Skip to main content

Update Orchestrator - Reboot Prevention [Change]

Summary​

The monitor set renames the reboot file at C:/Windows/System32/Tasks/Microsoft/Windows/UpdateOrchestrator/reboot in order to prevent the Windows Update Orchestrator service from rebooting the computer. It will also enable the UsoSvc service if it's disabled.

What will change?​

This monitor will rename the reboot file at
C:/Windows/System32/Tasks/Microsoft/Windows/UpdateOrchestrator/reboot
and keep the Windows Update Orchestrator Service enabled and running.

This action will happen regardless of what alert template is set against the monitor.
Monitors that make a change to the environment can be difficult to audit actions taken. Use with caution.

Details​

Suggested "Limit to": Update Orchestrator - UsoSvc
Suggested Alert Style: Once
Suggested Alert Template: Default - Create Automate Ticket

Insert the details of the monitor in the table below.

Check ActionServer AddressCheck TypeExecute InfoComparatorIntervalResult
System127.0.0.1Run FileREDACTEDDoes Not Contain600Failed to rename the reboot file

Target​

Managed Windows Servers and Workstations

Ticketing​

Subject:
Windows Update Orchestrator Monitor - Failed - %ComputerName%

Body:
The reboot file at C:/Windows/System32/Tasks/Microsoft/Windows/UpdateOrchestrator/reboot failed to be renamed. The update orchestrator uses this file; it should either be deleted or renamed to prevent the update orchestrator from restarting the computer at any moment.

Implementation​

Import - Remote Monitor - Windows Update Orchestrator

Changelog​

2025-04-10​

  • Initial version of the document