I’m trying to find an easier way to turn off automatic updating in Win10 Pro Anniversary Update, version 1607. Several of you have recommended using t
[See the full post at: An experiment with Win10 Pro]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
An experiment with Win10 Pro
Home » Forums » Newsletter and Homepage topics » An experiment with Win10 Pro
- This topic has 30 replies, 4 voices, and was last updated 8 years, 6 months ago.
Tags: Windows 10 Pro Notify
AuthorTopicViewing 29 reply threadsAuthorReplies-
Roc
GuestNovember 8, 2016 at 8:04 am #23627Last I checked using the “2” setting leads to annoying full screen notifications that interrupt whatever you’re doing, if you don’t decide to install updates for a week (or two… don’t know the exact time).
So even if it works after AU I wouldn’t use it. Instead on W10 I set “Configure Automatic Updates” to disabled and then do manual check&install.
But I’ll do the experiment in a VM and let you know how it goes.
-
zero2dash
GuestNovember 8, 2016 at 8:12 am #23628Yeah, Hoffman’s wrong – it works fine in AU.
Have several machines on 10 Pro, version 1607, build 14393.351.
Local GP set to “2 – Notify for download and notify for install”. As you’ve said, it doesn’t notify twice (as the setting alludes to), but it does alert and not do anything until you go to Windows Update and tell it to Update/Download.I have noticed that yes indeed, Windows Defender/MSE updates are included in this lot, so you get a lot of notifications if that’s what you’re using. Because of this, I’ve switched my home machines to Bitdefender Free 2016 and now only get Windows Update notifications when there’s an actual update out there (which hasn’t happened lately though I expect that’ll change today).
IMHO it’s the only way to fly with 10. I may not be able to pick and choose updates anymore, but at least I can postpone them without my system doing anything in the meantime. Hopefully that doesn’t change, but knowing Microsoft, I’m not holding my breath.
-
AlexEiffel
GuestNovember 8, 2016 at 8:48 am #23629Maybe I am naïve or I don’t know where to look or I don’t subscribe to some big enterprise Microsoft information and documentation channel, but isn’t that very unprofessional to not publish clear specifications of what is changed in settings behavior between versions of Windows? Considering many businesses, small or big, rely on Windows and can have their productivity affected by lack of information, isn’t that completely amateurish?
-
woody
ManagerNovember 8, 2016 at 9:14 am #23630The documentation’s better than it used to be. See
https://support.microsoft.com/en-us/help/12387/windows-10-update-history
-
NotBill
GuestNovember 8, 2016 at 11:41 am #23631Yup, the ‘2’ setting works as expected since day one, but the full screen notification sucks because there is no close button; the only way out is via ESC key.. And the notification pops up several times a day until the updates get installed.. Looks like Microsoft ignores that some folks keep machines running 24/7 with several VMs up.. Installing updates on all of them and rebooting them all each time Microsoft ships their junkdates (roughly once a week) really sucks. Before Windows 10, this has been done once a month..
However, the most disturbing thing with AU updates currently is that the LSM (local session manger) service hangs on start after reboot. The only workaround currently available is to shut down the computer the hard way (pulling the plug or pressing the power button until the computer turns off) and power up the machine a few times until LSM makes it…
-
David
GuestNovember 8, 2016 at 11:56 am #23632 -
BobbyB
Guest -
woody
ManagerNovember 8, 2016 at 12:06 pm #23634Very good question – and I’m not absolutely sure of the answer. In my InfoWorld article
it’s Step 3B. But I’m skeptical that it’ll work in the long run – and I’m fearful of the prospects of disabling Windows Update altogether.
-
PKCano
Manager -
ch100
AskWoody_MVPNovember 8, 2016 at 12:56 pm #23636Woody, the Windows 2016 Server has a command line which comes from the Core version, but works in the Desktop Experience version. This is the same build 1607.
When running sconfig.exe, there are only 3 options:********************************************
5) Windows update Settings: DownloadOnly
Enter number to select and option: 5
Windows Update currently set to: DownloadOnly
Select (A)utomatic, (D)ownloadOnly, (M)anual update:********************************************
Anyone can register and run the Server trial for 180 days.
This may indicate that the Notify for download and notify for install has been deprecated (in the server, but this is the same build)? The default for the server seems to be DownloadOnly
The command line sconfig.exe in fact does a basic configuration of the Group Policies without all the fancy options available in the Group Policy Editor.
