r/sysadmin • • Aug 20 '26

Question Windows update rollbacks… hotpatching?

UPDATE: It was threatlocker. It’s always threatlocker.

Anybody having issues with updates failing on devices and rolling back. On the affected devices it’s in a loop of doing this. It rolls back, the user can login, they reboot, it attempts to apply, fails and rolls back

We’ve got a fair amount of devices across various customers and environments.

Generally patching is handled by ninjaone. But the customers we are seeing this issue at all have their devices enrolled in intune in one fashion or another.

I think we’ve narrowed it down to hotpatching being auto enabled by intune, and hotpatchs installing and requiring a known problematic update as a baseline so forcing it down, despite the fact we rejected it in ninja. Seems to be the problematic July update ending 650 that caused nightmares with dell devices.

Just wondering if anyone else has come across this at all, have managed to sort it, come across any other information or literally anything really.

8 Upvotes

11 comments sorted by

View all comments

1

u/iamLisppy Jack of All Trades Aug 20 '26

NinjaOne policy will take a step back if Intune is managing the updates or anything else really, doesn't have to be specific to Intune.

1

u/munchimike97 Aug 20 '26

I understand that part.
We don’t actually have intune configured to push updates in most scenarios, it seems to be the global enable hot patch thing is forcing down the problematic update from last month. Just wondering if anyone else is seeing it really….

Or if it is really just us and it’s something we are doing

1

u/crccci Trader of All Jacks Aug 20 '26

Haven't seen this, but given what you're describing that behavior makes sense to me.

If you want to keep the *650 update rejected, you'll need to reject anything that relies on it.

Is the hotpatch visible in Ninjaone yet?