Solved

Windows Server are rebooting after patching even with No Auto-restart GP settings enabled

Posted on 2008-06-23
16
432 Views
Last Modified: 2010-04-18
Servers rebooting without user consent

We have a group of servers which are rebooting automatically after being patched. The servers are part of a group policy that has the "No auto-restart for scheduled Automatic Updates installations" set to enabled. They don't restart right away, but instead wait for someone to log into the server. Most of the time the servers begin the reboot right after the credentials are entered, but some analysts claim they also reboot several minutes after logging in.

Any ideas?

The group policy is enforced through active directory. There are no local policies set at all in regards to automatic updates.

We are patching using SMS2003 or Shavlik.
0
Comment
Question by:bbcac
  • 8
  • 7
16 Comments
 
LVL 28

Expert Comment

by:jhyiesla
ID: 21847601
Have you had your analysts look to see if the parameters in the GPO are actually being applied to the servers?  Make sure that you have someone log in who has had this happen to them.
0
 
LVL 30

Expert Comment

by:LauraEHunterMVP
ID: 21848693
This is a frequently misunderstood setting within GPO - "No auto-restart..." does -not- mean "Server will never reboot". It means "Server will not reboot automatically; rather, it will prompt the next interactively-logged-on user to reboot."

From http://support.microsoft.com/kb/328010: "This policy specifies that Automatic Updates will wait for the computer to be restarted by any user who is logged on to complete a scheduled installation. If this policy is not used, the computer restarts automatically."

If your goal is "no restart prompt ever, no way, no how", then you need to disable WSUS on your servers entirely and patch using only your managed SMS/Shavlik methods.
0
 

Author Comment

by:bbcac
ID: 21849055
There is no prompt. Often upon signing in, the server will reboot without any interaction at all.
There are some analyst (I haven't seen it happen) that claim while working, the server reboots citing "winlogon.exe" has initiated a reboot.

We are not clicking ok on any popups but rather the server simply reboots without notice
0
Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

 
LVL 30

Expert Comment

by:LauraEHunterMVP
ID: 21849170
I would check your other WSUS GPO settings then, ensure that it's configured to notify for install, etc.  If the analyst in question isn't a local admin on the box, there's another setting for "allow non-admins to see notifications" you probably want to double-check as well.
0
 

Author Comment

by:bbcac
ID: 21855469
The user is using a domain admin account which is setup as a local administrator.

Any ideas?
0
 
LVL 30

Expert Comment

by:LauraEHunterMVP
ID: 21855505
If the RSoP on the server in question displays the settings that you expect, make a copy of the user account and try to repro the behavior (since you say you haven't actually seen it and are going by user report.)
0
 

Author Comment

by:bbcac
ID: 21855859
I have seen it happen where it reboots upon login, I have not seen it happen where it reboots while working on the server
0
 

Author Comment

by:bbcac
ID: 21858407
The RSOP shows that the "No auto-restart" option as enabled.
Any other ideas?
0
 
LVL 30

Expert Comment

by:LauraEHunterMVP
ID: 21858578
Unless you can actually reproduce the behavior being reported, it's impossible to determine whether it's a misconfiguration in your GP or a user issue; at the moment you're attempting to troubleshoot hearsay, which is virtually impossible to do.  The AU reboot window steals focus when it prompts to reboot, so it's entirely possible that the user is being prompted to reboot while working in another window and presses 'Enter' at the wrong time.  A reported time delay could also be accounted for if the 'Reschedule Automatic Update scheduled installations' option is configured.
0
 

Author Comment

by:bbcac
ID: 21858675
This is something that I have personally seen happen on several occassions. I know that there is no user interaction when it happens. The reboot happens immediately after logging in without notice or input from the user. The login can be 1 day, or 1 week after patching. We can't reproduce the issue because it only happens on some servers
The RSOP is not showing a GP issue, then where could it be?
0
 
LVL 30

Expert Comment

by:LauraEHunterMVP
ID: 21858843
> "There are some analyst (I haven't seen it happen)"

Your earlier comment indicated that you had not been able to repro the behavior.  

Without seeing your GP structure, it's difficult to offer additional advice.  Generally speaking, best to start from a clean slate - create a new OU with no GPOs linked to it (and none being inherited), move the servers to that OU and begin troubleshooting from there.
0
 

Author Comment

by:bbcac
ID: 21874338
Here's some logs that we found in the WindowsUpdate.log

2008-06-23      11:01:12:139      1448      d30      AU      AU setting pending client directive to 'Forced Reboot'

2008-06-23      11:01:27:775      1448      d30      AU      Launched new AU client for directive 'Forced Reboot', session id = 0x1

2008-06-23      11:01:28:652      5972      175c      CltUI      AU client got new directive = 'Forced Reboot', serviceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, return = 0x00000000
0
 

Author Comment

by:bbcac
ID: 21874692
We have found that the boxes that are not rebooting are part of a different active directory OU. They have no AU settings configured. The boxes that are rebooting are part of the wrong OU that has AU configured.
That being said, it still doesn't explain why these servers are rebooting. None of the RSOP settings indicate a that a reboot will be forced. In fact they indicate that auto reboots will be avoided.
0
 
LVL 30

Expert Comment

by:LauraEHunterMVP
ID: 21874728
You're contradicting yourself here - if they have no AU settings configured, that is not the same as indicating that auto-reboots will be avoided.  If the "No auto-restart..." GP setting is not configured, and if AU is set to auto-download and auto-install, then any updates that require a reboot will automatically reboot the servers.

As I indicated before, if you are having difficulties determining which GP settings are being applied to these servers it's best to start with a clean slate and add in settings until you have them configured the way you desire.
0
 

Author Comment

by:bbcac
ID: 21875393
"We have found that the boxes that are not rebooting are part of a different active directory OU. They have no AU settings configured."
- this comment was suppose to convey that there are two OU's. One which is rebooting and one which is not. The servers that are not rebooting, do not have AU settings configured.

"The boxes that are rebooting are part of the wrong OU that has AU configured."
- this other group, which is rebooting, actually has the AU settings configured
0
 
LVL 30

Accepted Solution

by:
LauraEHunterMVP earned 500 total points
ID: 21875445
My previous advice holds - remove any configured AU settings and add them back in one at a time until you've unravelled the Gordian knot.  First rule of troubleshooting: simplify your configuration.
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Synchronize a new Active Directory domain with an existing Office 365 tenant
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

815 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

8 Experts available now in Live!

Get 1:1 Help Now