-
MS-DEFCON 2: Make sure Windows automatic update is locked down
With Patch Tuesday coming up tomorrow, it’s time to get your Win 7, 8.1 and 10 machines locked down. Turn off automatic updating using the techniques listed in the tab above marked “Automatic Updates.”
For those of you using Win10 with a Wi-Fi internet connection, that involves setting your internet connection to “metered.” If you have a wired internet connection, in Win10 Pro, you can turn off updating with GPEdit. If you have Win10 Home with a wired internet connection, you have to mess around with the internals a bit.
In Win7 and 8.1 it’s not hard – go for “Check for updates but let me choose whether to download and install them” or “Never check for updates (not recommended).” Not recommended by Microsoft, that is. Fully recommend by yours truly.
Those of you who intend to stick with Win7 or 8.1 should start giving some thought about Group A and Group B – whether you trust Microsoft to apply all of its updates, or whether you want to just stick with the security patches. You don’t need to make a decision about that until October, but now’s a good time to think it through.
I’m moving to MS-DEFCON 2: Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don’t do it.