-restart Resolves #5093 * Clarify update installation notification behavior --------- Co-authored-by: Chris Titus <contact@christitus.com>
84 lines
4.6 KiB
PowerShell
84 lines
4.6 KiB
PowerShell
function Invoke-WPFUpdatessecurity {
|
|
<#
|
|
|
|
.SYNOPSIS
|
|
Sets Windows Update to recommended settings
|
|
|
|
.DESCRIPTION
|
|
1. Disables driver offering through Windows Update
|
|
2. Defers feature updates for 365 days
|
|
3. Defers quality updates for 4 days
|
|
4. Configures automatic updates to notify when downloaded updates are ready to install
|
|
|
|
#>
|
|
|
|
Write-Host "Disabling driver offering through Windows Update..."
|
|
Write-WinUtilLog -Component "Updates" -Message "Applying recommended Windows Update settings."
|
|
Write-WinUtilLog -Component "Updates" -Message "Disabling driver offering through Windows Update."
|
|
|
|
$windowsUpdatePolicyPath = "HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate"
|
|
$automaticUpdatePolicyPath = Join-Path $windowsUpdatePolicyPath "AU"
|
|
|
|
Write-Host "Restoring Windows Update availability..."
|
|
Write-WinUtilLog -Component "Updates" -Message "Restoring Windows Update services and scheduled tasks before applying recommended settings."
|
|
|
|
Remove-ItemProperty -Path $automaticUpdatePolicyPath -Name "NoAutoUpdate" -ErrorAction SilentlyContinue
|
|
Remove-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Config" -Name "DODownloadMode" -ErrorAction SilentlyContinue
|
|
|
|
Set-Service -Name BITS -StartupType Manual
|
|
Set-Service -Name wuauserv -StartupType Manual
|
|
Set-Service -Name UsoSvc -StartupType Automatic
|
|
Start-Service -Name UsoSvc
|
|
|
|
$Tasks =
|
|
'\Microsoft\Windows\InstallService\*',
|
|
'\Microsoft\Windows\UpdateOrchestrator\*',
|
|
'\Microsoft\Windows\UpdateAssistant\*',
|
|
'\Microsoft\Windows\WaaSMedic\*',
|
|
'\Microsoft\Windows\WindowsUpdate\*',
|
|
'\Microsoft\WindowsUpdate\*'
|
|
|
|
foreach ($Task in $Tasks) {
|
|
Get-ScheduledTask -TaskPath $Task -ErrorAction SilentlyContinue | Enable-ScheduledTask -ErrorAction SilentlyContinue
|
|
}
|
|
|
|
New-Item -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\Device Metadata" -Force
|
|
Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\Device Metadata" -Name "PreventDeviceMetadataFromNetwork" -Type DWord -Value 1
|
|
|
|
New-Item -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\DriverSearching" -Force
|
|
|
|
Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\DriverSearching" -Name "DontPromptForWindowsUpdate" -Type DWord -Value 1
|
|
Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\DriverSearching" -Name "DontSearchWindowsUpdate" -Type DWord -Value 1
|
|
Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\DriverSearching" -Name "DriverUpdateWizardWuSearchEnabled" -Type DWord -Value 0
|
|
|
|
New-Item -Path $windowsUpdatePolicyPath -Force
|
|
Set-ItemProperty -Path $windowsUpdatePolicyPath -Name "ExcludeWUDriversInQualityUpdate" -Type DWord -Value 1
|
|
|
|
Write-Host "Deferring feature updates by 365 days and quality updates by 4 days..."
|
|
Write-WinUtilLog -Component "Updates" -Message "Deferring feature updates by 365 days and quality updates by 4 days."
|
|
|
|
Set-ItemProperty -Path $windowsUpdatePolicyPath -Name "DeferFeatureUpdates" -Type DWord -Value 1
|
|
Set-ItemProperty -Path $windowsUpdatePolicyPath -Name "DeferFeatureUpdatesPeriodInDays" -Type DWord -Value 365
|
|
Set-ItemProperty -Path $windowsUpdatePolicyPath -Name "DeferQualityUpdates" -Type DWord -Value 1
|
|
Set-ItemProperty -Path $windowsUpdatePolicyPath -Name "DeferQualityUpdatesPeriodInDays" -Type DWord -Value 4
|
|
|
|
$legacySettingsPath = "HKLM:\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings"
|
|
foreach ($legacyValue in @("BranchReadinessLevel", "DeferFeatureUpdatesPeriodInDays", "DeferQualityUpdatesPeriodInDays")) {
|
|
Remove-ItemProperty -Path $legacySettingsPath -Name $legacyValue -ErrorAction SilentlyContinue
|
|
}
|
|
|
|
Write-Host "Configuring automatic updates to download and notify before installation..."
|
|
Write-WinUtilLog -Component "Updates" -Message "Configuring automatic updates to download and notify before installation."
|
|
|
|
New-Item -Path $automaticUpdatePolicyPath -Force
|
|
|
|
# Remove the previous scheduled-install reboot policy when switching to download-and-notify.
|
|
Remove-ItemProperty -Path $automaticUpdatePolicyPath -Name "NoAutoRebootWithLoggedOnUsers" -ErrorAction SilentlyContinue
|
|
|
|
# AUOptions 3 downloads updates and notifies before installation; it does not control restarts.
|
|
Set-ItemProperty -Path $automaticUpdatePolicyPath -Name "AUOptions" -Type DWord -Value 3
|
|
Set-ItemProperty -Path $automaticUpdatePolicyPath -Name "AUPowerManagement" -Type DWord -Value 0
|
|
|
|
Write-WinUtilLog -Component "Updates" -Message "Recommended Windows Update settings workflow completed."
|
|
}
|