SOLVED: Unable to get rid of windows update group policy
-
I am trying to use Widows update rings on intune replacing our old group policy. Our machines were set with "disable automatic updates" via gpo. Our service provider at that time who managed our infrastructure used the default domain policy to disable windows updates!
I disabled those policies from the default domain policies, did gpupdate on my computer and found that the policy was changed to MDM managed. The next day, the 3 policies are back on the machine and now I am not able to figure out where is this policy from. Checked each and every GPO settings on my server and confirmed that there are no policies related to windows update.
Checked gpedit.msc as admin on my computer
User configuration:
Computer configuration
My gpresult html report which has Windows update search result
Not sure where else to look at and possibly remove this policy
-
While searching for this scenario, came across a topic called "tatooing" from https://docs.microsoft.com/en-us/archive/blogs/grouppolicy/gp-policy-vs-preference-vs-gp-preferences
I then looked at the registry entry and found this.
Changed the NoAutoUpdate value set to 0, did another gpupdate /force and now I dont see any GP policies on the windows update settings!
Will need to restart and confirm once more
-
Jared ran into a simliar'ish problem recently... There is a thread around here somewhere.