Intune: Turn Off 'Upgrade To Latest Windows' Prompts
π 2025-10-30
β’
β±οΈ 3 minuten lezen
β’
π’ Should-Have
πΌ Management Samenvatting
Turn off 'Get the latest Windows' prompts - prevents Windows from nagging users to upgrade to newer major version (enterprise controls upgrades centrally).
Aanbeveling
IMPLEMENT
Risico zonder
Low
Risk Score
3/10
Implementatie
2u (tech: 1u)
Van toepassing op:
β Windows 10 β Windows 11
Upgrade prompts = user-initiated chaos: Windows prompts: 'Get Windows 11!' (on Windows 10 devices), 'Upgrade to 24H2!' (on Windows 11 23H2), User clicks: Immediate upgrade download β installation β NO enterprise testing/approval, Risks: App compatibility breaks (untested upgrade), Driver issues (hardware incompatibility), Helpdesk flood (users upgrade β problems β support tickets). Enterprise approach: Centralized upgrades (Intune feature update deployment rings - tested, phased rollout), User prompts: BLOCKED (no self-service upgrades).
PowerShell Modules Vereist
Primary API: Microsoft Graph API Connection:Connect-MgGraph Required Modules: Microsoft.Graph.DeviceManagement
Implementatie
Disable upgrade prompts: Policy: Turn off the offer to update to the latest version of Windows: Enabled, Effect: Windows does NOT show 'Get Windows 11' / 'Upgrade' prompts, Upgrades: Controlled via Intune Update rings (admin-initiated, tested), User: Cannot self-upgrade (centralized control).
Intune Settings Catalog: Windows Update β Turn off the offer to update to the latest version of Windows: Enabled. Effect: No upgrade prompts. Intune controls upgrades (deployment rings).
Compliance
BIO 12.06 (Change management - controlled upgrades), ISO 27001 A.12.6.1.
Monitoring
Gebruik PowerShell-script turn-off-the-offer-to-update-to-the-latest-version-of-windows-is-set-to-enabled.ps1 (functie Invoke-Monitoring) β Controleren.
Remediatie
Gebruik PowerShell-script turn-off-the-offer-to-update-to-the-latest-version-of-windows-is-set-to-enabled.ps1 (functie Invoke-Remediation) β Herstellen.
Compliance & Frameworks
BIO: 12.06.02 -
ISO 27001:2022: A.12.6.1 -
Automation
Gebruik het onderstaande PowerShell script om deze security control te monitoren en te implementeren. Het script bevat functies voor zowel monitoring (-Monitoring) als remediation (-Remediation).