# Windows Update Group Policy: 7 Settings for Windows 11

Source: https://srvscripts.com/guides/windows-update-group-policy/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

A Windows Update Group Policy object decides where Windows 11 and Windows Server machines get their updates, when they install them and how hard they push for a restart. This guide covers the settings that matter on Windows 11 24H2 and 25H2 and Windows Server 2016 to 2025: the WSUS server location, client-side targeting, Configure Automatic Updates, compliance deadlines, active hours, deferrals and the target feature update version, with the registry values behind each one and the Intune equivalent.

**Short answer:** Create a GPO for each update ring and link it to the matching computer OU. For WSUS, enable `Computer Configuration » Policies » Administrative Templates » Windows Components » Windows Update » Manage updates offered from Windows Server Update Service » "Specify intranet Microsoft update service location"` with `http://wsus01.contoso.com:8530` in both URL fields, then enable “Enable client-side targeting” with the WSUS group name. Add the two deadline policies under Manage end user experience so machines restart within a known number of days, and check the result in **Settings » Windows Update » Advanced options » Configured update policies**.

In short: Create a GPO for each update ring and link it to the matching computer OU.

## Which method to use

Every Windows Update Group Policy setting has a registry value and, on current builds, an MDM equivalent. Choose by where the machine is managed and where it gets its content.

| Method | Update source | Scope | Pros | Cons |
| --- | --- | --- | --- | --- |
| GPO + WSUS | Your WSUS server | Domain-joined clients and servers | You approve every update; works offline from the internet | WSUS needs care and feeding; no new WSUS features |
| GPO + Windows Update client policies (formerly Windows Update for Business) | Microsoft Windows Update | Domain-joined clients | No server; deferrals and target versions per OU | Internet bandwidth; less granular than approvals |
| Registry values (GPP or script) | Either | Workgroup machines, images | No ADMX needed | Easy to get wrong; values persist after removal |
| Intune update rings | Windows Update | Entra-joined or co-managed devices | Works off the corporate network; reporting | Do not mix with the same GPO settings on one device |

If you still run WSUS, keep it and use this guide to control the clients. Installation and cleanup of the server itself is covered in our [WSUS on Windows Server 2025 guide](/guides/wsus-windows-server-2025/). WSUS is on Microsoft’s deprecated features list, which means no new features, but it is still included and supported in Windows Server 2025.

## Prerequisites

- Windows 11 Pro, Enterprise or Education (24H2 or 25H2), or Windows Server 2016 to 2025, joined to the domain.

- Current Windows 11 ADMX files in the Central Store (`\\contoso.com\SYSVOL\contoso.com\Policies\PolicyDefinitions`). Older `WindowsUpdate.admx` files show a flat list instead of the Windows 11 subfolders and miss the newer deadline policies.

- Rights to create and link GPOs, and one pilot OU with a few test machines.

- For WSUS: the server URL and port (`8530` for HTTP, `8531` for HTTPS) and the computer group names you created in the WSUS console.

## How the Windows Update policy folder is laid out

With current ADMX files, the node `Computer Configuration » Policies » Administrative Templates » Windows Components » Windows Update` contains four subfolders. Knowing which folder a setting lives in saves a lot of searching.

| Subfolder | Main settings |
| --- | --- |
| Manage end user experience | “Configure Automatic Updates”, “Turn off auto-restart for updates during active hours”, “Specify active hours range for auto-restarts”, the deadline policies |
| Manage updates offered from Windows Server Update Service | “Specify intranet Microsoft update service location”, “Enable client-side targeting”, “Automatic Updates detection frequency”, “Do not connect to any Windows Update Internet locations”, “Specify source service for specific classes of Windows Updates” |
| Manage updates offered from Windows Update | “Select when Preview Builds and Feature Updates are received”, “Select when Quality Updates are received”, “Select the target Feature Update version”, “Disable safeguards for Feature Updates” |
| Legacy Policies | Older restart and notification settings that Microsoft marks as not applicable to Windows 11 |

## Method 1: Point clients at WSUS

This part of the Windows Update Group Policy tells the client which server to scan and which WSUS computer group it belongs to.

- In **Group Policy Management**, create a GPO such as WU – Workstations – Pilot and link it to the pilot OU.

- Go to `Computer Configuration » Policies » Administrative Templates » Windows Components » Windows Update » Manage updates offered from Windows Server Update Service`.

