Issue:
You do not want Windows Machines in your AD environment to update automatically on Patch Tuesday
Resolution:
-
Create a new group Policy
-
Set Windows Components>Windows Update>Defer Windows Updates>Select when Feature Updates are received to: enabled
-
Set Branch Readiness level to: Current Branch for Business (this feature is being deprecated soon, but it won't hurt to have it on)
-
Set After a feature update is released, defer receiving it for this many days to: 30
-
-
Set Windows Components>Delivery Optimization>Download Mode to: Enabled
-
Set Download Mode to: Group 2 (Group 2 only allows the P2P sharing of an update on devices in the same Active Directory Site)
-