I’m trying to find an easier way to turn off automatic updating in Win10 Pro Anniversary Update, version 1607. Several of you have recommended using t
[See the full post at: An experiment with Win10 Pro]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
An experiment with Win10 Pro
Home » Forums » Newsletter and Homepage topics » An experiment with Win10 Pro
- This topic has 30 replies, 4 voices, and was last updated 8 years, 6 months ago.
Tags: Windows 10 Pro Notify
AuthorTopicViewing 29 reply threadsAuthorReplies-
Roc
GuestNovember 8, 2016 at 8:04 am #23627Last I checked using the “2” setting leads to annoying full screen notifications that interrupt whatever you’re doing, if you don’t decide to install updates for a week (or two… don’t know the exact time).
So even if it works after AU I wouldn’t use it. Instead on W10 I set “Configure Automatic Updates” to disabled and then do manual check&install.
But I’ll do the experiment in a VM and let you know how it goes.
-
zero2dash
GuestNovember 8, 2016 at 8:12 am #23628Yeah, Hoffman’s wrong – it works fine in AU.
Have several machines on 10 Pro, version 1607, build 14393.351.
Local GP set to “2 – Notify for download and notify for install”. As you’ve said, it doesn’t notify twice (as the setting alludes to), but it does alert and not do anything until you go to Windows Update and tell it to Update/Download.I have noticed that yes indeed, Windows Defender/MSE updates are included in this lot, so you get a lot of notifications if that’s what you’re using. Because of this, I’ve switched my home machines to Bitdefender Free 2016 and now only get Windows Update notifications when there’s an actual update out there (which hasn’t happened lately though I expect that’ll change today).
IMHO it’s the only way to fly with 10. I may not be able to pick and choose updates anymore, but at least I can postpone them without my system doing anything in the meantime. Hopefully that doesn’t change, but knowing Microsoft, I’m not holding my breath.
-
AlexEiffel
GuestNovember 8, 2016 at 8:48 am #23629Maybe I am naรฏve or I don’t know where to look or I don’t subscribe to some big enterprise Microsoft information and documentation channel, but isn’t that very unprofessional to not publish clear specifications of what is changed in settings behavior between versions of Windows? Considering many businesses, small or big, rely on Windows and can have their productivity affected by lack of information, isn’t that completely amateurish?
-
woody
ManagerNovember 8, 2016 at 9:14 am #23630The documentation’s better than it used to be. See
https://support.microsoft.com/en-us/help/12387/windows-10-update-history
-
NotBill
GuestNovember 8, 2016 at 11:41 am #23631Yup, the ‘2’ setting works as expected since day one, but the full screen notification sucks because there is no close button; the only way out is via ESC key.. And the notification pops up several times a day until the updates get installed.. Looks like Microsoft ignores that some folks keep machines running 24/7 with several VMs up.. Installing updates on all of them and rebooting them all each time Microsoft ships their junkdates (roughly once a week) really sucks. Before Windows 10, this has been done once a month..
However, the most disturbing thing with AU updates currently is that the LSM (local session manger) service hangs on start after reboot. The only workaround currently available is to shut down the computer the hard way (pulling the plug or pressing the power button until the computer turns off) and power up the machine a few times until LSM makes it…
-
David
GuestNovember 8, 2016 at 11:56 am #23632 -
BobbyB
Guest -
woody
ManagerNovember 8, 2016 at 12:06 pm #23634Very good question – and I’m not absolutely sure of the answer. In my InfoWorld article
it’s Step 3B. But I’m skeptical that it’ll work in the long run – and I’m fearful of the prospects of disabling Windows Update altogether.
-
PKCano
Manager -
ch100
AskWoody_MVPNovember 8, 2016 at 12:56 pm #23636Woody, the Windows 2016 Server has a command line which comes from the Core version, but works in the Desktop Experience version. This is the same build 1607.
When running sconfig.exe, there are only 3 options:********************************************
5) Windows update Settings: DownloadOnly
Enter number to select and option: 5
Windows Update currently set to: DownloadOnly
Select (A)utomatic, (D)ownloadOnly, (M)anual update:********************************************
Anyone can register and run the Server trial for 180 days.
This may indicate that the Notify for download and notify for install has been deprecated (in the server, but this is the same build)? The default for the server seems to be DownloadOnly
The command line sconfig.exe in fact does a basic configuration of the Group Policies without all the fancy options available in the Group Policy Editor.
