Applications and updates · GraphQL type

WindowsAutoUpdateSettings type

Configuration that controls how the endpoint downloads and installs Windows updates. Many of these fields reflect settings normally configured by an administrator through Group Policy or Windows Update for Business. A null value means the agent could not read that particular setting on this endpoint.

Fields

Field Name Description
notificationLevel - WindowsUpdateNotificationLevel How the endpoint behaves when new updates are available — from "do nothing" through fully automated downloads and scheduled installs. See WindowsUpdateNotificationLevel.
readOnly - Boolean Whether the user of the endpoint is prevented from changing the update settings. When true, the configuration is locked down — typically because an administrator has enforced it through policy. When false, the user may have changed it.
required - Boolean Whether Automatic Updates is mandated for this endpoint by administrative policy. When true, the service cannot be turned off locally even by an administrator.
scheduledInstallationDay - WindowsScheduledInstallationDay Day of the week on which scheduled installations run. Only meaningful when notificationLevel is SCHEDULED_INSTALL. See WindowsScheduledInstallationDay.
scheduledInstallationHour - Int Hour of the day (0–23, local time on the endpoint) at which scheduled installations run. Only meaningful when notificationLevel is SCHEDULED_INSTALL. For example, a value of 3 means installs start at 03:00 local time.
includeRecommendedUpdates - Boolean Whether the endpoint includes optional / recommended updates in addition to required security updates. When true, the endpoint downloads driver updates and other recommended improvements alongside required ones.
featuredUpdatesEnabled - Boolean Whether the endpoint surfaces featured updates promoted by Microsoft. Rarely used on modern Windows versions and typically false; included for completeness.
nonAdministratorsElevated - Boolean Whether standard (non-administrator) users may approve and install updates without administrator elevation. When true, standard users can install updates themselves; when false, an administrator must approve.

Used by

  • SoftwareUpdatePreferencesWindows type: Windows-specific software update preferences and the list of updates the endpoint has discovered but has not yet installed.

Example

Example

{
  "notificationLevel": "NOT_CONFIGURED",
  "readOnly": false,
  "required": true,
  "scheduledInstallationDay": "EVERY_DAY",
  "scheduledInstallationHour": 987,
  "includeRecommendedUpdates": true,
  "featuredUpdatesEnabled": false,
  "nonAdministratorsElevated": true
}