Windows 10: Admins, check your W7/W8/W8.1 domain machines

Soldato
Joined
1 Oct 2006
Posts
14,596
Ouch, we use SCCM for updates but luckily the clients are locked down and can't select MS updates. Thought they would have put preventative measures in place :s
 
I think it's all down to KB3035583 installing, be that via SCCM or WU. If the machine has direct Internet access then it'll DL the update (whether it's on a domain or not).

Our machines are W7 Pro, so I presume a W7 Enterprise machine wouldn't have got the update - either way the domain caveat should have stopped that in it's tracks.
 
Surely this won't apply to machines configured to use a WSUS server? Whilst clients can opt to bypass and check Windows Update directly, unless they do so the relevant update shouldn't install as it won't be approved by WSUS.
 
I can only really see this hitting smaller organisations who update directly from WU such as ourselves. We've got limited outbound connectivity to WU in lieu of a WSUS host which my predecessor never got around to configuring.

Needless to say it's now pretty high on my list of priorities...
 
Only issue with WSUS is that, by default, the client has the option to bypass it and go directly to WU so, unless this has been explicitly blocked by the firewall, there's still the opportunity for a user to get the update.

Granted it's nowhere near the same scenario as that detailed above and users would have to deliberately go looking for and download the update and then install it but it still shouldn't be possible. There will be a great many sysadmins out there who've configured WSUS and fully believe they're safe from unwanted Win10 upgrades and will find out to their horror that this isn't the case. There should be no way whatsoever that a domain-joined computer will allow the download or installation of the update unless explicitly allowed by the sysadmin.

MS dropping the ball spectacularly yet again. They really are clueless.
 
I'm a bit confused by this? If you allow your domain machines to download Windows Updates on their own, why are you then surprised when they... download a Windows Update on their own?

Presumably exactly the same happened with SP1 for Windows 7, or any large update?
 
Back
Top Bottom