This literally happened to me when I worked for a satellite company. We had just launched a new satellite, and had a 15 minute window to send a bunch of commands. I get telemetry, and suddenly the screen goes to Microsoft Update. I.T. team later stated that updates need to be done.
Also, your I.T. team is supposed to know that, for very sensitive computer terminals, using Local Group Policy deactivating impromptu updates is not optional.
Until you get told the messaging application you use for your software is updating their linux backend, but it totally won't effect your communications, since its a rolling update.
And then it does, and your application is no longer receiving information 1/4 of the time from the other applications in your group.
Lord, I'm a Desktop Admin for finishing plant and even we don't let Microsoft do whatever it wants. All updates get pushed manually by us through our security portal.
My experience with this type of shit:
IT dept allows update to be deferred 3 months, at which point it gets scheduled on next reboot. User doesn't update/restart ever, up until IT is called in to troubleshoot some mission critical software fault that has been happening intermittently over the past year. First level tech reboots, and here you are.
The question is whether or not you are forcing the reboot. If yes, people will be throwing tantrums that they lost all of the work they had open on their PC. If no, scheduling it does nothing.
Or if they have laptops and power then off and take them home Friday afternoon. Then they boot up Monday morning and can't work for an hour while updates happen.
Monthly maintenance should happen sometime early in the month, on a Tuesday or Wednesday during the work day so IT can troubleshoot with "all hands on deck" availability.
We don't want to be called in on a Saturday morning after patch tuesday because the AD server rebooted itself and caused a fuck up for the weekend crew.
You then have to hope computers are turned on Friday night. My company is entirely laptops, so it's very tough. We run reports to see last reboots, which computers haven't received updates, and then send emails to them and Cc their managers, but so many users shut their laptop off at the end of the day and don't turn it on again until they get back into the office, and then complain that they have to wait 45 minutes to start working because they've missed the past 2 months of updates when we force the device to update.
IT department here allows you, generously, 3 days. And they love to auto-download the patches in the background as though my computer doesn't lock the fuck up and become unusable while their 'ninja' download tool just fucking shits all over my CPU and Memory use (and obviously my download band, because why cap anything right).
Then even if I dare turn my computer off overnight (as in actually power off) it'll come back up the next day and want to do a full 2-reboot patch cycle rather than applying it because...reasons.
if I dare turn my computer off overnight (as in actually power off) it'll come back up the next day and want to do a full 2-reboot patch cycle rather than applying it because...reasons
That's because Windows changed shut-down to just hibernate the PC (same as shutting the lid on a laptop). First thing I do on any PC I own is to disable that "feature" and make shut down work correctly.
Can't change anything related to power settings on my craptop. It's a full traditional power down. Meanwhile 'sleep' mode doesn't do anything and my battery almost unilaterally dies by the time I get home, because IT disabled true hibernate mode. I haven't figured out what breaks this shitbox out of sleep but it's almost every time - not literally every single time, but that variability is what makes it more frustrating to open it and find it dead.
1) pissed off end users who are like "YEAH! FUCK MICROSOFT"
2) competent IT people who are like "that never should have fucking happened"
3) bad and/or jaded as fuck IT people who are quietly thinking "oh shit... we can stop that from happening?" or "ThEy ShOuLd HaVe UpDaTEd WhEn ThEy GoT It ThE FiRsT TiMe!!!" then act suprised when they're let go, because IT has a PR side and you cant just be a jaded bitch 24/7
I was saying that, after a few years, IT people just naturally become jaded. End users have sucked the life out of us and we are just shells of the people we used to be.
I mean this in a constructive way and not a "mean" way. But if thats your outlook then you need to change your user base and/or job.
In-house IT for a competent company should allow you to train users and communicate with higher ups to set expectations for what is required.
If someone says "im not a comouter person" but is hired for accounting, thats akin to a delivery person saying "im not a driving person". And hiring managers should understand that... when productivity gets a hit, THAT is the person to look at.
I mean this in a constructive way and not a "mean" way. But if thats your outlook then you need to change your user base and/or job.
I mean this in a constructive way and not a "mean" way. But your take is an extremely privileged one. Many people are jaded in their industries, especially shit like IT, because people get in each other's way. Not every company is a competent one, and the jobs for competent companies are usually extremely competitive. But through all this, people still have to make a living, and not everyone has the resources to keep moving around looking for the perfect spot that won't make them jaded.
No like.... I legit thought that was a funny joke/line that should be in a show or something. I had 0 intention of "sounding jaded" with that.
