diff --git a/windows/deployment/update/images/waas-wufb-3-rings.png b/windows/deployment/update/images/waas-wufb-3-rings.png new file mode 100644 index 0000000000..5c8b7ec1ee Binary files /dev/null and b/windows/deployment/update/images/waas-wufb-3-rings.png differ diff --git a/windows/deployment/update/images/waas-wufb-fast-ring.png b/windows/deployment/update/images/waas-wufb-fast-ring.png new file mode 100644 index 0000000000..48f91a262f Binary files /dev/null and b/windows/deployment/update/images/waas-wufb-fast-ring.png differ diff --git a/windows/deployment/update/images/waas-wufb-pause.png b/windows/deployment/update/images/waas-wufb-pause.png new file mode 100644 index 0000000000..b8ea2c8df9 Binary files /dev/null and b/windows/deployment/update/images/waas-wufb-pause.png differ diff --git a/windows/deployment/update/images/waas-wufb-pilot-problem.png b/windows/deployment/update/images/waas-wufb-pilot-problem.png new file mode 100644 index 0000000000..b3fbf0aaad Binary files /dev/null and b/windows/deployment/update/images/waas-wufb-pilot-problem.png differ diff --git a/windows/deployment/update/images/waas-wufb-policy-pause.png b/windows/deployment/update/images/waas-wufb-policy-pause.png new file mode 100644 index 0000000000..b8ea2c8df9 Binary files /dev/null and b/windows/deployment/update/images/waas-wufb-policy-pause.png differ diff --git a/windows/deployment/update/images/waas-wufb-slow-ring.png b/windows/deployment/update/images/waas-wufb-slow-ring.png new file mode 100644 index 0000000000..b14aba135f Binary files /dev/null and b/windows/deployment/update/images/waas-wufb-slow-ring.png differ diff --git a/windows/deployment/update/waas-manage-updates-wufb.md b/windows/deployment/update/waas-manage-updates-wufb.md index 99b4a0686e..60a512e49c 100644 --- a/windows/deployment/update/waas-manage-updates-wufb.md +++ b/windows/deployment/update/waas-manage-updates-wufb.md @@ -6,9 +6,9 @@ description: Windows Update for Business lets you manage when devices received u ms.prod: w10 ms.mktglfcycl: manage ms.sitesec: library -author: greg-lindsay +author: jaimeo ms.localizationpriority: medium -ms.author: greglin +ms.author: jaimeo ms.topic: article --- @@ -18,111 +18,89 @@ ms.topic: article **Applies to** - Windows 10 -- Windows 10 Mobile - Windows Server 2016 - Windows Server 2019 +Windows Update for Business is a free service that is available for Windows Pro, Enterprise, Pro for Workstation, and Education editions. + > **Looking for consumer information?** See [Windows Update: FAQ](https://support.microsoft.com/help/12373/windows-update-faq) -Windows Update for Business enables information technology administrators to keep the Windows 10 devices in their organization always up to date with the latest security defenses and Windows features by directly connecting these systems to Windows Update service. You can use Group Policy or MDM solutions such as Intune to configure the Windows Update for Business settings that control how and when Windows 10 devices are updated. In addition, by using Intune, organizations can manage devices that are not joined to a domain at all or are joined to Microsoft Azure Active Directory (Azure AD) alongside your on-premises domain-joined devices. Windows Update for Business leverages diagnostic data to provide reporting and insights into an organization's Windows 10 devices. - -Specifically, Windows Update for Business allows for: - -- The creation of deployment rings, where administrators can specify which devices go first in an update wave, and which ones will come later (to allow for reliability and performance testing on a subset of systems before rolling out updates across the organization). -- Selectively including or excluding drivers as part of Microsoft-provided updates -- Integration with existing management tools such as Windows Server Update Services (WSUS), System Center Configuration Manager, and Microsoft Intune. -- Peer-to-peer delivery for Microsoft updates, which optimizes bandwidth efficiency and reduces the need for an on-site server caching solution. -- Control over diagnostic data level to provide reporting and insights in Windows Analytics. - -Windows Update for Business is a free service that is available for Windows Pro, Enterprise, Pro Education, and Education editions. +Windows Update for Business enables IT administrators to keep the Windows 10 devices in their organization always up to date with the latest security defenses and Windows features by directly connecting these systems to Windows Update service. You can use Group Policy or MDM solutions such as Microsoft Intune to configure the Windows Update for Business settings that control how and when Windows 10 devices are updated. + +Specifically, Windows Update for Business allows for control over update offering and experience to allow for reliability and performance testing on a subset