- Enable **“Specify intranet Microsoft update service location”**. Enter the same URL in Set the intranet update service for detecting updates and Set the intranet statistics server, for example `https://wsus01.contoso.com:8531`. Leave the alternate download server empty unless you host content elsewhere.

- Enable **“Enable client-side targeting”** and type the WSUS group name, for example `Workstations-Pilot`. Several groups can be separated with semicolons. In the WSUS console, set Options » Computers to “Use Group Policy or registry settings on computers”.

- Optionally enable **“Automatic Updates detection frequency”**. The interval is in hours (1 to 22, default 22), and Windows subtracts up to 20 percent at random so clients do not all scan at once.

- Enable **“Do not connect to any Windows Update Internet locations”** only if clients must never reach Microsoft directly. It can stop the Microsoft Store and Delivery Optimization from working.

### Scan source on Windows 11

On Windows 11, setting a WSUS server still sends all update classes to WSUS. The policy **“Specify source service for specific classes of Windows Updates”** lets you split this: for example, quality updates from WSUS but feature updates and drivers from Windows Update. Enable it only when you want a mixed source; otherwise leave it Not Configured.

### Registry values written

| Setting | Key | Value (type) |
| --- | --- | --- |
| WSUS URLs | HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate | WUServer, WUStatusServer (REG_SZ) |
| Use the WSUS server | ...\WindowsUpdate\AU | UseWUServer = 1 (REG_DWORD) |
| Client-side targeting | ...\WindowsUpdate | TargetGroupEnabled = 1, TargetGroup (REG_SZ) |
| Detection frequency | ...\WindowsUpdate\AU | DetectionFrequencyEnabled = 1, DetectionFrequency (hours) |

## Method 2: Install behaviour, deadlines and active hours

These settings apply whether the client scans WSUS or Windows Update, so put them in every Windows Update Group Policy object you create.

### Configure Automatic Updates

Go to `Windows Update » Manage end user experience` and open **“Configure Automatic Updates”**. The option you pick is stored as `AUOptions` under `...\WindowsUpdate\AU`:

| AUOptions | Behaviour | Typical use |
| --- | --- | --- |
| 2 | Notify for download and auto install | Rarely useful |
| 3 | Auto download and notify for install | Servers patched by an admin in a window |
| 4 | Auto download and schedule the install | Workstations; choose a day and hour or “Install during automatic maintenance” |
| 7 | Auto download, notify to install, notify to restart | Windows Server 2016 and later, where an admin controls restarts |

Option 5 (allow local admin to choose) does not apply to current Windows. With option 4, `ScheduledInstallDay` (0 = every day, 1 = Sunday to 7 = Saturday) and `ScheduledInstallTime` (0 to 23) hold the schedule. Setting the policy to **Disabled** writes `NoAutoUpdate = 1` and turns automatic updates off, which is almost never what you want.

### Deadlines

Deadlines are the main restart control on Windows 11. In Manage end user experience, Windows 11 22H2 and later offer two policies:

- **“Specify deadline for automatic updates and restarts for quality update”**

- **“Specify deadline for automatic updates and restarts for feature update”**

Each has a deadline in days (0 to 30), a grace period in days (0 to 7) and a checkbox to stop automatic restarts until the grace period ends. Windows uses whichever is later: the day the update was found plus the deadline, or the day a restart became pending plus the grace period. A common workstation value is 3 days for quality updates, 7 for feature updates and a 2-day grace period.

Once a deadline passes, Windows installs the update and restarts regardless of the choice in “Configure Automatic Updates”, so a device cannot postpone updates indefinitely. Check the Explain text in your ADMX version for any newer options.

### Active hours

Enable **“Turn off auto-restart for updates during active hours”** and set, for example, 07:00 to 19:00. It writes `SetActiveHours = 1`, `ActiveHoursStart` and `ActiveHoursEnd` (0 to 23) under `HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate`. **“Specify active hours range for auto-restarts”** caps the range a user can pick (up to 18 hours).

### Legacy restart policies

Policies such as “No auto-restart with logged on users for scheduled automatic updates installations” and “Always automatically restart at the scheduled time” are in Legacy Policies. Microsoft documents them as not applicable to Windows 11. If an older Windows Update Group Policy object still sets them, remove them and rely on deadlines instead.