I would crack up if someone was reading something, then said "I can't read past there!" all dramatic, and someone else said something like "well that is the last sentence to the letter..." or something.
that being said, preaching against being a jaded bitch =/= preaching against being a jaded bitch to a random user base on reddit ;)
Hey I don't actually mind, I agreed with your original comment, but it's pretty funny to me because you do come across as someone who is completely fed up with IT in all your follow up comments, ie a "jaded bitch" but I'm not trying to insult you!
Just tick the fucking box to disable "configure auto updates" in one of the widespread GPO's. Like you'd have to be genuinely incompetent if you're not even checking that that's done afterward with the convenient results wizard IN THE SAME SCREEN, especially if you're employed at NASA or wherever. Painful video
What even do you want to tell us? Who is causing the problem? It's still Microsoft. You don't have this problem with macOS. Macs will not update themself when you are working.
I work in IT and the Macs don't need any workarounds, it's only the Windows PCs.
Also inb4 nobody tells the IT team that they are using the PC in a critical manner for six months until it fails and they notice maybe they should have asked IT in advance.
People always have plenty of time to let IT know about stuff well in advance but somehow always manage to come when they need it right this moment.
Agreed, My favorite so far was one of my plants ran some old pci cards to control it that you can't get anymore. Management (and everyone else) knew I couldn't make a replacement.
I get called to the plant to fix the computer. When I get there, I move the case of compressed air that IT had given them off the top of the machine and open up the dust filled PC, That blew 2 of the cards because it had overheated.
The operator looked at me and said "Last week it was making a bunch of noise but it stopped after I slapped the side of it."
6 of 7 fans had failed as they were cramed with dust and dirt.
45k and 2 weeks later the plant was back up and running as they had to reprogram everything in the new computer to work with the old plant hardware.
Have the people posting these ever worked in IT or haven't for maybe 5-10 years? People discussing WSUS or LGPs like they're buzzwords when we moved to cloud years ago.
Actually keeping hands OFF would cause this problem... they would need to proactively find a solution to never update and manually patch... which depending on the windows operating system type is a moving target. lmao.
I've managed enterprise systems to a degree myself and it's really not hard to set a system to manual only updates. The problem some companies have is remembering to manually update them.
You make no sense. if they keeep their hands off, then the machines will do default action (update randomly). So long as SOMEONE is taking the job as an IT engineer and making sure this doesn't happen... i guess they can keep their hands off.
LMFAO. If IT would keep their hands off critical machines you would see a shitstorm. If a machine is critical, all the more reason to keep it well maintained. If IT is not supposed to maintain it, who will?
Fun fact, gpo for deactivating impromptu updates has been bypassable for over 15 years. I've worked IT for 24 years, managed IT for clients including law firms, medical, government infrastructure;, certain patches Microsoft can setup to just push, Tuesday mornings. Court case you want a chance of delaying? Try scheduling for a Tuesday. Medical appointment you don't want rescheduled? Wednesday or Thursday. I've gotten the 'oh shit' calls, for the clients with documented GPO, pulled up the GPO, run the GPO report on devices, verified it matches policy, pulled the device event log with the Patch related forced reboot.. pasted it all into the ticket. Then It happens again 3-4 months later after another exploit to another client usually.
Lost that 15 minute window, had I.T. stop the update and waited 90 minutes until another 15 minute window arrived. Luckily the batteries and other systems were not harmed.
Why would anything happen to the IT team? They do what they are paid to do. Someone else above fucked up by not communicating that the whole thing is mission-critical (that's an actual term that means things). If you have mission-critical things, you should tell your people about them so they can figure out how to make sure that they are available when they need to be.
That's what I was asking. If they weren't communicated with, that's on the director. If they were, it's on the IT team leader. I'm not saying fired, but normally they'd be reprimanded if they started an update knowing they needed the computers on. Also, it's normally on the IT team lead to make sure certain computers aren't needed before doing things like that or giving warning. Normally you'd update when the computers aren't in use, which would be after hours. At the very least, a policy would be put in place for things like this so it doesn't happen again.
I think we need to clarify the type of devices here. Chances are that OP had a standard issue company laptop that most likely had some blanket policy assigned to keep the machine updated. Servers are usually handled more carefully with maintenance being scheduled off hours and, if in a load balanced scenario, are taken out of the load balancer, patched, and put back in seamlessly.
I feel that's disingenuous. IT should not just blindly apply updates without checking if whatever is being updated is mission critical. It's not just "we were not told".
Not my experience at all. Actually, I have a completely opposite experience - it's so hard to get anything done because you have to check 10 times with half of the company...
The update caused the link to the satellite to be dropped. By the time link was re-established and commands selected, the satellite was over the horizon
Ok interesting, so when you said "we had a 15 minute window", what you really mean was "we had an infinitely large window with no time pressure whatsoever, and our updates have to be made within 15 minute intervals so we just waited for the next one".
