Inquiry Regarding Automatic Restart Behavior During Windows 11 24H2 Feature Update Deployment

GONDO RANTO(権藤 嵐人) 0 Reputation points
2026-10-06T02:08:06.54+00:00

We would like to inquire about the restart behavior during the deployment of a Windows 11 Feature Update (23H2 → 24H2).

Environment

  • OS: Windows 11 23H2
  • Update Method: WSUS
  • Feature Update: Windows 11 24H2
  • Target Devices: Approximately 100 devices

WSUS and GPO Configuration

The Windows 11 24H2 Feature Update has been approved on the WSUS server.

The following Windows Update-related Group Policies are configured on the target devices:

  • Specify intranet Microsoft update service location
  • Turn off auto-restart for updates during active hours
    • Active Hours Start: 08:00
      • Active Hours End: 19:00

Additionally, the following deadline-related policies are Not Configured:

  • Specify deadline for automatic updates and restarts for feature updates
  • Specify deadline for automatic updates and restarts for quality updates

No other policies related to restart deadlines or forced restarts are configured.

Issue Description

After approving Windows 11 24H2 in WSUS around mid-September, the target devices remained powered on for an extended period.

Subsequent investigation revealed the following:

  • Windows Update history showed that Windows 11 24H2 had been successfully installed.
  • As of October 2, more than 100 devices were still running Windows 11 23H2 and appeared to be waiting for a restart.
  • When checked again on October 5, all devices had been upgraded to Windows 11 24H2.

No users reported manually restarting their devices. Therefore, we suspect that an automatic restart may have been performed by Windows Update.

Note: Monthly quality updates are automatically restarted in our environment.

Event Log Information

The following event was observed in the System log:

  • Event ID: 1074
  • Source: User32
  • User: NT AUTHORITY\SYSTEM
  • Process: C:\Windows\System32\winlogon.exe
  • Reason: "Operating System: Upgrade (Planned)"

Based on this event, we assume that Windows initiated a restart to complete the operating system upgrade.

Questions

When deploying a Windows 11 Feature Update (23H2 → 24H2), can Windows Update (Update Orchestrator) perform an automatic restart as part of its default behavior even when the deadline-related policies are not configured?

If a device remains in a pending restart state for an extended period after a Feature Update installation, is there any Windows Update mechanism or design behavior that automatically initiates a restart to complete the upgrade?

We would appreciate any clarification regarding this behavior, as well as any related Microsoft documentation that explains the expected restart behavior for Feature Updates when deadline policies are not configured.

Thank you for your assistance.Subject: Inquiry Regarding Automatic Restart Behavior During Windows 11 24H2 Feature Update Deployment

We would like to inquire about the restart behavior during the deployment of a Windows 11 Feature Update (23H2 → 24H2).

Environment

  • OS: Windows 11 23H2
  • Update Method: WSUS
  • Feature Update: Windows 11 24H2
  • Target Devices: Approximately 100 devices

WSUS and GPO Configuration

The Windows 11 24H2 Feature Update has been approved on the WSUS server.

The following Windows Update-related Group Policies are configured on the target devices:

  • Specify intranet Microsoft update service location
  • Turn off auto-restart for updates during active hours
    • Active Hours Start: 08:00
      • Active Hours End: 19:00

Additionally, the following deadline-related policies are Not Configured:

  • Specify deadline for automatic updates and restarts for feature updates
  • Specify deadline for automatic updates and restarts for quality updates

No other policies related to restart deadlines or forced restarts are configured.

Issue Description

After approving Windows 11 24H2 in WSUS around mid-September, the target devices remained powered on for an extended period.

Subsequent investigation revealed the following:

  • Windows Update history showed that Windows 11 24H2 had been successfully installed.
  • As of October 2, more than 100 devices were still running Windows 11 23H2 and appeared to be waiting for a restart.
  • When checked again on October 5, all devices had been upgraded to Windows 11 24H2.

No users reported manually restarting their devices. Therefore, we suspect that an automatic restart may have been performed by Windows Update.

Note: Monthly quality updates are automatically restarted in our environment.