## Method 3: Deferrals and target feature update version

If clients get updates straight from Microsoft, the Windows Update Group Policy settings to use are in `Windows Update » Manage updates offered from Windows Update`. These settings do not affect updates you approve in WSUS.

- **“Select when Quality Updates are received”**: defer monthly cumulative updates by 0 to 30 days. Pilot ring 0, broad ring 7, servers 14 is a common split. Values: `DeferQualityUpdates = 1`, `DeferQualityUpdatesPeriodInDays`.

- **“Select when Preview Builds and Feature Updates are received”**: defer feature updates by up to 365 days. Values: `DeferFeatureUpdates = 1`, `DeferFeatureUpdatesPeriodInDays`.

- **“Select the target Feature Update version”**: enter the product (`Windows 11`) and the version (`24H2` or `25H2`). The device stays on or moves to that version and ignores newer ones until you change it. Values: `TargetReleaseVersion = 1`, `ProductVersion` and `TargetReleaseVersionInfo` (REG_SZ).

Target version is usually a better control than long feature deferrals: it is explicit and it survives new releases. Keep “Disable safeguards for Feature Updates” off so compatibility holds still protect devices; see our note on the [Windows 11 compatibility hold](/guides/windows-11-compatibility-hold/).

## Method 4: Registry values without a GPO

For a workgroup server or a build image, the same values can be set directly. Run from an elevated prompt:

```
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v WUServer /t REG_SZ /d "https://wsus01.contoso.com:8531" /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v WUStatusServer /t REG_SZ /d "https://wsus01.contoso.com:8531" /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v TargetGroupEnabled /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v TargetGroup /t REG_SZ /d "Servers-Workgroup" /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v UseWUServer /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v AUOptions /t REG_DWORD /d 3 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v NoAutoUpdate /t REG_DWORD /d 0 /f
Restart-Service wuauserv
```

The last line is PowerShell; in Command Prompt use `net stop wuauserv` and `net start wuauserv`. For domain machines, use the ADMX settings instead: a GPP registry item does not clean up after itself, and a later Windows Update Group Policy change would fight with it.

## Method 5: Intune update rings

For Entra-joined or co-managed devices, go to **Devices » By platform » Windows » Manage updates » Windows updates » Update rings » Create profile**. The ring holds the servicing channel, quality and feature deferrals, deadlines (the `Update/ConfigureDeadlineForQualityUpdates`, `ConfigureDeadlineForFeatureUpdates` and grace period CSPs), auto-restart behaviour and active hours. Pin a feature version with a separate Feature updates policy rather than a long deferral.

On co-managed devices, move the Windows Update workload to Intune or keep it in Group Policy, but do not configure the same setting in both. If the device still points at WSUS from an old GPO, Intune rings have no effect on where it scans.

## Target rings with separate GPOs

- **One GPO per ring.** WU – Pilot, WU – Broad and WU – Servers, each with its own targeting group, deferral and deadline. Link each to the OU that holds those machines.

- **Security filtering.** If rings do not match your OU layout, link all ring GPOs high up and filter each to a computer group (remove Authenticated Users from the filter but keep its Read permission). See [GPO security filtering](/guides/group-policy-security-filtering/).

- **Servers.** Use option 3 or 7 and no deadline, and patch in your own maintenance window. A WMI filter on `ProductType` keeps server settings off workstations if both share an OU.

- **Domain controllers.** Give them their own WSUS group and patch them one at a time.

## Verify it works

Check each layer in order: the GPO, the registry, the client view and the server view. Most Windows Update Group Policy problems show up in the first two steps.

- Refresh policy and confirm the GPO applied:

```
gpupdate /forcegpresult /r /scope computergpresult /h C:\Temp\gp.html
```

- Read the values the client actually uses:

```
reg query "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate"reg query "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU"
```

- Open **Settings » Windows Update » Advanced options » Configured update policies**. It lists each active policy and whether it came from Group Policy or MDM.

- Click **Check for updates**. A WSUS client shows only approved updates; if the message says updates are managed by your organisation, the policy is in effect.

- For scan detail, build the readable log from the ETL traces. `Get-WindowsUpdateLog` writes `WindowsUpdate.log` to the desktop by default:

```
Get-WindowsUpdateLog -LogPath C:\Temp\WindowsUpdate.logSelect-String -Path C:\Temp\WindowsUpdate.log -Pattern "WSUS|ServiceUrl|TargetGroup" | Select-Object -Last 20
```

- In the WSUS console, the machine should appear in the target group within one or two detection cycles.

