locked
Windows 10 EDU 1607 downloading updates from Microsoft instead of WSUS RRS feed

  • General discussion

  • Hi,

    We have a horrid 2 Mbps internet connection that we share with over 100 users.  It is paramount that we have a functional WSUS server.

    However, all of our Windows 10 v1607 machines are going straight to Microsoft.  I can validate this by looking at the firewall logs during the update (and the fact that the updates take so long to download).

    I wish I could post a Get-WindowsUpdateLog from the machines, but all I get is GUID junk.  I have already tried clearing the %TEMP%\WindowsUpdateLog and tried manually downloading the symbols and nothing works.  All Windows Update logs have GUID entries and nothing helpful at all.

    What can we do?

    Friday, January 27, 2017 12:38 AM

All replies

  • i've just fixed this by following this info: https://blogs.technet.microsoft.com/windowsserver/2017/01/09/why-wsus-and-sccm-managed-clients-are-reaching-out-to-microsoft-online/

    for us, we were setting 'deferupgrade' regkey via GP, which was the problem. 1607 doesnt like this, and these regkeys are for WUfB usage.

    also, you may wish to look at 'Do not connect to any Windows Update Internet locations'

    also, ensure you have the 1607 ADMX files installed on your AD - theres a number of new settings for windows update in there..

    Friday, January 27, 2017 8:06 AM
  • This appears to have resolved the issue.  However, I read on that forum from a couple of users that a Windows Cumulative patch turned the setting back on again.  I hope this is not a recurring problem.

    I would mark your comment as Answer, but there is no option to do so...

    • Edited by mjmrad81 Friday, January 27, 2017 6:30 PM
    Friday, January 27, 2017 6:13 PM
  • Does anyone know a way to prevent users from accidentally clicking on "Defer feature updates"?
    Friday, January 27, 2017 6:33 PM