• Recommended ACTIVE Group Policies for non-business Windows 10 Pro

    Home » Forums » AskWoody support » Windows » Windows 10 » Questions: Win10 » Recommended ACTIVE Group Policies for non-business Windows 10 Pro

    Author
    Topic
    #2423191

    I’ve disabled all Group Policies in my Windows 10 Pro PC (Installed 12/28/2021 – OS Build 19044.1503 – Windows Feature Experience Pack 120.2212.4170.0) except for these two
    – Target release version for feature updates (set at 21H2)
    – Target product version for feature updates (set at 21H2)

    Does anyone have a current list of active group policies that you recommend, plus a brief reason why you recommend that specific policy? Thanks

     

     

    Viewing 2 reply threads
    Author
    Replies
    • #2423200

      Three things to start:

      Firstly, the computers I manage are still on 21H1, so everything below is based on that, but there aren’t any big changes between 21H1 and 21H2 Group Policies, as far as I know. But apologies in advance if anything is inaccurate or missing.

      Secondly, disabling a Group Policy will often actively set something to not happen (or to happen, in some cases), so you don’t want to do this for literally every policy, as you say you have done. For the vast majority of policies you will want to leave them as Not configured.

      Thirdly, the “Target product version” that you have set, assuming you are referring to the option under ‘Select the target Feature Update version’, should be set to Windows 10, not 21H2. Windows 10 is the Windows product version, 21H2 is the target version for feature updates.

      Here’s a list of Group Policies I recommend for Windows Update:

      Computer Configuration > Administrative Templates > Windows Components > Windows Update > Configure Automatic Updates
      (Enabled and set to: 2 – Notify for download and auto install)
      (This prevents the automatic installation of updates)

      Computer Configuration > Administrative Templates > Windows Components > Windows Update > Do not include drivers with Windows Updates
      (Enabled)
      (If you prefer to manually update drivers)

      Computer Configuration > Administrative Templates > Windows Components > Windows Update -> Windows Update for Business > Manage preview builds
      (Enabled and set to Disable preview builds)
      (Self-explanatory)

      Computer Configuration > Administrative Templates > Windows Components > Windows Update -> Windows Update for Business > Select the target Feature Update version
      (Enabled and set to Windows 10 and 21H2)
      (This keeps you on Windows 10 and 21H2 respectively)

      4 users thanked author for this post.
    • #2423334
      1 user thanked author for this post.
    • #2428769

      Will disabling preview builds block all .NET updates; there seem to be no non-preview .net updates when I use this method to block previews: search Edit Group policy => Computer Configuration > Administrative Templates > Windows Components > Windows Update -> Windows Update for Business > Manage preview builds (Enabled and set to Disable preview builds)

      Thanks

      • #2428790

        See #2427699. Includes CU and .NET Previews.

        1 user thanked author for this post.
      • #2428886

        Based on my experience, I have suspicions that this setting blocks both preview and non-preview .NET updates with the exception of non-preview security .NET updates. Basically, it seems to treat the non-preview non-security .NET updates as previews. I can’t guarantee that this is accurate, as I’ve not read anything about it, it’s just been my observation.

    Viewing 2 reply threads
    Reply To: Recommended ACTIVE Group Policies for non-business Windows 10 Pro

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: