How to block user access to Windows Update on Windows Server

Applies to: Windows Server version 1803Windows Server version 1709Windows Server version 1803


The default settings in Windows Server allow user who are not an administrator to scan for and apply Windows Updates. Administrators may want to change this setting to limit access to Windows Updates, especially in Remote Desktop Services Host deployments.

More Information

To change this setting, use the Group Policy "Remove access to use all Windows update features." The full path to this Group Policy is:

Computer Configuration\Administrative Templates\Windows Components\Windows update\Remove access to use all Windows update features