You may find `UsoClient.exe` switches such as `StartScan` in older articles. Microsoft does not document them, so use the Settings button or wait for the next detection cycle instead.

## Troubleshooting

When a Windows Update Group Policy setting seems to be ignored, first confirm the value exists on the client, then look at the update source.

| Symptom | Likely cause | Fix |
| --- | --- | --- |
| Values missing in the registry | GPO not applied (link, filtering, WMI filter) | Check gpresult and events 1058/1030; see Group Policy not applying |
| Client never appears in WSUS | Wrong URL or port, firewall, HTTPS certificate not trusted | Open the URL from the client, trust the WSUS certificate, check ports 8530/8531 |
| Client lands in “Unassigned Computers” | WSUS set to server-side targeting, or group name misspelt | Switch WSUS to Group Policy targeting; match the name exactly |
| Feature update not offered | Target version set lower, or a safeguard hold | Raise TargetReleaseVersionInfo; check the release health dashboard |
| Machines restart in working hours | Deadline reached; active hours not set | Set active hours and a longer grace period |
| Store apps or Delivery Optimization stop working | “Do not connect to any Windows Update Internet locations” enabled | Disable it if clients may reach Microsoft |
| Updates install but fail | Component store or servicing stack problem | See Windows Update errors 0x800f0922 and 0x80070002 |

## Roll back or undo

- Set the changed settings to **Not Configured** or unlink the GPO, then run `gpupdate /force`. Administrative Template values under `SOFTWARE\Policies` are removed on refresh.

- Values you set with `reg add` or a GPP registry item stay behind. Delete them:

```
reg delete "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /fRestart-Service wuauserv
```

- To move a client off WSUS but keep other settings, delete only `WUServer`, `WUStatusServer` and `UseWUServer`.

- After a rollback, the next scan goes to Windows Update. Check **Configured update policies** again to confirm nothing remains.

Test every Windows Update Group Policy change on the pilot ring for one Patch Tuesday before you copy it to the broad ring, and keep the ring GPOs identical apart from targeting, deferral and deadline values.

## Windows Update Group Policy at a glance

**Official documentation:** [Manage additional Windows Update settings](https://learn.microsoft.com/en-us/windows/deployment/update/waas-wu-settings), [Enforce compliance deadlines with policies](https://learn.microsoft.com/en-us/windows/deployment/update/wufb-compliancedeadlines), [Update Policy CSP](https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-update).

**Related guides:** [WSUS Windows Server 2025: Reliable Install and Configuration](/guides/wsus-windows-server-2025/) · [Windows Update Error 0x800f0922, 0x80070002, 0x80073712: Proven Fixes](/guides/windows-update-error-0x800f0922/) · [Troubleshoot Group Policy not applying: gpresult, RSoP and Events 1058/1030](/guides/group-policy-not-applying/).

## Frequently asked questions

### Where are the Windows Update Group Policy settings in Windows 11?

Under Computer Configuration, Policies, Administrative Templates, Windows Components, Windows Update. With current ADMX files they are split into Manage end user experience, Manage updates offered from Windows Server Update Service, Manage updates offered from Windows Update and Legacy Policies.

### Which policy points Windows 11 clients at WSUS?

Enable “Specify intranet Microsoft update service location” and enter the WSUS URL, such as https://wsus01.contoso.com:8531, in both the update service and statistics server fields. Add “Enable client-side targeting” to place the machine in a WSUS computer group.

### How do I stop Windows 11 restarting during working hours?

Enable “Turn off auto-restart for updates during active hours” with your working hours and use the quality and feature update deadline policies with a grace period. Legacy restart policies are not applicable to Windows 11.

### How do I keep Windows 11 on 24H2 and block 25H2?

Enable “Select the target Feature Update version” with product Windows 11 and version 24H2. The device stays on 24H2 until you change the value. This applies to updates from Windows Update, not to feature updates you approve in WSUS.

### How can I check which update policies a PC is using?

Open Settings, Windows Update, Advanced options, Configured update policies, or query HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate with reg query. Get-WindowsUpdateLog builds a readable log of scans.