-
ch100
AskWoody_MVP -
ch100
AskWoody_MVP -
ch100
AskWoody_MVPNovember 8, 2016 at 1:06 pm #23639Microsoft does not want non-professionals to block the updates, due to the existence of so much malware in the wild and they have the tacit agreement of the industry to force the updates to end-users. Too many unsuspecting end-user machines are infected and cause problems on the internet.
Those who are in this business as professionals can sort it out, although it is not easy. -
Kenney
GuestNovember 8, 2016 at 1:06 pm #23640Woody,
I have both a Pro. system and a Home system.
The Pro. system is an old Dell Optiplex 755 Desktop. I have Group Policy set for 2 in the auto update section. I think you are right to not set the whole policy to disable. I get a flyout from the Action Center, that I have set the time it shows on screen to 5 seconds: Settings>Ease of Access>Other Options>Show Notifications for. There is a drop down box to set time display is shown time from 5 sec. min to 5 min. maximum. I have never had a full window notification for updates in either system. The Laptop is a Dell Inspiron 15 I got back in May this year. The desktop is on Ver. 1607 now, the laptop is still running 1511 with 1607 hidden by Wushowhide.
I still use Wushowhide on both systems to stop updates from loading and installing till Defcon changes. I can only guess that some systems react differently from brand to brand and on setup to setup from implementation of the different settings. -
ch100
AskWoody_MVPNovember 8, 2016 at 1:13 pm #23641Disable AU works with a caveat. If you click on the button to check for updates, it will actually behave like on Automatic Updates. The button is no longer greyed out as far as I can tell.
Another way is to set a fake update server in Group Policies, which may generate timeouts and slow down the machine.
The Check for updates has never been a great idea, although it makes some sense. Those very curious to find out what is available, can use DownloadOnly instead which is certainly supported. -
pfp
Guest -
David
GuestNovember 8, 2016 at 2:18 pm #23643I’ve felt all along that “Disable AU” was only a temporary workaround that MS will eventually patch out. And I share your concern that Windows Update should not be left disabled long-term. A reactivation issue is one easy way MS can force an update after a delay such as six months. I always follow the Woody Go Sign and have been updating Win 10 almost a month after update release.
A couple of months ago I bought a laptop which came with 1607 installed–wouldn’t have been my choice then, but I wasn’t given one. No problems. And then in late October, I updated a Win 10 desktop to 1607. Problem. It knocked out my sound, by resetting my Creative Sound Blaster Z driver to defaults and thereby disabling a digital audio out port I was using. I wasted an hour or two troubleshooting to run that problem down. I hadn’t updated the driver, so that was unexpected.
Also thanks, Neil (below) for the guidance.
-
PKCano
ManagerNovember 8, 2016 at 3:42 pm #23644I have set up three scenarios on VMs running 1607 14393.351 Pro. On all three initially, WU was set to Manual (Trigger Start) and Group Policies was set to 2 – Notify for download and notify for install.
#1 I left the settings as is. I get a flyout in the Action Center “You need some updates. Select this message to install.”
If I instead go to Windows Update in Settings, the available updates are listed and there is a “Download” button. Downloads do not start automatically.#2 I left the Group Policies and WU settings as they were.
In Task Scheduler under WindowsUpdate there were four tasks: “Automatic App Update,” “Scheduled Start,” “sih,” and “sihboot.” I disabled “Automatic App Update,” but it reset to Ready on reboot or when I left it sitting for a while.
Also, four other tasks appeared: “AUFirmwareInstall, “AUSessionConnect AUScheduledInstall,” and “Scheduled Start With Network.”
I deleted the “Automatic App Update” task (see recommendations under “An experiment with Win10 Home”) and disabled the rest. The “Scheduled Start” task kept resetting to Ready.
However, I received NO notification for updates. Under Settings, Windows Update did not search and there was no pending update list.#3 I set Group Policies to “not configured” (the default).
I left WU service set to Manual (Trigger Start).
In Task Scheduler under WindowsUpdate I deleted “Automatic App Update” and disabled the other three tasks (Scheduled Start, sih, and sihboot). None reset to Ready.
This is as close as I can come to the experiment with Home edition – no Group Policies.
I received no notifications.