of systems before rolling out updates across the organization as well as a positive update experience for those within your organization. >[!NOTE] ->See [Build deployment rings for Windows 10 updates](waas-deployment-rings-windows-10-updates.md) to learn more about deployment rings in Windows 10. +> To use Windows Update for Business, you must allow devices to access the Windows Update service. -## Update types +## Types of updates managed by Windows Update for Business -Windows Update for Business provides three types of updates to Windows 10 devices: +Windows Update for Business provides management policies for several types of updates to Windows 10 devices: -- **Feature Updates**: previously referred to as *upgrades*, Feature Updates contain not only security and quality revisions, but also significant feature additions and changes; they are released semi-annually. -- **Quality Updates**: these are traditional operating system updates, typically released the second Tuesday of each month (though they can be released at any time). These include security, critical, and driver updates. Windows Update for Business also treats non-Windows updates (such as those for Microsoft Office or Visual Studio) as Quality Updates. These non-Windows Updates are known as *Microsoft Updates* and devices can be optionally configured to receive such updates along with their Windows Updates. -- **Non-deferrable updates**: Currently, antimalware and antispyware Definition Updates from Windows Update cannot be deferred. +- **Feature updates:** previously referred to as upgrades, feature updates contain not only security and quality revisions, but also significant feature additions and changes; they are released semi-annually in the fall and in the spring. +- **Quality updates:** these are traditional operating system updates, typically released the second Tuesday of each month (though they can be released at any time). These include security, critical, and driver updates. Windows Update for Business also treats non-Windows updates (such as those for Microsoft Office or Visual Studio) as quality updates. These non-Windows Updates are known as "Microsoft updates" and can configure devices to receive or not receive such updates along with their Windows updates. +- **Driver updates:** these are non-Microsoft drivers that are applicable to your devices. Driver updates can be turned off by using Windows Update for Business policies. +- **Microsoft product updates**: these are updates for other Microsoft products, such as Office. These updates can be enabled or disabled by using Windows Update for Business policy. + + + +## Offering + +You can control when updates are applied, for example by deferring when an update is installed on a device or by pausing updates for a certain period of time. + +### Manage which updates are offered + +Windows Update for Business offers you the ability to turn on or off both driver and Microsoft product updates. + +- Drivers (on/off): When "on," this policy will not include drivers with Windows Update. +- Microsoft product updates (on/off): When "on" this policy will install udpates for other Microsoft products. + + +### Manage when updates are offered +You can defer or pause the installation of updates for a set period of time. + +#### Defer or pause an update + +A Windows Update for Business administrator can defer the installation of both feature and quality updates from deploying to devices within a bounded range of time from when those updates are first made available on the Windows Update service. You can use this deferral to allow time to validate deployments as they are pushed to devices. Deferrals work by allowing you to specify the number of days after an update is released before it is offered to a device (if you set a feature update deferral period of 365 days, the device will not install a feature update that has been released for less than 365 days). To defer feature updates use the **Select when Preview Builds and Feature Updates are Received** policy. + + +|Category |Maximum deferral | +|---------|---------| +|Feature updates | 365 days | +|Quality updates | 30 days | +|Non-deferrable | none | + +#### Pause an update + +If you discover a problem while deploying a feature or quality update, the IT administrator can pause the update for 35 days to prevent other devices from installing it until the issue is mitigated. + +If you pause a feature update, quality updates are still offered to devices to ensure they stay secure. The pause period for both feature and quality updates is calculated from a start date that you set. + +To pause feature updates use the **Select when Preview Builds and Feature Updates are Received** policy and to pause quality updates use the **Select when Quality Updates are Received** policy. For more information, see [Pause feature updates](waas-configure-wufb.md#pause-feature-updates) and [Pause quality updates](waas-configure-wufb.md#pause-quality-updates). + +#### Select branch readiness level for feature updates + +The branch readiness level enables administrators to specify which channel of feature updates they want to receive. Today there are branch readiness level options for both pre-release and released updates: + +- Windows Insider Program for Business pre-release updates + - Windows Insider Fast + - Windows Insider Slow + - Windows Insider Release Preview +- Semi-annual Channel for released updates -Both Feature and Quality Updates can be deferred from deploying to client devices by a Windows Update for Business administrator within a bounded range of time from when those updates are first made available on the Windows Update Service. This deferral capability allows administrators to validate deployments as they are pushed to all client devices configured for Windows Update for Business. Deferrals work by allowing you to specify the number of days after an update is released before it is offered to a device (if you set a deferral period of 365 days, the update will not be offered until 365 days after that update was released). - -| Category | Maximum deferral | Deferral increments | Example | WSUS classification GUID | -| --- | --- | --- | --- | --- | -| Feature Updates | 365 days | Days | From Windows 10, version 1511 to version 1607 maximum was 180 days.From Windows 10, version 1703 to version 1809, the maximum is 365 days. | 3689BDC8-B205-4AF4-8D4A-A63924C5E9D5 | -| Quality Updates | 30 days | Days | Security updatesDrivers (optional)Non-security updatesMicrosoft updates (Office,Visual Studio, etc.) | 0FA1201D-4330-4FA8-8AE9-B877473B6441EBFC1FC5-71A4-4F7B-9ACA-3B9A503104A0CD5FFD1E-E932-4E3A-BF74-18BF0B1BBD83varies | -| Non-deferrable | No deferral | No deferral | Definition updates | E0789628-CE08-4437-BE74-2495B842F43B | - ->[!NOTE] ->For information about classification GUIDs, see [WSUS Classification GUIDs](https://msdn.microsoft.com/library/ff357803.aspx). - -## Windows Update for Business in various Windows 10 versions - -Windows Update for Business was first available in Windows 10, version 1511. This diagram lists new or changed capabilities and updated behavior in subsequent versions. - - -| Windows 10, version 1511 | 1607 | 1703 | 1709 | 1803 | 1809 | -| --- | --- | --- | --- | --- | --- | -| Defer quality updatesDefer feature updatesPause updates | All 1511 features, plus: **WSUS integration** | All 1607 features, plus **Settings controls** | All 1703 features, plus **Ability to set slow vs. fast Insider Preview branch** | All 1709 features, plus **Uninstall updates remotely** | All 1803 features, plus **Option to use default automatic updates****Ability to set separate deadlines for feature vs. quality updates****Admins can prevent users from pausing updates** -## Managing Windows Update for Business with Group Policy - -The group policy path for Windows Update for Business has changed to correctly reflect its association to Windows Update for Business and provide the ability to easily manage pre-release Windows Insider Preview builds in Windows 10, version 1709. - -| Action | Windows 10 versions prior to 1709 | Windows 10 versions after 1709 | -| --- | --- | --- | -| Set Windows Update for Business Policies | Computer Configuration > Administrative Templates > Windows Components > Windows Update > Defer Windows Update | Computer Configuration > Administrative Templates > Windows Components > Windows Update > Windows Update for Business | -| Manage Windows Insider Preview builds | Computer Configuration/Administrative Templates/Windows Components/Data Collection and Preview Builds/Toggle user control over Insider builds | Computer Configuration/Administrative Templates/Windows Components/Windows Update/Windows Update for Business - *Manage preview builds* | -| Manage when updates are received | Select when Feature Updates are received | Select when Preview Builds and Feature Updates are received (Computer Configuration/Administrative Templates/Windows Components/Windows Update/ Windows Update for Business - **Select when Preview Builds and Feature Updates are received**) | - -## Managing Windows Update for Business with MDM - -Starting with Windows 10, version 1709, the Windows Update for Business settings in MDM were changed to correctly reflect the associations with Windows Update for Business and provide the ability to easily manage Windows Insider Preview builds in 1709. - -| Action | Windows 10 versions prior to 1709 | Windows 10 versions after 1709 | -| --- | --- | --- | -| Manage Windows Insider Preview builds | System/AllowBuildPreview | Update/ManagePreviewBuilds | -| Manage when updates are received | Select when Feature Updates are received | Select when Preview Builds and Feature Updates are received (Update/BranchReadinessLevel) | - -## Managing