SOLVED

Disabling automatic updates

%3CLINGO-SUB%20id%3D%22lingo-sub-1482274%22%20slang%3D%22en-US%22%3EDisabling%20automatic%20updates%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1482274%22%20slang%3D%22en-US%22%3E%3CP%3EHello%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20trying%20to%20disable%20automatic%20updates%20using%20group%20policy.%26nbsp%3B%20We%20are%20deploying%20the%20Stable%20channel%20release%20and%20have%20the%20following%20settings%20%3CEM%3EEnabled%3C%2FEM%3E%20and%20set%20to%20%3CEM%3EUpdates%20disabled%3C%2FEM%3E%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EUpdate%20policy%20override%20default%3C%2FP%3E%3CP%3EUpdate%20policy%20override%26nbsp%3B%20%26nbsp%3B%20(the%20Stable%20channel%20option)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EWe%20have%20some%20end%20points%20where%20the%20browser%20is%20automatically%20updating%20itself%20to%20the%20most%20recent%20version.%26nbsp%3B%20It%20is%20not%20always%20the%20same%20end%20point.%26nbsp%3B%20Each%20time%20it%20happens%2C%20when%20we%20check%20the%20above%20settings%20and%20the%20About%20page%2C%20we%20find%20that%20updates%20are%20disabled%20%2F%20managed%20by%20the%20organisation.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20read%20on%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2FDeployEdge%2Fmicrosoft-edge-update-policies%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2FDeployEdge%2Fmicrosoft-edge-update-policies%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThat%20there%20are%20two%20other%20settings%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAllow%20installation%20default%3C%2FP%3E%3CP%3EAllow%20installation%26nbsp%3B%20%26nbsp%3B%20(by%20channel)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EShould%20we%20also%20be%20setting%20one%20of%20these%20%3CEM%3EAllow%20installation%3C%2FEM%3E%20settings%20to%20prevent%20new%20versions%20of%20the%20browser%20automatically%20installing%2C%20or%20should%20the%26nbsp%3B%3CEM%3EUpdate%20policy%20override%20default%3C%2FEM%3E%20and%26nbsp%3B%3CEM%3EUpdate%20policy%20override%3C%2FEM%3E%20settings%20we%20are%20already%20using%20be%20sufficient%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDuring%20our%20initial%20testing%20it%20appeared%20that%20setting%20%3CEM%3EAllow%20installation%20default%3C%2FEM%3E%20to%20Disabled%20caused%20the%26nbsp%3BSCCM%20deployment%20to%20fail.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20guidance%20would%20be%20much%20appreciated.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMany%20thanks%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERichard%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1482793%22%20slang%3D%22en-US%22%3ERe%3A%20Disabling%20automatic%20updates%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1482793%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F466611%22%20target%3D%22_blank%22%3E%40Ricoli610%3C%2FA%3E%26nbsp%3Bif%20you%20deploy%20Edge%20using%20SCCM%20you%20select%20the%20default%20channel%20in%20SCCM%20and%20configure%20the%20auto%20update%20in%20SCCM.%20SCCM%20handles%20that%20and%20the%20automatic%20update%20within%20Edge%20is%20disabled.%3C%2FP%3E%3CP%3EThis%20does%20need%20no%20extra%20configuration.%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fconfigmgr%2Fapps%2Fdeploy-use%2Fdeploy-edge%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fconfigmgr%2Fapps%2Fdeploy-use%2Fdeploy-edge%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20do%20want%20to%20achieve%3F%20What%20version%20of%20SCCM%20%2F%20MECM%20do%20you%20have%20in%20place%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%2C%20Henno%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1483043%22%20slang%3D%22en-US%22%3ERe%3A%20Disabling%20automatic%20updates%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1483043%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F400875%22%20target%3D%22_blank%22%3E%40Henno_Keers%3C%2FA%3E%26nbsp%3B%20Thanks%20very%20much%20for%20your%20reply.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20using%20SCCM%20%2F%20MECM%202002%20version%205.0.8968.1000.%26nbsp%3B%20Edge%20is%20being%20deployed%20as%20an%20application%20using%20the%20msi%20-%20MicrosoftEdgeEnterpriseX64%20(Software%20Library%20%2F%20Application%20Management).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20trying%20to%20ensure%20that%20Edge%20does%20not%20update%20unless%20we%20deploy%20a%20new%20version%20via%20SCCM.%26nbsp%3B%20We%20have%20had%20a%20small%20number%20of%20clients%20where%20the%20browser%20has%20updated%20itself%20(not%20via%20SCCM).%26nbsp%3B%20The%20group%20policy%20settings%20I%20mention%20above%20are%20set%20and%20the%20browser%20shows%26nbsp%3B%3CEM%3EYour%20organization%20disabled%20updates%3C%2FEM%3E%20when%20we%20check%20the%20About%20page.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20guidance%20in%20the%20link%20you%20posted%20advises%20that%2C%20on%20the%20clients%2C%20the%26nbsp%3B%3CEM%3EPowerShell%20Execution%20Policy%26nbsp%3B%3C%2FEM%3E%3CSPAN%3E%3CEM%3Ecan't%20be%20set%20to%20Restricted.%26nbsp%3B%20%3C%2FEM%3EThis%20may%20not%20be%20something%20that%20we%20are%20able%20to%20get%20approval%20to%20change.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMany%20thanks%3C%2FP%3E%3CP%3ERichard%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

Hello

 

We are trying to disable automatic updates using group policy.  We are deploying the Stable channel release and have the following policies Enabled and set to Updates disabled:

 

Update policy override default

Update policy override    (the Stable channel option)

 

We have some end points where the browser is automatically updating itself to the most recent version.  It is not always the same end point.  Each time it happens, when we check the above policies and the About page, we find that updates are disabled / managed by the organisation.

 

I have read on:

 

https://docs.microsoft.com/en-us/DeployEdge/microsoft-edge-update-policies

 

That there are two other settings:

 

Allow installation default

Allow installation    (by channel)

 

Should we also be setting one of these Allow installation policies to prevent new versions of the browser automatically installing, or should the Update policy override default and Update policy override settings we are already using be sufficient?

 

During our initial testing it appeared that setting Allow installation default to Disabled caused the SCCM deployment to fail.

 

Any guidance would be much appreciated.

 

Many thanks

 

Richard

2 Replies
Highlighted
Best Response confirmed by Ricoli610 (New Contributor)
Solution

@Ricoli610 if you deploy Edge using SCCM you select the default channel in SCCM and configure the auto update in SCCM. SCCM handles that and the automatic update within Edge is disabled.

This does need no extra configuration. 

https://docs.microsoft.com/en-us/mem/configmgr/apps/deploy-use/deploy-edge

 

What do want to achieve? What version of SCCM / MECM do you have in place?

 

Regards, Henno

Highlighted

@Henno_Keers  Thanks very much for your reply.

 

We are using SCCM / MECM 2002 version 5.0.8968.1000.  Edge is being deployed as an application using the msi - MicrosoftEdgeEnterpriseX64 (Software Library / Application Management).

 

We are trying to ensure that Edge does not update unless we deploy a new version via SCCM.  We have had a small number of clients where the browser has updated itself (not via SCCM).  The group policy settings I mention above are set and the browser shows Your organization disabled updates when we check the About page.

 

The guidance in the link you posted advises that, on the clients, the PowerShell Execution Policy can't be set to Restricted.  This may not be something that we are able to get approval to change.

 

Many thanks

Richard