-
ch100
AskWoody_MVP -
ch100
AskWoody_MVP -
ch100
AskWoody_MVPNovember 8, 2016 at 1:06 pm #23639Microsoft does not want non-professionals to block the updates, due to the existence of so much malware in the wild and they have the tacit agreement of the industry to force the updates to end-users. Too many unsuspecting end-user machines are infected and cause problems on the internet.
Those who are in this business as professionals can sort it out, although it is not easy. -
Kenney
GuestNovember 8, 2016 at 1:06 pm #23640Woody,
I have both a Pro. system and a Home system.
The Pro. system is an old Dell Optiplex 755 Desktop. I have Group Policy set for 2 in the auto update section. I think you are right to not set the whole policy to disable. I get a flyout from the Action Center, that I have set the time it shows on screen to 5 seconds: Settings>Ease of Access>Other Options>Show Notifications for. There is a drop down box to set time display is shown time from 5 sec. min to 5 min. maximum. I have never had a full window notification for updates in either system. The Laptop is a Dell Inspiron 15 I got back in May this year. The desktop is on Ver. 1607 now, the laptop is still running 1511 with 1607 hidden by Wushowhide.
I still use Wushowhide on both systems to stop updates from loading and installing till Defcon changes. I can only guess that some systems react differently from brand to brand and on setup to setup from implementation of the different settings. -
ch100
AskWoody_MVPNovember 8, 2016 at 1:13 pm #23641Disable AU works with a caveat. If you click on the button to check for updates, it will actually behave like on Automatic Updates. The button is no longer greyed out as far as I can tell.
Another way is to set a fake update server in Group Policies, which may generate timeouts and slow down the machine.
The Check for updates has never been a great idea, although it makes some sense. Those very curious to find out what is available, can use DownloadOnly instead which is certainly supported. -
pfp
Guest -
David
GuestNovember 8, 2016 at 2:18 pm #23643I’ve felt all along that “Disable AU” was only a temporary workaround that MS will eventually patch out. And I share your concern that Windows Update should not be left disabled long-term. A reactivation issue is one easy way MS can force an update after a delay such as six months. I always follow the Woody Go Sign and have been updating Win 10 almost a month after update release.
A couple of months ago I bought a laptop which came with 1607 installed–wouldn’t have been my choice then, but I wasn’t given one. No problems. And then in late October, I updated a Win 10 desktop to 1607. Problem. It knocked out my sound, by resetting my Creative Sound Blaster Z driver to defaults and thereby disabling a digital audio out port I was using. I wasted an hour or two troubleshooting to run that problem down. I hadn’t updated the driver, so that was unexpected.
Also thanks, Neil (below) for the guidance.
-
PKCano
ManagerNovember 8, 2016 at 3:42 pm #23644I have set up three scenarios on VMs running 1607 14393.351 Pro. On all three initially, WU was set to Manual (Trigger Start) and Group Policies was set to 2 – Notify for download and notify for install.
#1 I left the settings as is. I get a flyout in the Action Center “You need some updates. Select this message to install.”
If I instead go to Windows Update in Settings, the available updates are listed and there is a “Download” button. Downloads do not start automatically.#2 I left the Group Policies and WU settings as they were.
In Task Scheduler under WindowsUpdate there were four tasks: “Automatic App Update,” “Scheduled Start,” “sih,” and “sihboot.” I disabled “Automatic App Update,” but it reset to Ready on reboot or when I left it sitting for a while.
Also, four other tasks appeared: “AUFirmwareInstall, “AUSessionConnect AUScheduledInstall,” and “Scheduled Start With Network.”
I deleted the “Automatic App Update” task (see recommendations under “An experiment with Win10 Home”) and disabled the rest. The “Scheduled Start” task kept resetting to Ready.
However, I received NO notification for updates. Under Settings, Windows Update did not search and there was no pending update list.#3 I set Group Policies to “not configured” (the default).
I left WU service set to Manual (Trigger Start).
In Task Scheduler under WindowsUpdate I deleted “Automatic App Update” and disabled the other three tasks (Scheduled Start, sih, and sihboot). None reset to Ready.
This is as close as I can come to the experiment with Home edition – no Group Policies.
I received no notifications.