Windows Update for Business with System Center Configuration Manager - -Starting with Windows 10, version 1709, you can assign a collection of devices to have dual scan enabled and manage that collection with Windows Update for Business policies. Starting with Windows 10, version 1809, you can set a collection of devices to receive the Windows Insider Preview Feature Updates from Windows Update from within System Center Configuration Manager. - -| Action | Windows 10 versions between 1709 and 1809 | Windows 10 versions after 1809 | -| --- | --- | --- | -| Manage Windows Update for Business in Configuration Manager | Manage Feature or Quality Updates with Windows Update for Business via Dual Scan | Manage Insider pre-release builds with Windows Update for Business within System Center Configuration Manager | - -## Managing Windows Update for Business with Windows Settings options -Windows Settings includes options to control certain Windows Update for Business features: - -- [Configure the readiness level](waas-configure-wufb.md#configure-devices-for-the-appropriate-service-channel) for a branch by using **Settings > Update & security > Windows Update > Advanced options** -- [Pause feature updates](waas-configure-wufb.md#pause-feature-updates) by using Settings > Update & security > Window Update > Advanced options - -## Other changes in Windows Update for Business in Windows 10, version 1703 and later releases - - -### Pause and deferral periods - -The maximum pause time period is 35 days for both quality and feature updates. The maximum deferral period for feature updates is 365 days. - -Also, the pause period is calculated from the set start date. For more details, see [Pause Feature Updates](waas-configure-wufb.md#pause-feature-updates) and [Pause Quality Updates](waas-configure-wufb.md#pause-quality-updates). As a result, certain policy keys have different names; see the "Comparing keys in Windows 10, version 1607 to Windows 10, version 1703" section in [Configure Windows Update for Business](waas-configure-wufb.md) for details. +Prior to Windows 10, version 1903, there are two channels for released updates: Semi-annual Channel and Semi-annual Channel (Targeted). Deferral days are calculated against the release date of the chosen channel. Starting with Windows 10, version 1903 there is only the one release channel: Semi-annual Channel. All deferral days will be calculated against a release’s Semi-annual Channel release date. To see release dates, visit [Windows Release Information](https://docs.microsoft.com/windows/release-information/). You can set the branch readiness level by using the **Select when Preview Builds and Feature Updates are Received** policy. In order to use this to manage pre-release builds, first enable preview builds by using the **Manage preview Builds** policy. ## Monitor Windows Updates by using Update Compliance -Update Compliance provides a holistic view of OS update compliance, update deployment progress, and failure troubleshooting for Windows 10 devices. This new service uses diagnostic data including installation progress, Windows Update configuration, and other information to provide such insights, at no extra cost and without additional infrastructure requirements. Whether used with Windows Update for Business or other management tools, you can be assured that your devices are properly updated. +Update Compliance provides a holistic view of operating system update compliance, update deployment progress, and failure troubleshooting for Windows 10 devices. This service uses diagnostic data including installation progress, Windows Update configuration, and other information to provide such insights, at no extra cost and without additional infrastructure requirements. Whether used with Windows Update for Business or other management tools, you can be assured that your devices are properly updated.  For more information about Update Compliance, see [Monitor Windows Updates using Update Compliance](update-compliance-monitor.md). -## Manage Windows Update for Business with Intune - -Microsoft Intune provides the ability to configure Windows Update for Business settings on devices. Intune doesn’t store the updates, but only the update policy assignment. For more information, see [Manage software updates](https://docs.microsoft.com/intune/windows-update-for-business-configure). ## Steps to manage updates for Windows 10 diff --git a/windows/deployment/update/waas-wufb-group-policy.md b/windows/deployment/update/waas-wufb-group-policy.md index bf19d89efa..b447161237 100644 --- a/windows/deployment/update/waas-wufb-group-policy.md +++ b/windows/deployment/update/waas-wufb-group-policy.md @@ -22,337 +22,108 @@ ms.topic: article > **Looking for consumer information?