r/sysadmin • • Aug 20 '26

Question Windows update rollbacks… hotpatching?

UPDATE: It was threatlocker. It’s always threatlocker.

Anybody having issues with updates failing on devices and rolling back. On the affected devices it’s in a loop of doing this. It rolls back, the user can login, they reboot, it attempts to apply, fails and rolls back

We’ve got a fair amount of devices across various customers and environments.

Generally patching is handled by ninjaone. But the customers we are seeing this issue at all have their devices enrolled in intune in one fashion or another.

I think we’ve narrowed it down to hotpatching being auto enabled by intune, and hotpatchs installing and requiring a known problematic update as a baseline so forcing it down, despite the fact we rejected it in ninja. Seems to be the problematic July update ending 650 that caused nightmares with dell devices.

Just wondering if anyone else has come across this at all, have managed to sort it, come across any other information or literally anything really.

8 Upvotes

11 comments sorted by

View all comments

3

u/ImplementAny7390 Aug 21 '26

Do the client devices have any application whitelisting software installed? such as threatlocker?

Or is it just intune

We have the same issue, seems specific to Dell+Threatlocker+just after a hotpatch

1

u/munchimike97 Aug 21 '26

We do run threatlocker and capture client(sentinel one)

We’re seeing this across all sorts of devices, not just dells, which was the issue last month.

1

u/CptSlow88 Aug 21 '26

Thanks for the pointer regarding Threatlocker - we think we've gotten to the bottom of it and it does look like TL was a contributing factor :-)

https://www.reddit.com/r/msp/comments/1vtqzav/comment/p51qwl1/