We've noticed that a few of our managed endpoins have been upgraded to 20H2. This despite our efforts to stop that from happening (now) since we're not ready to deploy it yet (not everything is validated at the moment). Out endpoints are managed with ConfigMgr/MECM and configured to use SUP ór our internal WSUS servers. Both have not pushed any upgrades / updates regarding 20H2.
Since we're only seeing this now, after the fact, we'd like to check how this happend in the first place. I can't get a clear point of origin from the c:\windows\panther\setupact.log nor does the WindowsUpdateLog show something usefull (looks like its wiped after the upgrade). The eventlogs are also limited to information áfter the upgrade.