** See [Windows Update: FAQ](https://support.microsoft.com/help/12373/windows-update-faq) ->[!IMPORTANT] ->Due to [naming changes](waas-overview.md#naming-changes), older terms like CB,CBB and LTSB may still be displayed in some of our products. -> ->In the following settings CB refers to Semi-Annual Channel (Targeted), while CBB refers to Semi-Annual Channel. - -Using Group Policy to manage Windows Update for Business is simple and familiar: use the same Group Policy Management Console (GPMC) you use to manage other device and user policy settings in your environment. Before configuring the Windows Update for Business Group Policy settings, consider a [deployment strategy](waas-servicing-strategy-windows-10-updates.md) for updates and feature updates in your environment. - -In Windows 10 version 1511, only Current Branch for Business (CBB) upgrades could be delayed, restricting the Current Branch (CB) builds to a single deployment ring. Windows 10 version 1607, however, has a new Group Policy setting that allows you to delay feature updates for both CB and CBB, broadening the use of the CB servicing branch. - -> [!NOTES] -> The terms *feature updates* and *quality updates* in Windows 10, version 1607, correspond to the terms *upgrades* and *updates* in version 1511. -> -> To follow the instructions in this article, you will need to download and install the relevant ADMX templates for your Windows 10 version. -> See the following articles for instructions on the ADMX templates in your environment. -> -> - [How to create and manage the Central Store for Group Policy Administrative Templates in Windows](https://support.microsoft.com/help/3087759) -> - [Step-By-Step: Managing Windows 10 with Administrative templates](https://blogs.technet.microsoft.com/canitpro/2015/10/20/step-by-step-managing-windows-10-with-administrative-templates/) - - -To use Group Policy to manage quality and feature updates in your environment, you must first create Active Directory security groups that align with your constructed deployment rings. Most customers have many deployment rings already in place in their environment, and these rings likely align with existing phased rollouts of current patches and operating system upgrades. - -## Configure Windows Update for Business in Windows 10 version 1511 - -In this example, you use two security groups to manage your updates: **Ring 4 Broad business users** and **Ring 5 Broad business users #2** from Table 1 in [Build deployment rings for Windows 10 updates](waas-deployment-rings-windows-10-updates.md). - -- The **Ring 4 Broad business users** group contains PCs of IT members who test the updates as soon as they’re released for Windows clients in the Current Branch for Business (CBB) servicing branch. This phase typically occurs after testing on Current Branch (CB) devices. -- The **Ring 5 Broad business users #2** group consists of the first line-of-business (LOB) users, who consume quality updates after 1 week and feature updates 1 month after the CBB release. - ->[!NOTE] ->Although the [sample deployment rings](waas-deployment-rings-windows-10-updates.md) specify a feature update deferral of 2 weeks for Ring 5, deferrals in Windows 10, version 1511 are in increments of months only. -> ->Windows 10 version 1511 does not support deferment of CB builds of Windows 10, so you can establish only one CB deployment ring. In version 1607 and later, CB builds can be delayed, making it possible to have multiple CB deployment rings. - - Complete the following steps on a PC running the Remote Server Administration Tools or on a domain controller. - - ### Configure the Ring 4 Broad business users deployment ring for CBB with no deferral - -1. Open GPMC (gpmc.msc). - -2. Expand **Forest** > **Domains** > *your domain*. - -3. Right-click *your domain* and select **Create a GPO in this domain, and Link it here**. - -  - -4. In the **New GPO** dialog box, type **Windows Update for Business - CBB1** for the name of the new GPO. - - >[!NOTE] - >In this example, you’re linking the GPO to the top-level domain. This is not a requirement: you can link the Windows Update for Business GPOs to any organizational unit (OU) that’s appropriate for your Active Directory Domain Services (AD DS) structure. - -5. Right-click the **Windows Update for Business - CBB1** GPO, and then click **Edit**. - -  - -6. In the Group Policy Management Editor, go to **Computer Configuration** > **Policies** > **Administrative Templates** > **Windows Components** > **Windows Update**. -7. Right-click **Defer Upgrades and Updates**, and then click **Edit**. +## Overview -  - - In the **Defer Upgrades and Updates** Group Policy setting configuration, you see several options: - - **Enable/Disable Deferred Updates**. Enabling this policy setting sets the receiving client to the CBB servicing branch. Specifically disabling this policy forces the client into the CB servicing branch, making it impossible for users to change it. - - **Defer