en-US windows computer

Configure Automatic Updates

Verified with Windows 11 25H2 — updated on July 30, 2026

Windows 11 25H2

Supported on: Windows XP Professional Service Pack 1 or At least Windows 2000 Service Pack 3 Option 7 only supported on servers of at least Windows Server 2016 edition​

Path in the GPO console

Computer Configuration\Administrative Templates\Windows Components\Windows Update\Manage end user experience

Description

Specifies whether this computer will receive security updates and other important downloads through the Windows automatic updating service. Note: This policy does not apply to Windows RT. This setting lets you specify whether automatic updates are enabled on this computer. If the service is enabled, you must select one of the four options in the Group Policy Setting: 2 = Notify before downloading and installing any updates. When Windows finds updates that apply to this computer, users will be notified that updates are ready to be downloaded. After going to Windows Update, users can download and install any available updates. 3 = (Default setting) Download the updates automatically and notify when they are ready to be installed Windows finds updates that apply to the computer and downloads them in the background (the user is not notified or interrupted during this process). When the downloads are complete, users will be notified that they are ready to install. After going to Windows Update, users can install them. 4 = Automatically download updates and install them on the schedule specified below. When "Automatic" is selected as the scheduled install time, Windows will automatically check, download, and install updates. The device will reboot as per Windows default settings unless configured by group policy. (Applies to Windows 10, version 1809 and higher) Specify the schedule using the options in the Group Policy Setting. For version 1709 and above, there is an additional choice of limiting updating to a weekly, bi-weekly, or monthly occurrence. If no schedule is specified, the default schedule for all installations will be every day at 3:00 AM. If any updates require a restart to complete the installation, Windows will restart the computer automatically. (If a user is signed in to the computer when Windows is ready to restart, the user will be notified and given the option to delay the restart.) On Windows 8 and later, you can set updates to install during automatic maintenance instead of a specific schedule. Automatic maintenance will install updates when the computer is not in use and avoid doing so when the computer is running on battery power. If automatic maintenance is unable to install updates for 2 days, Windows Update will install updates right away. Users will then be notified about an upcoming restart, and that restart will only take place if there is no potential for accidental data loss. 5 = Allow local administrators to select the configuration mode that Automatic Updates should notify and install updates. (This option has not been carried over to any Win 10 Versions) With this option, local administrators will be allowed to use the Windows Update control panel to select a configuration option of their choice. Local administrators will not be allowed to disable the configuration for Automatic Updates. 7 = Notify for install and notify for restart. (Windows Server only) With this option from Windows Server 2016, applicable only to Server SKU devices, local administrators will be allowed to use Windows Update to proceed with installations or reboots manually. If the status for this policy is set to Disabled, any updates that are available on Windows Update must be downloaded and installed manually. To do this, search for Windows Update using Start. If the status is set to Not Configured, use of Automatic Updates is not specified at the Group Policy level. However, an administrator can still configure Automatic Updates through Control Panel.

Registry

HKLM Software\Policies\Microsoft\Windows\WindowsUpdate\AU

Value name: NoAutoUpdate

Enabled: NoAutoUpdate = 0

Disabled: NoAutoUpdate = 1

More options available

Options

Configure automatic updating:
AUOptions enum
  • 2 - Notify for download and auto install -> 2
  • 3 - Auto download and notify for install -> 3 (default)
  • 4 - Auto download and schedule the install -> 4
  • 5 - Allow local admin to choose setting -> 5
  • 7 - Auto Download, Notify to install, Notify to Restart -> 7
Install during automatic maintenance
AutomaticMaintenanceEnabled boolean - default: 0
Scheduled install day:
ScheduledInstallDay enum
  • 0 - Every day -> 0 (default)
  • 1 - Every Sunday -> 1
  • 2 - Every Monday -> 2
  • 3 - Every Tuesday -> 3
  • 4 - Every Wednesday -> 4
  • 5 - Every Thursday -> 5
  • 6 - Every Friday -> 6
  • 7 - Every Saturday -> 7
Scheduled install time:
ScheduledInstallTime enum
  • Automatic -> 24
  • 00:00 -> 0
  • 01:00 -> 1
  • 02:00 -> 2 (default)
  • 03:00 -> 3
  • 04:00 -> 4
  • 05:00 -> 5
  • 06:00 -> 6
  • 07:00 -> 7
  • 08:00 -> 8
  • 09:00 -> 9
  • 10:00 -> 10
  • 11:00 -> 11
  • 12:00 -> 12
  • 13:00 -> 13
  • 14:00 -> 14
  • 15:00 -> 15
  • 16:00 -> 16
  • 17:00 -> 17
  • 18:00 -> 18
  • 19:00 -> 19
  • 20:00 -> 20
  • 21:00 -> 21
  • 22:00 -> 22
  • 23:00 -> 23
Install updates for other Microsoft products
AllowMUUpdateService boolean - default: 0
Every week
ScheduledInstallEveryWeek boolean - default: 1
First week of the month
ScheduledInstallFirstWeek boolean - default: 0
Second week of the month
ScheduledInstallSecondWeek boolean - default: 0
Third week of the month
ScheduledInstallThirdWeek boolean - default: 0
Fourth week of the month
ScheduledInstallFourthWeek boolean - default: 0

MDM / Intune (CSP)

./Device/Vendor/MSFT/Policy/Config/Update/AllowAutoUpdate
Device Since Windows 10, version 1507 [10.0.10240] and later Official mapping (Microsoft Learn)

Multiple CSP matches are possible; the first one was selected.

