Windows Updates reboot notification for logged on users

%3CLINGO-SUB%20id%3D%22lingo-sub-1345818%22%20slang%3D%22en-US%22%3EWindows%20Updates%20reboot%20notification%20for%20logged%20on%20users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1345818%22%20slang%3D%22en-US%22%3E%3CP%3EWhat%20group%20policy%20setting(s)%20are%20needed%20to%20generate%20notifications%20to%20logged%20on%20users%26nbsp%3Bwhen%20updates%20requiring%20a%20restart%26nbsp%3Bis%20installed%3F%26nbsp%3B%20We%20deploy%20updates%20via%20WSUS%20using%20a%20group%20policy%20to%20configure%20the%20updates%20behavior%20-%20if%2Fwhen%20updates%20requiring%20restart%20are%20installed%20and%20a%20user%20is%20logged%20on%2C%20there%20is%20no%20notification%20that%20the%20system%20needs%20to%20be%20restarted.%26nbsp%3B%20I%20recently%20added%20the%20%22Configure%20auto-restart%20required%20notification%20for%20updates%22%20value%202-User%20Action%2C%20which%20is%20supposed%20to%20generate%20a%20notification%20that%20does%20not%20auto-dismiss%2C%20but%20it%20is%20still%20not%20working.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1345930%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Updates%20reboot%20notification%20for%20logged%20on%20users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1345930%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20for%20the%20reply.%3C%2FP%3E%3CP%3EWe%20are%20using%20WSUS%20standalone.%3C%2FP%3E%3CP%3EGroup%20policy%20is%20configured%20to%20check%20for%20new%20updates%20every%206(ish)%20hours%2C%20to%20auto-install%20at%204am%20and%20reboot%20if%20necessary.%26nbsp%3B%20The%204am%20install%20was%20relevant%20in%20pre-Win10%20days%2C%20I%20understand%20that%20W10%20will%20auto-install%20immediately%20but%20is%20supposed%20to%20do%20the%20reboot%20at%20the%20designated%204am.%26nbsp%3B%20Systems%20with%20logged%20on%20users%20do%20not%20auto-reboot%20(even%20when%20the%20active%20hours%20are%20set%20for%20normal%20business%20hours)%20and%20there%20is%20never%20a%20notification%20to%20logged%20on%20users%20that%20an%20update%20has%20been%20installed%20that%20requires%20a%20reboot.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDavid%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1346001%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Updates%20reboot%20notification%20for%20logged%20on%20users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1346001%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F634934%22%20target%3D%22_blank%22%3E%40Davidf58%3C%2FA%3E%20perfect!%20Let's%20discuss%20the%20policies%20you%20have%20set%3A%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CEM%3EI%20would%20recommend%20setting%20as%20few%20Windows%20Update%20Group%20Policies%20as%20possible.%20Below%20is%20my%20recommendation%20for%20both%20a%20great%20end%20user%20experience%20and%20compliance%3A%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E-%20Typically%2C%20I%20would%20let%20the%20end%20user%20manage%20their%20own%20Active%20Hours%2C%20but%20you%20can%20set%20the%20rang%20for%20such%20via%20%22Specify%20active%20hours%20range%20for%20auto-restarts%22%20(the%20default%20is%2018%20hours).%26nbsp%3B%3C%2FP%3E%0A%3CP%3E-%20I%20would%20recommend%20not%20configuring%20automatic%20updates%20for%20the%20best%20behavior.%20That%20said%2C%20if%20you%20would%20like%20you%20can%20set%20%22Configure%20Automatic%20Updates%22%20to%204%2C%20automatic%20download%20and%20schedule%20the%20install%20or%20to%202%20if%20you%20want%20your%20user%20to%20choose%20to%20download%20the%20update%20for%20a%20period%20of%20time.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E-%20I%20would%20recommend%20setting%20a%20deadline%20if%20you%20have%20compliance%20goals%2C%20for%20versions%201709%2B%2C%20use%20%22Specify%20deadlines%20for%20automatic%20updates%20and%20restarts%22%20this%20will%20allow%20you%20to%20specify%20the%20deadline%20to%20finish%20installing%20and%20a%20grace%20period%20by%20which%20the%20update%20should%20go%20from%20pending%20reboot%20to%20forced%20reboot.%20This%20provides%20a%20good%20user%20experience%20with%20notifications%20asking%20the%20user%20to%20schedule%20the%20reboot%20or%20reboot%20now.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20you%20have%20set%20no%20other%20Group%20Policies%20under%20Windows%20Update%20but%20these%20and%20those%20needed%20to%20point%20at%20your%20specific%20WSUS%20Standalone%20server%2C%20you%20should%20have%20a%20good%20update%20experience%20and%20your%20users%20should%20be%20seeing%20multiple%20restart%20notifications.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20those%20policies%20do%20not%20meet%20your%20needs%20or%20you%20have%20further%20questions%2C%20please%20feel%20free%20to%20go%20to%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fdeployment%2Fupdate%2Fwaas-manage-updates-wufb%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EWindows%20Update%20for%20Business%20docs%20page%3C%2FA%3E%2C%20to%20respond%20to%20this%20thread%2C%20or%20to%20reach%20out%20to%20me%20directly.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAll%20the%20Best%2C%3C%2FP%3E%0A%3CP%3EAria%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1345879%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Updates%20reboot%20notification%20for%20logged%20on%20users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1345879%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F634934%22%20target%3D%22_blank%22%3E%40Davidf58%3C%2FA%3E%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFirst%2C%20what%20deployment%20tool%20are%20you%20using%3F%20Configuration%20Manager%2C%20WSUS%20Stand-alone%2C%20or%20a%203rd%20party%20WSUS%20management%20tool%3F%20The%20Windows%20Update%20Group%20Policies%20you%20are%20referring%20to%20are%20only%20available%20today%20to%20control%20the%20experience%20for%20devices%20that%20are%20being%20managed%20by%20some%20of%20the%20above.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAll%20the%20Best%2C%3C%2FP%3E%0A%3CP%3EAria%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

