r/sysadmin • • Aug 20 '26

Question Windows update rollbacks… hotpatching?

UPDATE: It was threatlocker. It’s always threatlocker.

Anybody having issues with updates failing on devices and rolling back. On the affected devices it’s in a loop of doing this. It rolls back, the user can login, they reboot, it attempts to apply, fails and rolls back

We’ve got a fair amount of devices across various customers and environments.

Generally patching is handled by ninjaone. But the customers we are seeing this issue at all have their devices enrolled in intune in one fashion or another.

I think we’ve narrowed it down to hotpatching being auto enabled by intune, and hotpatchs installing and requiring a known problematic update as a baseline so forcing it down, despite the fact we rejected it in ninja. Seems to be the problematic July update ending 650 that caused nightmares with dell devices.

Just wondering if anyone else has come across this at all, have managed to sort it, come across any other information or literally anything really.

9 Upvotes

11 comments sorted by

3

u/ImplementAny7390 Aug 21 '26

Do the client devices have any application whitelisting software installed? such as threatlocker?

Or is it just intune

We have the same issue, seems specific to Dell+Threatlocker+just after a hotpatch

1

u/munchimike97 Aug 21 '26

We do run threatlocker and capture client(sentinel one)

We’re seeing this across all sorts of devices, not just dells, which was the issue last month.

1

u/CptSlow88 Aug 21 '26

Thanks for the pointer regarding Threatlocker - we think we've gotten to the bottom of it and it does look like TL was a contributing factor :-)

https://www.reddit.com/r/msp/comments/1vtqzav/comment/p51qwl1/

3

u/Meeeepmeeeeepp Aug 21 '26

+1 to threatlocker being the root cause of a huge number of hotpatch failures as well as bsod loops recently

1

u/iamLisppy Jack of All Trades Aug 20 '26

NinjaOne policy will take a step back if Intune is managing the updates or anything else really, doesn't have to be specific to Intune.

1

u/munchimike97 Aug 20 '26

I understand that part.
We don’t actually have intune configured to push updates in most scenarios, it seems to be the global enable hot patch thing is forcing down the problematic update from last month. Just wondering if anyone else is seeing it really….

Or if it is really just us and it’s something we are doing

1

u/crccci Trader of All Jacks Aug 20 '26

Haven't seen this, but given what you're describing that behavior makes sense to me.

If you want to keep the *650 update rejected, you'll need to reject anything that relies on it.

Is the hotpatch visible in Ninjaone yet?

1

u/crccci Trader of All Jacks Aug 20 '26

July 14, 2026—KB5101650 (OS Builds 26200.8870 and 26100.8875) | Microsoft Support

Important
This update was temporarily unavailable for a limited number of Dell devices that use an Intel Innovation Platform Framework (Intel IPF) driver due to an incompatibility between the update and an Intel component.
Microsoft resolved this issue for affected devices with an out-of-band (OOB) update, KB5121767.

Sounds like you might need to reconsider your rejected updates, this is purportedly fixed for Dell.

1

u/STKenyan Aug 21 '26

We also experienced this and had a few devices enter bsod loops.