If the user has local administration rights on the computer they can postpone the install or the restart.It is suggested to approve updates outside of core business hours and ask clients to leave their computers on and ‘at the log on prompt’ to minimise interruptions.

To do that highlight the desired computers in your Batch Patch grid and select as shown in the screenshot below.

You can see the results below, which show that my targets are configured to use my local WSUS server, WIN2012R2, for their updating.

After an update is approved for the server group the computer will not install the update or restart automatically.

This method requires an administrator to log onto each server and manually start the installation and restart the server.

Whilst this might seem like a lot of work it is suggested as it ensures servers won’t automatically restart in core hours and if an update fails an administrator will be aware or it immediately.

This method also allows for the updates to be approved, distributed and reported on via WSUS.If you determine, using the above method, that your target computers are pointing to a WSUS server, it’s still possible that they will retrieve updates from Microsoft’s public Windows Update or Microsoft Update servers if “Dual Scan” is enabled.To determine, with certainty, whether or not Dual Scan is enabled and whether your machines are going to search for and retrieve updates from your local WSUS server or Microsoft’s public update servers, please review the following two posts carefully: “Dual Scan” Difficulties with Windows Update on Windows 10 versions 1607 ‘Anniversary update’ and 1703 ‘Creators update’ Deciphering “Dual Scan” Behavior in Windows 10 In Batch Patch you should first verify your Windows Update settings under .However You CAN fix this by adding an extra TS Variable.. Reg Write "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Windows Update\WUStatus Server", o Environment. Reg Write "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Windows Update\Target Group", o Environment. First we setup the Variable in the file \”mdtshare”\Control\In "" then o Shell. Create Entry "Configuring client to use WSUS server " & o Environment. Reg Write "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Windows Update\WUServer", o Environment. They will appear under their own group as specified in step 3.

