Files
winutil/functions/public/Invoke-WPFUpdatessecurity.ps1
T
eduardodepaivaandChris Titus 4d4e219562 fix(updates): notify before installing downloaded updates (#5105)
* fix(windows update): prevent sudden restart

Microsoft has documented that the `NoAutoRebootWithLoggedOnUsers` registry
key is unreliable and does not work as described in newer versions of Windows.

To effectively prevent unexpected restarts in modern configurations,
this PR updates the `Recommended` settings workflow on the `Updates` tab.

Changes
- Modify `AUOptions` to 3: automatic download and manual installation.
- Remove the obsolete registry key.
- Keep the removal of the registry key in functions that reset Windows Update to default.
- Update UI text and documentation.
- Update Pester tests.

Microsoft documentation:
https://learn.microsoft.com/en-us/windows/deployment/update/waas-restart

Resolves #5093

* Clarify update installation notification behavior

---------

Co-authored-by: Chris Titus <contact@christitus.com>
2026-09-29 11:18:47 -05:00

84 lines
4.6 KiB
PowerShell

function Invoke-WPFUpdatessecurity {
<#
.SYNOPSIS
Sets Windows Update to recommended settings
.DESCRIPTION
1. Disables driver offering through Windows Update
2. Defers feature updates for 365 days
3. Defers quality updates for 4 days
4. Configures automatic updates to notify when downloaded updates are ready to install
#>
Write-Host "Disabling driver offering through Windows Update..."
Write-WinUtilLog -Component "Updates" -Message "Applying recommended Windows Update settings."
Write-WinUtilLog -Component "Updates" -Message "Disabling driver offering through Windows Update."
$windowsUpdatePolicyPath = "HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate"
$automaticUpdatePolicyPath = Join-Path $windowsUpdatePolicyPath "AU"
Write-Host "Restoring Windows Update availability..."
Write-WinUtilLog -Component "Updates" -Message "Restoring Windows Update services and scheduled tasks before applying recommended settings."
Remove-ItemProperty -Path $automaticUpdatePolicyPath -Name "NoAutoUpdate" -ErrorAction SilentlyContinue
Remove-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Config" -Name "DODownloadMode" -ErrorAction SilentlyContinue
Set-Service -Name BITS -StartupType Manual
Set-Service -Name wuauserv -StartupType Manual
Set-Service -Name UsoSvc -StartupType Automatic
Start-Service -Name UsoSvc
$Tasks =
'\Microsoft\Windows\InstallService\*',
'\Microsoft\Windows\UpdateOrchestrator\*',
'\Microsoft\Windows\UpdateAssistant\*',
'\Microsoft\Windows\WaaSMedic\*',
'\Microsoft\Windows\WindowsUpdate\*',
'\Microsoft\WindowsUpdate\*'
foreach ($Task in $Tasks) {
Get-ScheduledTask -TaskPath $Task -ErrorAction SilentlyContinue | Enable-ScheduledTask -ErrorAction SilentlyContinue
}
New-Item -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\Device Metadata" -Force
Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\Device Metadata" -Name "PreventDeviceMetadataFromNetwork" -Type DWord -Value 1
New-Item -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\DriverSearching" -Force
Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\DriverSearching" -Name "DontPromptForWindowsUpdate" -Type DWord -Value 1
Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\DriverSearching" -Name "DontSearchWindowsUpdate" -Type DWord -Value 1
Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\DriverSearching" -Name "DriverUpdateWizardWuSearchEnabled" -Type DWord -Value 0
New-Item -Path $windowsUpdatePolicyPath -Force
Set-ItemProperty -Path $windowsUpdatePolicyPath -Name "ExcludeWUDriversInQualityUpdate" -Type DWord -Value 1
Write-Host "Deferring feature updates by 365 days and quality updates by 4 days..."
Write-WinUtilLog -Component "Updates" -Message "Deferring feature updates by 365 days and quality updates by 4 days."
Set-ItemProperty -Path $windowsUpdatePolicyPath -Name "DeferFeatureUpdates" -Type DWord -Value 1
Set-ItemProperty -Path $windowsUpdatePolicyPath -Name "DeferFeatureUpdatesPeriodInDays" -Type DWord -Value 365
Set-ItemProperty -Path $windowsUpdatePolicyPath -Name "DeferQualityUpdates" -Type DWord -Value 1
Set-ItemProperty -Path $windowsUpdatePolicyPath -Name "DeferQualityUpdatesPeriodInDays" -Type DWord -Value 4
$legacySettingsPath = "HKLM:\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings"
foreach ($legacyValue in @("BranchReadinessLevel", "DeferFeatureUpdatesPeriodInDays", "DeferQualityUpdatesPeriodInDays")) {
Remove-ItemProperty -Path $legacySettingsPath -Name $legacyValue -ErrorAction SilentlyContinue
}
Write-Host "Configuring automatic updates to download and notify before installation..."
Write-WinUtilLog -Component "Updates" -Message "Configuring automatic updates to download and notify before installation."
New-Item -Path $automaticUpdatePolicyPath -Force
# Remove the previous scheduled-install reboot policy when switching to download-and-notify.
Remove-ItemProperty -Path $automaticUpdatePolicyPath -Name "NoAutoRebootWithLoggedOnUsers" -ErrorAction SilentlyContinue
# AUOptions 3 downloads updates and notifies before installation; it does not control restarts.
Set-ItemProperty -Path $automaticUpdatePolicyPath -Name "AUOptions" -Type DWord -Value 3
Set-ItemProperty -Path $automaticUpdatePolicyPath -Name "AUPowerManagement" -Type DWord -Value 0
Write-WinUtilLog -Component "Updates" -Message "Recommended Windows Update settings workflow completed."
}