How a Windows endpoint behaves when new updates are available. This is the top-level posture an administrator picks for Automatic Updates: it determines whether updates are downloaded, when the user is notified, and whether installs happen on a fixed schedule. Each subsequent value is "more automated" than the previous one. Reference: Windows Update Agent API
Values
| Enum Value | Description |
|---|---|
|
|
Automatic Updates has not been configured on this endpoint. The endpoint typically falls back to the operating system's default behavior, but no explicit configuration is in effect. |
|
|
Automatic Updates is turned off. The endpoint will not check for, download, or install updates on its own. This is generally considered insecure for production endpoints. |
|
|
The endpoint asks the user before downloading any update. Nothing is fetched or installed without explicit user action. Useful on metered or bandwidth- constrained connections but slow to deliver security updates. |
|
|
The endpoint downloads updates automatically but waits for the user to initiate installation. The download is silent; the install is opt-in. |
|
|
The endpoint downloads updates automatically and installs them on the schedule given by scheduledInstallationDay and scheduledInstallationHour. The most "hands-off" setting and the one most commonly enforced by policy. |
|
|
The agent reported a value that does not match any known posture. |
Used by
WindowsAutoUpdateSettingstype: Configuration that controls how the endpoint downloads and installs Windows updates.
Example
Example
"NOT_CONFIGURED"