Defender Updates - Automatic OK to download and install?

Page 1 of 2 12 LastLast

  1. Posts : 45
    Windows 10 64 bit
       #1

    Defender Updates - Automatic OK to download and install?


    I'm using Windows 10 Pro 18363.778. I would like to give an automatic approval to Windows to download and install Security Intelligence Updates for Windows Defender Antivirus, without any human interaction. But I'd also like to keep the deferrals I have set for quality and feature updates. Is there a way to do this?
    Last edited by abacus; 22 Apr 2020 at 14:56.
      My Computer


  2. Posts : 1,612
    11, 10, 8.1 and 7 all Professional versions, and Linux Mint
       #2

    1. It depends on how you have set deferrals
    If for instance you have paused updates then that pause, as far as I know, does not apply to Defender updates
    Enable or Disable Pause Updates Feature in Windows 10

    2. That said although I know you have asked for how to set automatic - it is I think far easier to simply open settings
    update and security
    Windows security on left pane
    Virus and Threat Protection on main pane
    and scroll down on new window to
    check for updates

    3. The reason I say that is because even if you could configure it by batch file or in GPEditor
    I think you may find that Windows 10 will either simply ignore those settings OR you will start to experience problems

    4. Actually I think you may be better leaving ALL updates for Windows ON
    and then setting active hours to suit
    that is settings Windows update
    so that the device is not restarted during those hours, even if you are only on desktop

    5. AND setting bandwidth which is
    Windows update
    advanced options
    delivery optimization
    advanced option on that window and then you get to bandwidth settings for background and foreground

    6. Hope you find it useful. Not as I said what you asked, but I think it is the best method.
      My Computer


  3. Posts : 31,663
    10 Home x64 (22H2) (10 Pro on 2nd pc)
       #3

    abacus said:
    I'm using Windows 10 Pro 18363.778. I would like to give an automatic approval to Windows to download and install Security Intelligence Updates for Windows Defender Antivirus, without any human interaction. But I'd also like to keep the deferrals I have set for quality and feature updates. Is there a way to do this?

    I presume you mean that in advanced settings you have set a number of days to defer quality updates and to defer feature updates and that you have not made any other changes, such as configuring Automatic Updates in the group policy editor.

    Windows Update - Defer Feature and Quality Updates in Windows 10

    I have just set those two defer options on my Pro system, then checked for updates. The latest definition update was downloaded, so those two setting appear to have no effect on defender definitions. Yours should continue to download automatically regardless of either of those defer settings.
      My Computers


  4. Posts : 45
    Windows 10 64 bit
    Thread Starter
       #4

    [QUOTE=Bree;1893156]I presume you mean that in advanced settings you have set a number of days to defer quality updates and to defer feature updates and that you have not made any other changes, such as configuring Automatic Updates in the group policy editor... /QUOTE]

    That's true. What happens is that in the notification area, I get an icon and upon clicking it I get a message that there are updates which are for Windows Defender. I can click "update" and the update occurs. I'd rather not get that notification and get the updates without having to click "update"; but I want to keep deferring feature and quality updates.
      My Computer


  5. Posts : 7,607
    Windows 10 Home 20H2
       #5

    abacus said:
    I'd rather not get that notification and get the updates without having to click "update"
    I use Task Scheduler to run a VBScript file that will automatically install Windows Defender updates in the background.

    Reference: Using CMD script and VBScript to control Windows Update

    The scripts make it possible to do the following:
    abacus said:
    I want to keep deferring feature and quality updates.
      My Computer


  6. Posts : 31,663
    10 Home x64 (22H2) (10 Pro on 2nd pc)
       #6

    abacus said:
    Bree said:
    I presume you mean that in advanced settings you have set a number of days to defer quality updates and to defer feature updates and that you have not made any other changes, such as configuring Automatic Updates in the group policy editor...
    That's true. What happens is that in the notification area, I get an icon and upon clicking it I get a message that there are updates which are for Windows Defender. I can click "update" and the update occurs. I'd rather not get that notification and get the updates without having to click "update"; but I want to keep deferring feature and quality updates.

    Are you sure you haven't run gpedit and configured Automatic Updates at some time in the past? That is the behaviour I get for all my updates (by choice) because I have Automatic Updates configured for 'Notify to download and auto-install'. That policy should be set to 'Not Configured' for the default daily check, automatic download and automatic install.

    Look in gpedit under Local Computer Policy > Computer Configuration >Administrative Templates > Windows Components > Windows Update.

    Defender Updates - Automatic OK to download and install?-automatic-updates-gp.png
      My Computers


  7. Posts : 45
    Windows 10 64 bit
    Thread Starter
       #7

    Bree said:
    Are you sure you haven't run gpedit and configured Automatic Updates at some time in the past? That is the behaviour I get for all my updates (by choice) because I have Automatic Updates configured for 'Notify to download and auto-install'. That policy should be set to 'Not Configured' for the default daily check, automatic download and automatic install....
    Well, I was sure but I was wrong. I have that policy set to 2 - Notify for download and auto install.
    If I change that policy to "Not Configured", leave my update deferrals set to 365 for feature updates and 30 for quality updates, would the effect be to retain the deferrals, and to have automatic installation ONLY of Defender updates? Or would other stuff install automatically also? If other stuff would install occasionally, is there any reason not to allow that? Note: I like feature and quality updates to be beta tested by others before I install them.
      My Computer


  8. Posts : 31,663
    10 Home x64 (22H2) (10 Pro on 2nd pc)
       #8

    abacus said:
    Well, I was sure but I was wrong. I have that policy set to 2 - Notify for download and auto install.
    thought that might be the case....
    If I change that policy to "Not Configured", leave my update deferrals set to 365 for feature updates and 30 for quality updates, would the effect be to retain the deferrals, and to have automatic installation ONLY of Defender updates? Or would other stuff install automatically also? If other stuff would install occasionally, is there any reason not to allow that? Note: I like feature and quality updates to be beta tested by others before I install them.
    With that policy set to 'not configured' windows update will by default automatically check for updates approximately* once a day and install any it finds automatically. Even the Quality and Feature updates will install automatically, but they will not be found by windows update until the defer period you have set for them has expired.

    The are very few other types of updates, most of them being for security purposes, like the defender definitions. The others that come to mind are Defender platform updates, Flash updates and of course the Malicious Software Removal tool. I would not expect your defer settings to apply to them either (just to Quality/Feature updates) but I can't see any harm in letting them install.


    * to be precise, it's 22 hours, plus a random delay of up to 4 hours (to spread the load on the update servers).
      My Computers


  9. Posts : 45
    Windows 10 64 bit
    Thread Starter
       #9

    Thanks to all who posted; all were helpful and useful ideas. I'm going to try Bree's ideas first. I'll post back results.
      My Computer


  10. Posts : 45
    Windows 10 64 bit
    Thread Starter
       #10

    Defender Updates now install automatically with Bree's suggested change in Group Policy. Thanks!
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 08:24.
Find Us




Windows 10 Forums