Microsoft Learn documentation Mapping data: Microsoft Learn (CC BY 4.0)

CSP values
  • 0 - Notify the user before downloading the update. This policy is used by the enterprise who wants to enable the end-users to manage data usage. With this option users are notified when there are updates that apply to the device and are ready for download. Users can download and install the updates from the Windows Update control panel.
  • 1 - Auto install the update and then notify the user to schedule a device restart. Updates are downloaded automatically on non-metered networks and installed during "Automatic Maintenance" when the device isn't in use and isn't running on battery power. If automatic maintenance is unable to install updates for two days, Windows Update will install updates immediately. If the installation requires a restart, the end-user is prompted to schedule the restart time. After the update is installed, if the user hasn't scheduled a restart, the device will attempt to restart automatically. The user will be notified about the scheduled restart and can reschedule it if the proposed time is inconvenient. Enabling the end-user to control the start time reduces the risk of accidental data loss caused by applications that don't shutdown properly on restart.
  • 2 (Default) - Auto install and restart. Updates are downloaded automatically on non-metered networks and installed during "Automatic Maintenance" when the device isn't in use and isn't running on battery power. If automatic maintenance is unable to install updates for two days, Windows Update will install updates right away. If a restart is required, then the device is automatically restarted when the device isn't actively being used. This is the default behavior for unmanaged devices. Devices are updated quickly, but it increases the risk of accidental data loss caused by an application that doesn't shutdown properly on restart.
  • 3 - Auto install and restart at a specified time. The IT specifies the installation day and time. If no day and time are specified, the default is 3 AM daily. Automatic installation happens at this time and device restart happens after a 15-minute countdown. If the user is logged in when Windows is ready to restart, the user can interrupt the 15-minute countdown to delay the restart.
  • 4 - Auto install and restart without end-user control. Updates are downloaded automatically on non-metered networks and installed during "Automatic Maintenance" when the device isn't in use and isn't running on battery power. If automatic maintenance is unable to install updates for two days, Windows Update will install updates right away. If a restart is required, then the device is automatically restarted when the device isn't actively being used. This setting option also sets the end-user control panel to read-only.
  • 5 - Turn off automatic updates.

Export Builder

BETA

Configure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.

These exports write the registry — this is not a managed GPO.

.reg file

Windows Registry Editor Version 5.00

; Exported from gporais.com
; Policy: Configure Automatic Updates
; State: Enabled
; Supported on: Windows XP Professional Service Pack 1 or At least Windows 2000 Service Pack 3 Option 7 only supported on servers of at least Windows Server 2016 edition​

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\WindowsUpdate\AU]
"NoAutoUpdate"=dword:00000000
"AUOptions"=dword:00000003
"AutomaticMaintenanceEnabled"=dword:00000000
"ScheduledInstallDay"=dword:00000000
"ScheduledInstallTime"=dword:00000002
"AllowMUUpdateService"=dword:00000000
"ScheduledInstallEveryWeek"=dword:00000001
"ScheduledInstallFirstWeek"=dword:00000000
"ScheduledInstallSecondWeek"=dword:00000000
"ScheduledInstallThirdWeek"=dword:00000000
"ScheduledInstallFourthWeek"=dword:00000000
More formats (PowerShell, Intune, SCCM)

PowerShell

# Exported from gporais.com
# Policy: Configure Automatic Updates
# State: Enabled
# Supported on: Windows XP Professional Service Pack 1 or At least Windows 2000 Service Pack 3 Option 7 only supported on servers of at least Windows Server 2016 edition​

$path = 'HKLM:\Software\Policies\Microsoft\Windows\WindowsUpdate\AU'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'NoAutoUpdate' -Value 0 -Type DWord
Set-ItemProperty -Path $path -Name 'AUOptions' -Value 3 -Type DWord
Set-ItemProperty -Path $path -Name 'AutomaticMaintenanceEnabled' -Value 0 -Type DWord
Set-ItemProperty -Path $path -Name 'ScheduledInstallDay' -Value 0 -Type DWord
Set-ItemProperty -Path $path -Name 'ScheduledInstallTime' -Value 2 -Type DWord
Set-ItemProperty -Path $path -Name 'AllowMUUpdateService' -Value 0 -Type DWord
Set-ItemProperty -Path $path -Name 'ScheduledInstallEveryWeek' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'ScheduledInstallFirstWeek' -Value 0 -Type DWord
Set-ItemProperty -Path $path -Name 'ScheduledInstallSecondWeek' -Value 0 -Type DWord
Set-ItemProperty -Path $path -Name 'ScheduledInstallThirdWeek' -Value 0 -Type DWord
Set-ItemProperty -Path $path -Name 'ScheduledInstallFourthWeek' -Value 0 -Type DWord

Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.

Open the Builder

Embed this policy on your site

What to embed
Theme

Adds one script line: the theme follows your site’s appearance and the height fits the content. If your site blocks scripts, the embed follows the visitor’s system theme.

Preview