Under Settings, WU did not search and there was no list of pending updates.Observations:
I would be hesitant to delete the “Automatic App Update” task in a real-life situation, not knowing the other implications.I got no full screen notification that froze what I was doing. I did not “Select this message to install” but when I went to Windows Update in Settngs there was a “Download” button and downloads did not start automatically.
I will try all three VMs again this evening and tomorrow to see if things changed. I will also run wushowhide as well as manually check for updates to see what happens. I will add the results below this entry.
It appears the 2 in Group Policies works as expected in AU 1607 14393.351
-
woody
Manager -
PKCano
Manager -
ch100
AskWoody_MVP -
ch100
AskWoody_MVP -
ch100
AskWoody_MVP -
Roc
GuestNovember 9, 2016 at 2:52 am #23650I just checked now and indeed I received that message in the notification center that I need to install some updates.
I did not choose to install them. When shutting down it said installing updates… but I believe that’s referring to something other than the main updates, I’ve seen it often on W10. -
Roc
GuestNovember 9, 2016 at 2:56 am #23651Yeah that’s what I meant with check&install as it’s a single process on W10.
I’ve not yet tried any 3rd party tool for selecting individual updates, but I might do that. So far the only ones I’ve wanted to hide were the “Malicious software removal tool”, since it’s a large-ish download and I don’t believe I need it, plus it reports to MS. -
PKCano
ManagerNovember 9, 2016 at 9:54 am #23652Results from +/- 8:00am 11/9
#1 No change with Policies set to 2, WU on Manual (Trigger Start). Pending list of updates in Settings, Download button, no auto install.
#2 WU did a search as there is now a list of pending updates and a Download button in Settings. Policies still set to 2, WU still set to Manual (Trigger Start), and no auto install. Tasks “Scheduled Start,” “sih,” and “sihboot” still disabled but “sih” Next Run Time is 12:10am 11/10 so I will check back on this later.
In both these cases, running wushowhide gives the opportunity to hide any of the updates.
Observations:
I would not choose to delete the “Automatic App Update” task or disable the other tasks in a real-life situation unless it proved to be the only way. It doesn’t seem to change anything (yet).
The Group Policy setting of 2 seems to work like stated in the description. Unless it gets automatically changed to 3, of ceases to be effective, I would not change it. Reason: I do not want to download something I have no intention of installing. Don’t forget – in Win7/8.1 this setting automatically installed on reboot—————-
#3 Policies set to “not configured,” WU still disabled, 3 tasks still disabled but the “sih” task Next Run Time is at 10:35pam 11/9, so I will check back early in the morning. There has been no search, no list of pending updates.
wushowhide does not run as WU is disabled
Observations:
I would not choose to delete the “Automatic App Update” task in a real-life situation unless it proved to be the only way.
It remains to be seen if the “sih” task changes the settings. -
ch100
AskWoody_MVPNovember 9, 2016 at 1:56 pm #23653Options 2 and 3 are not for those who choose to not install. They are for those who prefer to do the installation of the updates at a time suitable for their situation.
For those trying not to install, or selectively install whatever they choose and I am against this practice unless temporary, they should set the GP to disabled or the Wi-Fi to metered, although that last solution is just a band-aid, not a professional and reliable approach.
There is not much more to investigate here.
I said it before, abbodi86 said it with even more details, there are complex scheduled tasks which trigger the services and their self-repair and it is not worth changing their behaviour, unless doing it from a perspective of building VDIs or other similar environments which are not within the reach of most readers here. -
PKCano
Manager -
ch100
AskWoody_MVPNovember 10, 2016 at 3:05 am #23655wushowhide is documented to temporarily delay the install of faulty drivers. This could apply to patches too. Notice the work “temporary”.
Anybody is entitled to use the tool as it suits their purpose in an unsupported configuration, but after that action, they are entirely on their own. -
PKCano
ManagerNovember 10, 2016 at 8:08 am #23656Results from +/- 7:30am 11/10
#1 No change with Policies set to 2, WU on Manual (Trigger Start). Pending list of updates in Settings, Download button, no auto install.
#2 WU did a search at login, there is a list of pending updates and a Download button in Settings. Policies still set to 2, WU still set to Manual (Trigger Start), and no auto install. Tasks โScheduled Start,โ โsih,โ and โsihbootโ still disabled. โsihโ Next Run Time is now blank and task was not run.