Under Settings, WU did not search and there was no list of pending updates.Observations:
I would be hesitant to delete the “Automatic App Update” task in a real-life situation, not knowing the other implications.I got no full screen notification that froze what I was doing. I did not “Select this message to install” but when I went to Windows Update in Settngs there was a “Download” button and downloads did not start automatically.
I will try all three VMs again this evening and tomorrow to see if things changed. I will also run wushowhide as well as manually check for updates to see what happens. I will add the results below this entry.
It appears the 2 in Group Policies works as expected in AU 1607 14393.351
-
woody
Manager -
PKCano
Manager -
ch100
AskWoody_MVP -
ch100
AskWoody_MVP -
ch100
AskWoody_MVP -
Roc
GuestNovember 9, 2016 at 2:52 am #23650I just checked now and indeed I received that message in the notification center that I need to install some updates.
I did not choose to install them. When shutting down it said installing updates… but I believe that’s referring to something other than the main updates, I’ve seen it often on W10. -
Roc
GuestNovember 9, 2016 at 2:56 am #23651Yeah that’s what I meant with check&install as it’s a single process on W10.
I’ve not yet tried any 3rd party tool for selecting individual updates, but I might do that. So far the only ones I’ve wanted to hide were the “Malicious software removal tool”, since it’s a large-ish download and I don’t believe I need it, plus it reports to MS. -
PKCano
ManagerNovember 9, 2016 at 9:54 am #23652Results from +/- 8:00am 11/9
#1 No change with Policies set to 2, WU on Manual (Trigger Start). Pending list of updates in Settings, Download button, no auto install.
#2 WU did a search as there is now a list of pending updates and a Download button in Settings. Policies still set to 2, WU still set to Manual (Trigger Start), and no auto install. Tasks “Scheduled Start,” “sih,” and “sihboot” still disabled but “sih” Next Run Time is 12:10am 11/10 so I will check back on this later.
In both these cases, running wushowhide gives the opportunity to hide any of the updates.
Observations:
I would not choose to delete the “Automatic App Update” task or disable the other tasks in a real-life situation unless it proved to be the only way. It doesn’t seem to change anything (yet).
The Group Policy setting of 2 seems to work like stated in the description. Unless it gets automatically changed to 3, of ceases to be effective, I would not change it. Reason: I do not want to download something I have no intention of installing. Don’t forget – in Win7/8.1 this setting automatically installed on reboot—————-
#3 Policies set to “not configured,” WU still disabled, 3 tasks still disabled but the “sih” task Next Run Time is at 10:35pam 11/9, so I will check back early in the morning. There has been no search, no list of pending updates.
wushowhide does not run as WU is disabled
Observations:
I would not choose to delete the “Automatic App Update” task in a real-life situation unless it proved to be the only way.
It remains to be seen if the “sih” task changes the settings. -
ch100
AskWoody_MVPNovember 9, 2016 at 1:56 pm #23653Options 2 and 3 are not for those who choose to not install. They are for those who prefer to do the installation of the updates at a time suitable for their situation.
For those trying not to install, or selectively install whatever they choose and I am against this practice unless temporary, they should set the GP to disabled or the Wi-Fi to metered, although that last solution is just a band-aid, not a professional and reliable approach.
There is not much more to investigate here.
I said it before, abbodi86 said it with even more details, there are complex scheduled tasks which trigger the services and their self-repair and it is not worth changing their behaviour, unless doing it from a perspective of building VDIs or other similar environments which are not within the reach of most readers here. -
PKCano
Manager -
ch100
AskWoody_MVPNovember 10, 2016 at 3:05 am #23655wushowhide is documented to temporarily delay the install of faulty drivers. This could apply to patches too. Notice the work “temporary”.
Anybody is entitled to use the tool as it suits their purpose in an unsupported configuration, but after that action, they are entirely on their own. -
PKCano
ManagerNovember 10, 2016 at 8:08 am #23656Results from +/- 7:30am 11/10
#1 No change with Policies set to 2, WU on Manual (Trigger Start). Pending list of updates in Settings, Download button, no auto install.
#2 WU did a search at login, there is a list of pending updates and a Download button in Settings. Policies still set to 2, WU still set to Manual (Trigger Start), and no auto install. Tasks “Scheduled Start,” “sih,” and “sihboot” still disabled. “sih” Next Run Time is now blank and task was not run.