What group policy setting(s) are needed to generate notifications to logged on users when updates requiring a restart is installed?  We deploy updates via WSUS using a group policy to configure the updates behavior - if/when updates requiring restart are installed and a user is logged on, there is no notification that the system needs to be restarted.  I recently added the "Configure auto-restart required notification for updates" value 2-User Action, which is supposed to generate a notification that does not auto-dismiss, but it is still not working.

3 Replies

Hello @Davidf58,

 

First, what deployment tool are you using? Configuration Manager, WSUS Stand-alone, or a 3rd party WSUS management tool? The Windows Update Group Policies you are referring to are only available today to control the experience for devices that are being managed by some of the above.

 

All the Best,

Aria 

Thanks for the reply.

We are using WSUS standalone.

Group policy is configured to check for new updates every 6(ish) hours, to auto-install at 4am and reboot if necessary.  The 4am install was relevant in pre-Win10 days, I understand that W10 will auto-install immediately but is supposed to do the reboot at the designated 4am.  Systems with logged on users do not auto-reboot (even when the active hours are set for normal business hours) and there is never a notification to logged on users that an update has been installed that requires a reboot.

 

David

@Davidf58 perfect! Let's discuss the policies you have set: 

 

I would recommend setting as few Windows Update Group Policies as possible. Below is my recommendation for both a great end user experience and compliance:

- Typically, I would let the end user manage their own Active Hours, but you can set the rang for such via "Specify active hours range for auto-restarts" (the default is 18 hours). 

- I would recommend not configuring automatic updates for the best behavior. That said, if you would like you can set "Configure Automatic Updates" to 4, automatic download and schedule the install or to 2 if you want your user to choose to download the update for a period of time. 

- I would recommend setting a deadline if you have compliance goals, for versions 1709+, use "Specify deadlines for automatic updates and restarts" this will allow you to specify the deadline to finish installing and a grace period by which the update should go from pending reboot to forced reboot. This provides a good user experience with notifications asking the user to schedule the reboot or reboot now. 

 

If you have set no other Group Policies under Windows Update but these and those needed to point at your specific WSUS Standalone server, you should have a good update experience and your users should be seeing multiple restart notifications. 

 

If those policies do not meet your needs or you have further questions, please feel free to go to Windows Update for Business docs page, to respond to this thread, or to reach out to me directly. 

 

All the Best,

Aria