18.9.102.7 Ensure 'Reschedule Automatic Updates scheduled installations' is set to 'Enabled: 1 minute'

Information

This policy setting specifies the amount of time for Automatic Updates to wait, following system startup, before proceeding with a scheduled installation that was missed previously.

The recommended state for this setting is: Enabled: 1 minute.

Rationale:

Rescheduling Automatic Updates that were not installed on schedule will help ensure security patches get installed. By scheduling these missed updates to install quickly after starting up Windows, it will help to reduce the amount of productivity impact on users, as they would not likely have gotten very far into their workload.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: 1 minute:

Computer Configuration\Administrative Templates\Windows Components\Windows Update\Reschedule Automatic Updates scheduled installations

Note: This Group Policy path is provided by the Group Policy template WindowsUpdate.admx/adml that is included with all versions of the Microsoft Windows Administrative Templates.

Impact:

None - this is the default behavior.

Default Value:

Enabled: 1 minute. (A missed scheduled installation will occur one minute after the computer is next started.)

See Also

https://workbench.cisecurity.org/files/2700

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-2(5), CSCv6|4.5

Plugin: Windows

Control ID: 95cc6cf1cfc011eaf1ea2ee0d38e547bd4f64f228875e46659044cdef36d7641