How to block user access to Windows Update on Windows Server

This article describes how to block user access to Windows Update on Windows Server.

Applies to:   Windows Server 2019, Windows Server 2016
Original KB number:   4014345

Symptoms

The default settings in Windows Server allow user who is not an administrator to scan for and apply Windows Updates. Administrators may want to change this setting to limit access to Windows Updates, especially in Remote Desktop Services Host deployments.

More Information

To change this setting, use the Group Policy "Remove access to use all Windows update features." The full path to this Group Policy is:
Computer Configuration\Administrative Templates\Windows Components\Windows update\Remove access to use all Windows update features

Data collection

If you need assistance from Microsoft support, we recommend you collect the information by following the steps mentioned in Gather information by using TSS for deployment-related issues.