In both these cases, running wushowhide gives the opportunity to hide any of the available updates.
Conclusions:
The Group Policy setting of 2 seems to work like stated in the description. Unless it gets automatically changed to 3 after a period of time, or ceases to be effective, I would not change it to 3. Reason: I do not want to download something I have no intention of installing. Donโt forget โ in Win7/8.1 this setting automatically installed on reboot.WU on manual and Group Policies set to 2 give the User time to run wushowhide to hide updates (for however long it lasts).
I would not delete or disable the tasks.
โโโโโ-
#3 WU still disabled, 3 tasks still disabled The โsihโ task Next Run Time is at 9:26pm 11/10 although the Last Run Time was on 11/8 so it did not run but did reset the “next time”. There has been no search, no list of pending updates.
I set the WU to Manual and immediately rebooted. After login, I immediately ran wushowhide and the list of available updates was there. So the possibility exists to hide updates. (I did not hide)
Then I opened WU in Settings and did a search which resulted in immediate download/install.Conclusions:
This works…..BUT
I would not choose to delete the โAutomatic App Updateโ task and disable the others in a real-life situation. So I do not feel this is a viable option for Home users.
Viewing 29 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Kevin Beaumont on Microsoft Recall
by
Susan Bradley
1 hour, 36 minutes ago -
The Surface Laptop Studio 2 is no longer being manufactured
by
Alex5723
2 hours, 43 minutes ago -
0Patch, where to begin
by
cassel23
2 hours, 28 minutes ago -
CFPB Quietly Kills Rule to Shield Americans From Data Brokers
by
Alex5723
16 hours, 21 minutes ago -
89 million Steam account details just got leaked,
by
Alex5723
4 hours, 6 minutes ago -
KB5058405: Linux – Windows dual boot SBAT bug, resolved with May 2025 update
by
Alex5723
1 day ago -
A Validation (were one needed) of Prudent Patching
by
Nibbled To Death By Ducks
15 hours, 52 minutes ago -
Master Patch Listing for May 13, 2025
by
Susan Bradley
3 hours ago -
Installer program can’t read my registry
by
Peobody
3 hours, 53 minutes ago -
How to keep Outlook (new) in off position for Windows 11
by
EspressoWillie
13 hours, 39 minutes ago -
Intel : CVE-2024-45332, CVE-2024-43420, CVE-2025-20623
by
Alex5723
21 hours ago -
False error message from eMClient
by
WSSebastian42
1 day, 12 hours ago -
Awoke to a rebooted Mac (crashed?)
by
rebop2020
1 day, 21 hours ago -
Office 2021 Perpetual for Mac
by
rebop2020
1 day, 22 hours ago -
AutoSave is for Microsoft, not for you
by
Will Fastie
18 hours, 55 minutes ago -
Difface : Reconstruction of 3D Human Facial Images from DNA Sequence
by
Alex5723
2 days, 1 hour ago -
Seven things we learned from WhatsApp vs. NSO Group spyware lawsuit
by
Alex5723
1 day, 2 hours ago -
Outdated Laptop
by
jdamkeene
2 days, 7 hours ago -
Updating Keepass2Android
by
CBFPD-Chief115
2 days, 12 hours ago -
Another big Microsoft layoff
by
Charlie
2 days, 12 hours ago -
PowerShell to detect NPU – Testers Needed
by
RetiredGeek
9 hours, 44 minutes ago -
May 2025 updates are out
by
Susan Bradley
39 minutes ago -
Windows 11 Insider Preview build 26200.5600 released to DEV
by
joep517
2 days, 18 hours ago -
Windows 11 Insider Preview build 26120.3964 (24H2) released to BETA
by
joep517
2 days, 18 hours ago -
Drivers suggested via Windows Update
by
Tex265
2 days, 18 hours ago -
Thunderbird release notes for 128 esr have disappeared
by
EricB
14 hours, 20 minutes ago -
CISA mutes own website, shifts routine cyber alerts to X, RSS, email
by
Nibbled To Death By Ducks
3 days, 1 hour ago -
Apple releases 18.5
by
Susan Bradley
2 days, 19 hours ago -
Fedora Linux 40 will go end of life for updates and support on 2025-05-13.
by
Alex5723
3 days, 2 hours ago -
How a new type of AI is helping police skirt facial recognition bans
by
Alex5723
3 days, 3 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.