L1BIO 12.06.01ISO A.12.6.1CIS Windows - Pause updates
Intune: Block User Ability To Pause Windows Updates
π 2025-10-30
β’
β±οΈ 3 minuten lezen
β’
π΄ Must-Have
πΌ Management Samenvatting
Block users from pausing Windows Updates - prevents users delaying critical security patches (patch compliance enforcement).
Aanbeveling
IMPLEMENT
Risico zonder
High
Risk Score
8/10
Implementatie
3u (tech: 1u)
Van toepassing op:
β Windows 10 β Windows 11
Pause updates = security risk: Windows 10/11 feature: Users can pause updates 35 days (Settings β Windows Update β Pause updates), User behavior: 'I'm busy' β pause updates β forget to resume β 6 months unpatched, Security impact: Critical vulnerability (e.g., PrintNightmare) β Microsoft patches β user paused updates β vulnerable for months. Attack: Attacker scans network β finds unpatched device (user paused updates) β exploit β ransomware. Enterprise requirement: Patch compliance (100% devices patched within SLA - 30 days).
PowerShell Modules Vereist
Primary API: Microsoft Graph API Connection:Connect-MgGraph Required Modules: Microsoft.Graph.DeviceManagement
Implementatie
Block pause ability: Policy: SetDisablePauseUXAccess: Block, Effect: Settings β Windows Update β 'Pause updates' option REMOVED, Users: Cannot pause (updates install per schedule), Admin control: Intune Update rings (centralized pause for maintenance windows - controlled).
Vereisten
Intune subscription
Windows 10/11
Maintenance windows: Scheduled via Intune (user-friendly update times)
Implementatie
Intune: Windows Update ring β Block user from pausing updates: Block. Effect: 'Pause updates' removed from Settings. Maintenance: Configure active hours (non-disruptive update times).
Compliance
CIS Windows Benchmark L1, BIO 12.06 (Patch management), ISO 27001 A.12.6.1, NIS2 Art. 21.
Monitoring
Gebruik PowerShell-script block-pause-updates-ability-is-set-to-block.ps1 (functie Invoke-Monitoring) β Controleren.
Remediatie
Gebruik PowerShell-script block-pause-updates-ability-is-set-to-block.ps1 (functie Invoke-Remediation) β Herstellen.
Compliance & Frameworks
CIS M365: Control Windows - Pause updates (L1) -
BIO: 12.06.01 -
ISO 27001:2022: A.12.6.1 -
NIS2: Artikel -
Automation
Gebruik het onderstaande PowerShell script om deze security control te monitoren en te implementeren. Het script bevat functies voor zowel monitoring (-Monitoring) als remediation (-Remediation).