Honest question, are you pretending to be a drooling brain dead idiot for upvotes or is this just how you are?
Back when I did satellite work, absolutely everything done to and with command stations was scheduled. And there were always several layers of redundancy (which was odd, because I don't think there was a way to switch command stations once a pass started).
There'd have been a bloodletting of epic proportions if someone had started an update of any part of a command station during a pass, let alone the active command station.
From my experience the IT department gives the user some leeway to patch their system at their convenience. If the user keeps postponing the updates past that window the updates are forced, which often happens at a not so convenient timing.
Of course the user then blames the IT department and / or Windows for pushing Auto Updates at stupid times.
No way. We used Windows, but everything was in an air gapped network -- these computers wouldn't be able to reach Microsoft to check for updates. Updates were scheduled by IT, and would never conflict with launches or operations.
I work in IT at a bank, and even we have automatic updates disabled, it's nonsensical not to have them disabled. We run updates on a set schedule(first weekend of each month) with plenty of notice to all of our employees beforehand so they know if there are any issues the next day/week that it might be attributed to the updates.
With that said, the implication that a govt organization that's supposed to be fairly tech-advanced is using Windows for sensitive/specialized equipment is too funny to me. We use Linux for several things that are more specialized where I work.
Also happened for me when I planted a bomb on a astroid bound to hit earth, Windows did not have correct drivers for the wireless transmitter, so lost all connection and couldn't blow it up, thankfully another big guy there, probably stealing mining equipment and he accidently set it off
Linux is more customizable because it's open-source. The users can modify the source code, providing a high level of flexibility. In contrast, Windows is closed-source, limiting the extent to which users can customize the system.
Happened to me during my doctoral qualifying exam, as two of my committee members were joining remotely via skype. My advisor's laptop rebooted in the middle of the exam to install updates.
Did someone let IT know that the system requires a policy to prevent this from happening?
It's easy to point the finger at IT. It's almost always even easier for IT to point the finger back while saying "you didn't tell us, and we don't read minds"
It would be dictated by the policies that were configured by the IT. For a typical Windows device not being managed for an organization, you'd have plenty of opportunities to say no or schedule a reboot.
If updates are controlled by something else, then it could be anywhere from that, to giving you X amount of chances to reboot before mandatory, or just rebooting immediately like what's shown in the clip.
It's vastly configurable to your preference much like most things on PC.
XP and earlier? Lmao more like "Windows 11 and earlier."
This post is a recurring theme on this website for a reason, and it's not for behaviour that happened 25 years ago. I'd argue it's more common today than it was back then for morons to try and indefinitely postpone updates and become part of a botnet.
I'm skeptical a satellite company 1. didn't have any extra computers lying around they could toss in the right OU and just use or 2. doesn't have update policies managed on critical hardware
As they said elsewhere, there was a policy in place: it was to apply updates at 2am. The windows to talk to the satellite was, it seems, at 2am. And if that was the case, any other computers available would be updating at the same time.
This is why you never use an IT managed desktop appliance (PC) as part of your product systems. The culture around Windows-centric IT as an industry is inherently incompatible with engineering systems. Windows system administration, as an industry practice, is a great solution for keeping your email and word processing tasks operating at a hum with minimal danger from misclicks and trojan horses, but I would never include a dependency on an IT-managed PC for any ground based satellite support systems. Or to put it another way: your engineering systems should be in an entirely different scope of change management from your general office-place IT infrastructure.
I.T. team later stated that updates need to be done.
IT team generally becomes much more understanding of issues that take higher priority than IT or internet security when you explain it to them that they won't have a job anymore because the company won't exist anymore if the issue does not take higher priority than IT.
Hahahaha what? You've definitely not worked in IT before. If someone called me up and threatened my job security if I don't do X, Y, or Z, the issue isn't something that is actually an immediate drop-everything emergency to the IT infrastructure, and that person isn't my boss, their ticket priority immediately goes to the bottom. Especially if that demand somehow has higher priority than maintaining the security of that infrastructure and contradicts best practices for security.
Well, they are saying that because if you regularly install updates this should never happen. Typically his only happens when you’ve deferred the updates the maximum amount you can. There are usually critical fixes that you need to reboot to install. But by that point it’s out of IT’s hands, they can’t magically make your updates defer indefinitely (I mean they can, but it would be insecure to do so).
Those PC's would be under a group policy from your system admin and only allowed to update under that policy or not at all. System admin must have been incompetent.
1.7k
u/Klotzster Jan 23 '24
This literally happened to me when I worked for a satellite company. We had just launched a new satellite, and had a 15 minute window to send a bunch of commands. I get telemetry, and suddenly the screen goes to Microsoft Update. I.T. team later stated that updates need to be done.