Ultraparanoia

articles/


31-12-2024 / How to Disable Updates on Windows 10/11

Today, we'll be having a look at how to effectively disable system updates on Windows 10 and 11.


Introduction


Ah yes, Windows Updates.

If you've been a long-time Windows user, You must know that Microsoft FORCES system updates onto its users, and makes it very difficult to stop them; Short of not connecting Windows machines to the internet at all.


Some people dislike Windows updates due to extremely inopportune timing. Others dislike them because they'd rather stay on one particular version of the software. Not to forget, sometimes a bad update will break a perfectly functional system, Like what happened on the 19th of July, 2024. Those poor airport staffers...

(Okay, TECHNICALLY it wasn't a Windows update, but a bad update to software that ran as a driver in Windows' Kernel ring. A big chunk of public that didn't know exactly what happened blamed it on Windows updates and became a bit skeptical about frequent/automatic software updates, BUT I digress...)

I won't get too deep into the reasons of WHY you would want to disable updates. It's a very controversial topic, sparking lots of heated debates and from what I've seen, annoying many Windows fanboys and power users.


I figure if you've actively SEARCHED for this article, you probably have your reasons for doing so already. Let's get into it.



Blocking Microsoft Domains via the hosts file.
[Fig. 1.1] Blocking out Microsoft (and some other) domains in the hosts file. (It's not very effective against Updates.)


What works and what doesn't work


I've been looking for a way to properly disable updates on Windows for quite some time. I'll review some of the most popular "fixes" I've found.



Eventually, I came to the conclusion that the most effective way to disable updates, short of actually DELETING the update service (Like Ameliorated/AME 10 does, More on that later.), would be to make some Registry edits. So I did a little more research...



Disabling Windows Updates through the Registry



WARNING/DISCLAIMER: MESSING WITH THE REGISTRY CAN POTENTIALLY RESULT IN AN UNUSABLE SYSTEM.

PROCEED AT YOUR OWN RISK.



The Windows Registry is a massive database of configuration options used by the operating system. It can be accessed by running regedit.msc

Now there's a bunch of ways to disable the update service through registry edits, Like setting the pause updates period for 10 years or so. Though I'll be demonstrating a somewhat different approach. This is taken from InControl by Gibson Research Corporation. It's a small software tool that does a few registry edits that trick Windows into thinking it's at the maximum possible version it can update to, and it can't go further.

Sure, you can download the tool, It's freeware. Though I'd recommend making edits manually instead of relying on external software, That way you'll know what you're doing. (This specific tool seems perfectly safe, but there's a lot of malware out there that's disguised as "PC-fixing" software, so it's best to make fixes without using external apps.) So here's what you'll have to do...


1. Open the registry editor. Just execute regedit.msc from the Run dialog box.

2. Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\ and make the Key "WindowsUpdate". Just navigate to that directory and right click in the tree, Create a new key (If it doesn't already exist.).

3. Under WindowsUpdate, add the following entries... (Add the entries, right click and supply values via the Modify button)

4. Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsStore (Create this key if it doesn't exist.)

5. Under WindowsStore, add the following entry... Just one entry under this key.

6. Navigate to HKEY_LOCAL_MACHINE\SYSTEM\Setup\UpgradeNotification (Create this key if it doesn't exist.)

7. Under UpgradeNotification, add the following entry... Again, just one entry.


Registry Edits.
[Fig. 1.2] Disabling Updates through Windows Registry.

And that's pretty much it.

As far as I've tested, this method works. At the time of writing, It effectively disables ALL system updates. If you want to re-enable updates, just delete these six registry entries, and updates should work again as before.



Conclusion


So, we've seen a fairly reliable and effective method to disable Windows updates. But what if you wanted to go further and fully DELETE the Windows Update Service? (Because who knows, Microsoft MIGHT just bypass this "fix" in a future version of Windows.)

And while you're at it, why not get rid of a bunch of bloatware and telemetry/monitoring services aswell? That's where The Open-Source tool, Ameliorated comes in. We'll be taking a deeper dive into this another time; What it does, How it works, and so on.

I certainly hope you found this article useful. Credit where it's due. Be sure to check out Gibson Research Corporation, they seem to have a plethora of privacy and security-oriented tools and services.

I wish you all the best, and a Happy New Year!