How to turn off Windows updates for good?

Joined
Oct 16, 2018
Messages
1,773
Reaction score
5,857
Location
Florida, USA
I’ve tried a bunch of different things to prevent updates but none have been successful.

Any one have a solution?

Thanks
 

tigerwillow1

Known around here
Joined
Jul 18, 2016
Messages
4,200
Reaction score
9,453
Location
USA, Oregon
My solution is to run win 7 and linux. Aside from that I thought the updates could be turned off in Group Policy Editor.
 

Alaska Country

Getting comfortable
Joined
Jun 10, 2021
Messages
527
Reaction score
730
Location
Alaska
It would appear that Windows always finds a way to update.

For the BI install, that computer is 100% isolated from the net. In my case it is also 100% effective. Zero updates. For others, this solution is not appropriate for their needs.
 
Last edited:

tigerwillow1

Known around here
Joined
Jul 18, 2016
Messages
4,200
Reaction score
9,453
Location
USA, Oregon
There's got to be a way to shut them off. A large company with an IT department can't let updates not under their control go through.
 

OICU2

BIT Beta Team
Joined
Jan 12, 2016
Messages
872
Reaction score
1,481
Location
USofA
There's got to be a way to shut them off. A large company with an IT department can't let updates not under their control go through.
Apparently not, because half the world grinded to a halt the other day with that Crowdstrike update.
 
Joined
Dec 30, 2016
Messages
829
Reaction score
642
Location
Somewhere in the space/time continuum
OPTION 3 of the 7 ways listed, works well. Yet, if needed you can still manually run windows update if needed.


Definitely do not remove C:\Windows\system32\svchost.exe executable from Windows, as this is used for all services on the computer, including BI.
 
Joined
Mar 2, 2024
Messages
16
Reaction score
6
Location
CA
Apparently not, because half the world grinded to a halt the other day with that Crowdstrike update.
No, those companies (Delta, others) failed for simple reason of ignoring decades old lessons regarding handling ALL system updates (OS and security, plus others, especially anything with local admin/Ring 0 access). Any decently run enterprise configures their updates to hit Dev environments first, the Test/QA, and only a bit after that, Production systems. That's been true every place I worked for last 30+ years
Oh, and if I heard correctly the current CEO at CrowdStrike was also at MacAfee when same thing happened over 10 years ago ??? hope this isn't 'fake news' ... just sloppy processes regardless

Stopping OS updates makes all kinds of sense for completely isolated networks. BUT, for any devices reaching the Internet (email, browsing, etc) not having an update plan is just asking to get hacked. Even an enterprise class firewall for home won't help. There are work-arounds, but in reality, they are more cumbersome than a decent backup routine, not installing most updates on Day 1
Sorry not updating is simply trading one problem for an equal other one in most consumer situations. You aren't actually helping yourself. though it might have a certain in-the-moment emotional appeal

With that said, I do NOT immediately install updates upon release, I'm set to let them 'bake' a bit. And all of my Internet communications are done on Virtual Machines where it is easy to revert an OS image to a prior state.
 
Top