In both these cases, running wushowhide gives the opportunity to hide any of the available updates.
Conclusions:
The Group Policy setting of 2 seems to work like stated in the description. Unless it gets automatically changed to 3 after a period of time, or ceases to be effective, I would not change it to 3. Reason: I do not want to download something I have no intention of installing. Don’t forget – in Win7/8.1 this setting automatically installed on reboot.WU on manual and Group Policies set to 2 give the User time to run wushowhide to hide updates (for however long it lasts).
I would not delete or disable the tasks.
—————-
#3 WU still disabled, 3 tasks still disabled The “sih” task Next Run Time is at 9:26pm 11/10 although the Last Run Time was on 11/8 so it did not run but did reset the “next time”. There has been no search, no list of pending updates.
I set the WU to Manual and immediately rebooted. After login, I immediately ran wushowhide and the list of available updates was there. So the possibility exists to hide updates. (I did not hide)
Then I opened WU in Settings and did a search which resulted in immediate download/install.Conclusions:
This works…..BUT
I would not choose to delete the “Automatic App Update” task and disable the others in a real-life situation. So I do not feel this is a viable option for Home users.
Viewing 29 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Windows 11 Insider Preview build 26200.5600 released to DEV
by
joep517
1 hour, 56 minutes ago -
Windows 11 Insider Preview build 26120.3964 (24H2) released to BETA
by
joep517
1 hour, 58 minutes ago -
Drivers suggested via Windows Update
by
Tex265
1 hour, 49 minutes ago -
Thunderbird release notes for 128 esr have disappeared
by
EricB
32 minutes ago -
CISA mutes own website, shifts routine cyber alerts to X, RSS, email
by
Nibbled To Death By Ducks
8 hours, 49 minutes ago -
Apple releases 18.5
by
Susan Bradley
3 hours, 14 minutes ago -
Fedora Linux 40 will go end of life for updates and support on 2025-05-13.
by
Alex5723
10 hours, 15 minutes ago -
How a new type of AI is helping police skirt facial recognition bans
by
Alex5723
10 hours, 52 minutes ago -
Windows 7 ISO /Windows 10 ISO
by
ECWS
17 hours, 49 minutes ago -
No HP software folders
by
fpefpe
18 hours, 33 minutes ago -
Which antivirus apps and VPNs are the most secure in 2025?
by
B. Livingston
2 hours, 30 minutes ago -
Stay connected anywhere
by
Peter Deegan
23 hours, 56 minutes ago -
Copilot, under the table
by
Will Fastie
15 hours, 9 minutes ago -
The Windows experience
by
Will Fastie
1 day, 6 hours ago -
A tale of two operating systems
by
Susan Bradley
21 hours, 7 minutes ago -
Microsoft : Resolving Blue Screen errors in Windows
by
Alex5723
1 day, 11 hours ago -
Where’s the cache today?
by
Up2you2
2 days, 2 hours ago -
Ascension says recent data breach affects over 430,000 patients
by
Nibbled To Death By Ducks
1 day, 19 hours ago -
Nintendo Switch 2 has a remote killing switch
by
Alex5723
19 hours, 56 minutes ago -
Blocking Search (on task bar) from going to web
by
HenryW
2 hours, 14 minutes ago -
Windows 10: Microsoft 365 Apps will be supported up to Oct. 10 2028
by
Alex5723
2 days, 20 hours ago -
Add or Remove “Ask Copilot” Context Menu in Windows 11 and 10
by
Alex5723
2 days, 20 hours ago -
regarding april update and may update
by
heybengbeng
2 days, 21 hours ago -
MS Passkey
by
pmruzicka
1 day, 23 hours ago -
Can’t make Opera my default browser
by
bmeacham
3 days, 5 hours ago -
*Some settings are managed by your organization
by
rlowe44
2 days, 16 hours ago -
Formatting of “Forward”ed e-mails
by
Scott Mills
3 days, 4 hours ago -
SmartSwitch PC Updates will only be supported through the MS Store Going Forward
by
PL1
3 days, 23 hours ago -
CISA warns of hackers targeting critical oil infrastructure
by
Nibbled To Death By Ducks
4 days, 8 hours ago -
AI slop
by
Susan Bradley
2 days, 2 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.