upgrades for the following**. This option allows you to delay feature updates up to 8 months, a number added to the default CBB delay (approximately 4 months from CB). By using Windows Update for Business, you can use this option to stagger CBB feature updates, making the total offset up to 12 months from CB. - - **Defer updates for the following**. This option allows you to delay the installation of quality updates on a Windows 10 device for up to 4 weeks, allowing for phased rollouts of updates in your enterprise, but not all quality updates are deferrable with this option. Table 1 shows the deferment capabilities by update type. - - **Pause Upgrades and Updates**. Should an issue arise with a feature update, this option allows a one-time skip of the current month’s quality and feature update. Quality updates will resume after 35 days, and feature updates will resume after 60 days. For example, deploy this setting as a stand-alone policy to the entire organization in an emergency. - - Table 1 summarizes the category of update in Windows 10 and how long Windows Update for Business can defer its installation. - - **Table 1** - -
Category | -Maximum deferral | -Deferral increments | -Classification type | -Classification GUID | -
---|---|---|---|---|
OS upgrades | -8 months | -1 month | -Upgrade | -3689BDC8-B205-4AF4-8D4A-A63924C5E9D5 | -
OS updates | -4 weeks | -1 week | -Security updates | -0FA1201D-4330-4FA8-8AE9-B877473B6441 | -
Drivers | -EBFC1FC5-71A4-4F7B-9ACA-3B9A503104A0 | -|||
Updates | -CD5FFD1E-E932-4E3A-BF74-18BF0B1BBD83 | -|||
Other/non-deferrable | -No deferral | -No deferral | -Definition updates | -E0789628-CE08-4437-BE74-2495B842F43B | -
Category | -Maximum deferral | -Deferral increments | -Example | -Classification GUID | -
---|---|---|---|---|
Feature Updates | -180 days | -Days | -From Windows 10, version 1511 to version 1607 | -3689BDC8-B205-4AF4-8D4A-A63924C5E9D5 | -
Quality Updates | -30 days | -Days | -Security updates | -0FA1201D-4330-4FA8-8AE9-B877473B6441 | -
Drivers (optional) | -EBFC1FC5-71A4-4F7B-9ACA-3B9A503104A0 | -|||
Non-security updates | -CD5FFD1E-E932-4E3A-BF74-18BF0B1BBD83 | -|||
Microsoft updates (Office, Visual Studio, etc.) | varies | |||
Non-deferrable | -No deferral | -No deferral | -Definition updates | -E0789628-CE08-4437-BE74-2495B842F43B | -
Summary | Originating update | Status | Last updated |
Some applications may fail to run as expected on clients of AD FS 2016 Some applications may fail to run as expected on clients of Active Directory Federation Services 2016 (AD FS 2016) See details > | OS Build 14393.2941 April 25, 2019 KB4493473 | Mitigated | June 07, 2019 04:25 PM PT |
Opening Internet Explorer 11 may fail Internet Explorer 11 may fail to open if Default Search Provider is not set or is malformed. See details > | OS Build 14393.2999 May 23, 2019 KB4499177 | Mitigated | June 05, 2019 07:51 PM PT |
Some applications may fail to run as expected on clients of AD FS 2016 Some applications may fail to run as expected on clients of Active Directory Federation Services 2016 (AD FS 2016) See details > | OS Build 14393.2941 April 25, 2019 KB4493473 | Mitigated | June 04, 2019 05:55 PM PT |
Devices running Windows Server 2016 with Hyper-V seeing Bitlocker error 0xC0210000 Some devices running Windows Server with Hyper-V enabled may start into Bitlocker recovery with error 0xC0210000 See details > | OS Build 14393.2969 May 14, 2019 KB4494440 | Mitigated | May 23, 2019 09:57 AM PT |
Cluster service may fail if the minimum password length is set to greater than 14 The cluster service may fail to start with the error “2245 (NERR_PasswordTooShort)” if the Group Policy “Minimum Password Length” is configured with greater than 14 characters. See details > | OS Build 14393.2639 November 27, 2018 KB4467684 | Mitigated | April 25, 2019 02:00 PM PT |
Issue using PXE to start a device from WDS There may be issues using the Preboot Execution Environment (PXE) to start a device from a Windows Deployment Services (WDS) server configured to use Variable Window Extension. See details > | OS Build 14393.2848 March 12, 2019 KB4489882 | Mitigated | April 25, 2019 02:00 PM PT |
Details | Originating update | Status | History |
Some applications may fail to run as expected on clients of AD FS 2016 Some applications may fail to run as expected on clients of Active Directory Federation Services 2016 (AD FS 2016) after installation of KB4493473 on the server. Applications that may exhibit this behavior use an IFRAME during non-interactive authentication requests and receive X-Frame Options set to DENY. Affected platforms:
