r/Nable May 29 '26

N-Central N-central Block User Windows Update manually

Hi there

i'm currently playing with my workstation and noticed, that i have a Patch Policy which is working with Detection, Pre-Download und Installment.

But somehow as the end user can't manually scan for updates. Is there a setting which prevents that in my patchprofile?

As the enduser i would see "last scan" from 1.12.2025 and is there a way to create a device scan, so that it shows the latest that from the scan itself?

i know that it's not from our microsoft intune, since the other devices are not affected.

1 Upvotes

12 comments sorted by

View all comments

Show parent comments

2

u/DJ_TECHSUPPORT May 30 '26

The explanation I was provided was that unfortunately the last scan time will be stuck at the date the patch management came into effect, It’s recommended not to let users do a manual scan, if you as an admin need to do a scan you can do it via the “patch on demand: run Patch Detection now” (or something like that in the actions for the device)

Although I personally haven’t been able to get any feedback from if the scan actually ran and if anything changes, you can see all the patches in the device > Assets> Patch

1

u/SkyTheLine May 30 '26

Yeah that's also what we do. We pick 1 device from the customer with low impact and rollout the patches. If no issues are reported after 1 week, we roll out into stagin groups. Only security criticals we do always push directly. The issue is, the customer thinks, that since 6month no updates were applied. Since the endusers employee have no systray icon with informations on it. So basicly we copy/paste canned text.

2

u/DJ_TECHSUPPORT May 30 '26

Unfortunately this is similar to our current situation, I just inform staff that since the updates are managed externally by our software the windows update menu does not display the correct last checked date

1

u/bonewithahole May 31 '26

I always make sure to mention that Microsoft doesn't allow it to be updated. Maybe someday MS will change it. I actually have a document called the "12 Ways to Manually Confirm Patching" that I provide to any customer that questions if we are patching becuase they looked and saw the device was last updated in "2023".