Workaround: You can use the Allow-From value of the header if the IFRAME is only accessing pages from a single-origin URL. On the affected server, open a PowerShell window as an administrator and run the following command: set-AdfsResponseHeaders -SetHeaderName X-Frame-Options -SetHeaderValue \"allow-from https://example.com\" Next steps: We are working on a resolution and will provide an update in an upcoming release. Back to top | OS Build 14393.2941 April 25, 2019 KB4493473 | Mitigated | Last updated: June 07, 2019 04:25 PM PT Opened: June 04, 2019 05:55 PM PT |
Opening Internet Explorer 11 may fail Internet Explorer 11 may fail to open if Default Search Provider is not set or is malformed. Affected platforms:
Workaround: To set the Default Search Provider, use the following steps:
Next steps: We are working on a resolution and estimate a solution will be available in mid-June. Back to top | OS Build 14393.2999 May 23, 2019 KB4499177 | Mitigated | Last updated: June 05, 2019 07:51 PM PT Opened: June 05, 2019 05:49 PM PT |
Some applications may fail to run as expected on clients of AD FS 2016 Some applications may fail to run as expected on clients of Active Directory Federation Services 2016 (AD FS 2016) after installation of KB4493473 on the server. Applications that may exhibit this behavior use an IFRAME during non-interactive authentication requests and receive X-Frame Options set to DENY. Affected platforms:
Workaround: You can use the Allow-From value of the header if the IFRAME is only accessing pages from a single-origin URL. On the affected server, open a PowerShell window as an administrator and run the following command: set-AdfsResponseHeaders -SetHeaderName X-Frame-Options -SetHeaderValue \"allow-from https://example.com\" Next steps: We are working on a resolution and will provide an update in an upcoming release. Back to top | OS Build 14393.2941 April 25, 2019 KB4493473 | Mitigated | Last updated: June 04, 2019 05:55 PM PT Opened: June 04, 2019 05:55 PM PT |
Details | Originating update | Status | History |
System may be unresponsive after restart if ArcaBit antivirus software installed ArcaBit has confirmed this issue is not applicable to Windows 10, version 1809 (client or server). Microsoft and ArcaBit have identified an issue on devices with ArcaBit antivirus software installed that may cause the system to become unresponsive upon restart. Affected platforms:
Workaround: ArcaBit has released an update to address this issue for affected platforms. For more information, see the ArcaBit support article. Resolution: This issue has been resolved. ArcaBit has confirmed this issue is not applicable to Windows 10, version 1809 (client or server). Back to top | OS Build 17763.437 April 09, 2019 KB4493509 | Resolved | Resolved: May 08, 2019 03:30 PM PT Opened: April 09, 2019 10:00 AM PT |
Current status as of June 6, 2019: - Windows 10, version 1903 is available for any user who manually selects “Check for updates” via Windows Update. The recommended servicing status is Semi-Annual Channel.
+ Note follow @WindowsUpdate to find out when new content is published to the release information dashboard. Windows 10, version 1903 is available for any user who manually selects “Check for updates” via Windows Update. The recommended servicing status is Semi-Annual Channel.
Note follow @WindowsUpdate to find out when new content is published to the release information dashboard. |
\"Close other apps, error code: 0XA00F4243.”
or
or
AMD Ryzen™ or AMD Ryzen™ Threadripper™ configured in SATA or NVMe RAID mode.
“A driver is installed that causes stability problems on Windows. This driver will be disabled. Check with your software/driver provider for an updated version that runs on this version of Windows.”
Summary | Originating update | Status | Last updated |
IE11 may stop working when loading or interacting with Power BI reports Power BI reports that contain line charts with markers may cause Internet Explorer 11 to stop working See details > | May 14, 2019 KB4499164 | Mitigated | June 07, 2019 02:57 PM PT |
System may be unresponsive after restart with certain McAfee antivirus products Devices with McAfee Endpoint Security Threat Prevention 10.x, Host Intrusion Prevention 8.0, or VirusScan Enterprise 8.8 may be slow or unresponsive at startup. See details > | April 09, 2019 KB4493472 | Mitigated | April 25, 2019 02:00 PM PT |
Unable to access some gov.uk websites gov.uk websites that don’t support “HSTS” may not be accessible See details > | May 14, 2019 KB4499164 | Resolved KB4505050 | May 18, 2019 02:00 PM PT |
System may be unresponsive after restart if ArcaBit antivirus software installed Devices with ArcaBit antivirus software installed may become unresponsive upon restart. See details > | April 09, 2019 KB4493472 | Resolved | May 14, 2019 01:23 PM PT |
Details | Originating update | Status | History |
IE11 may stop working when loading or interacting with Power BI reports Internet Explorer 11 may stop working when loading or interacting with Power BI reports that have line charts with markers. This issue may also occur when viewing other content that contains Scalable Vector Graphics (SVG) markers. Affected platforms:
Workaround: To mitigate the issue with Power BI reports, the report needs to be republished with markers turned off. Markers can be turned off by selecting the line chart that is having issues and going to the Visualizations pane. Then on the Format tab under Shapes, set the Show marker slider to off. Next steps: We are working on a resolution and estimate a solution will be available in mid-July. Back to top | May 14, 2019 KB4499164 | Mitigated | Last updated: June 07, 2019 02:57 PM PT Opened: June 07, 2019 02:57 PM PT |
Summary | Originating update | Status | Last updated |
IE11 may stop working when loading or interacting with Power BI reports Power BI reports that contain line charts with markers may cause Internet Explorer 11 to stop working See details > | May 14, 2019 KB4499151 | Mitigated | June 07, 2019 02:57 PM PT |
Japanese IME doesn't show the new Japanese Era name as a text input option If previous dictionary updates are installed, the Japanese input method editor (IME) doesn't show the new Japanese Era name as a text input option. See details > | April 25, 2019 KB4493443 | Mitigated | May 15, 2019 05:53 PM PT |
Issue using PXE to start a device from WDS There may be issues using the Preboot Execution Environment (PXE) to start a device from a Windows Deployment Services (WDS) server configured to use Variable Window Extension. See details > | March 12, 2019 KB4489881 | Mitigated | April 25, 2019 02:00 PM PT |
Certain operations performed on a Cluster Shared Volume may fail Certain operations, such as rename, performed on files or folders on a Cluster Shared Volume (CSV) may fail with the error, “STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)”. See details > | January 08, 2019 KB4480963 | Mitigated | April 25, 2019 02:00 PM PT |
Details | Originating update | Status | History |
IE11 may stop working when loading or interacting with Power BI reports Internet Explorer 11 may stop working when loading or interacting with Power BI reports that have line charts with markers. This issue may also occur when viewing other content that contains Scalable Vector Graphics (SVG) markers. Affected platforms:
Workaround: To mitigate the issue with Power BI reports, the report needs to be republished with markers turned off. Markers can be turned off by selecting the line chart that is having issues and going to the Visualizations pane. Then on the Format tab under Shapes, set the Show marker slider to off. Next steps: We are working on a resolution and estimate a solution will be available in mid-July. Back to top | May 14, 2019 KB4499151 | Mitigated | Last updated: June 07, 2019 02:57 PM PT Opened: June 07, 2019 02:57 PM PT |
Summary | Originating update | Status | Last updated |
IE11 may stop working when loading or interacting with Power BI reports Power BI reports that contain line charts with markers may cause Internet Explorer 11 to stop working See details > | May 14, 2019 KB4499171 | Mitigated | June 07, 2019 02:57 PM PT |
Japanese IME doesn't show the new Japanese Era name as a text input option If previous dictionary updates are installed, the Japanese input method editor (IME) doesn't show the new Japanese Era name as a text input option. See details > | April 25, 2019 KB4493462 | Mitigated | May 15, 2019 05:53 PM PT |
Issue using PXE to start a device from WDS There may be issues using the Preboot Execution Environment (PXE) to start a device from a Windows Deployment Services (WDS) server configured to use Variable Window Extension. See details > | March 12, 2019 KB4489891 | Mitigated | April 25, 2019 02:00 PM PT |
Certain operations performed on a Cluster Shared Volume may fail Certain operations, such as rename, performed on files or folders on a Cluster Shared Volume (CSV) may fail with the error, “STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)”. See details > | January 08, 2019 KB4480975 | Mitigated | April 25, 2019 02:00 PM PT |
Details | Originating update | Status | History |
IE11 may stop working when loading or interacting with Power BI reports Internet Explorer 11 may stop working when loading or interacting with Power BI reports that have line charts with markers. This issue may also occur when viewing other content that contains Scalable Vector Graphics (SVG) markers. Affected platforms:
Workaround: To mitigate the issue with Power BI reports, the report needs to be republished with markers turned off. Markers can be turned off by selecting the line chart that is having issues and going to the Visualizations pane. Then on the Format tab under Shapes, set the Show marker slider to off. Next steps: We are working on a resolution and estimate a solution will be available in mid-July. Back to top | May 14, 2019 KB4499171 | Mitigated | Last updated: June 07, 2019 02:57 PM PT Opened: June 07, 2019 02:57 PM PT |