Event Log Information

The following event was observed in the System log:

  • Event ID: 1074
  • Source: User32
  • User: NT AUTHORITY\SYSTEM
  • Process: C:\Windows\System32\winlogon.exe
  • Reason: "Operating System: Upgrade (Planned)"

Based on this event, we assume that Windows initiated a restart to complete the operating system upgrade.

Questions

When deploying a Windows 11 Feature Update (23H2 → 24H2), can Windows Update (Update Orchestrator) perform an automatic restart as part of its default behavior even when the deadline-related policies are not configured?

If a device remains in a pending restart state for an extended period after a Feature Update installation, is there any Windows Update mechanism or design behavior that automatically initiates a restart to complete the upgrade?

We would appreciate any clarification regarding this behavior, as well as any related Microsoft documentation that explains the expected restart behavior for Feature Updates when deadline policies are not configured.

Thank you for your assistance.

Windows for business | Windows Server | Devices and deployment | Install Windows updates, features, or roles
0 comments No comments

2 answers

Sort by: Most helpful
  1. Daphne Huynh (WICLOUD CORPORATION) 1,575 Reputation points Microsoft External Staff Moderator
    2026-10-06T02:44:52.21+00:00

    Welcome to Microsoft Q&A!

    Thank you for providing such detailed information about your environment and observations.

    Based on the configuration and evidence you have shared, it is possible for Windows Update to automatically restart a device to complete a Windows 11 feature update even when the "Specify deadline for automatic updates and restarts for feature updates" policy is Not Configured.

    In your scenario, the sequence below would be consistent with the expected Windows Update behavior:

    • WSUS offered and installed the Windows 11 24H2 feature update.
    • The devices entered a pending restart state while still reporting Windows 11 23H2.
    • Windows deferred the restart until an appropriate opportunity became available, typically outside the configured active hours.
    • A system-initiated restart occurred under the NT AUTHORITY\SYSTEM context.
    • The restart completed the offline phase of the upgrade, and the devices subsequently reported Windows 11 24H2.

    The key distinction is that deadline policies determine when a restart must be enforced, but they do not enable or disable Windows Update's ability to perform automatic restarts. By default, Windows Update is designed to install updates and complete required restarts while attempting to minimize user disruption. When a restart is required, Windows generally schedules it outside configured active hours whenever possible.

    In your environment, the “Turn off auto-restart for updates during active hours" policy protects the period between 08:00 and 19:00. However, it does not prevent Windows from restarting outside those hours. Active hours is described as a mechanism to avoid interruptions while users are actively working, rather than as a restriction that completely blocks automatic restarts.

    As a result, once the 24H2 feature update reached a restart-pending state, Windows Update and the Update Orchestrator could select an appropriate maintenance window outside active hours and complete the restart automatically.

    1. Regarding Event ID 1074

    The Event ID 1074 information you captured strongly supports this interpretation:

    • User: NT AUTHORITY\SYSTEM
    • Process: C:\Windows\System32\winlogon.exe
    • Reason: Operating System: Upgrade (Planned)
    • Shutdown Type: Restart

    This event indicates that Windows initiated a planned restart associated with an operating system upgrade rather than a user-triggered restart or an unexpected shutdown. Event ID 1074 can be treated as a primary indicator when confirming whether a reboot was initiated by the operating system during update servicing.

    Moreover, Event ID 1074 does not identify every component involved in the restart sequence. While winlogon.exe is shown as the initiating process, it may be acting on behalf of Windows Setup, servicing components, or Update Orchestrator. Therefore, the event should be viewed as evidence that Windows performed a planned upgrade restart, rather than definitive proof of the specific component that scheduled it.

    2. Is there a built-in timeout that forces a restart?

    Based on the public available documentation from Microsoft, there is no documented Windows 11 behavior that automatically forces a feature update restart after a specific number of days when the feature update deadline policies are not configured.

    Instead, the behavior is:

    • Windows attempts to restart automatically outside active hours after an update requires a restart.
    • Windows continues looking for a suitable, minimally disruptive restart opportunity.
    • Configuring Specify deadline for automatic updates and restarts for feature updates introduces a defined deadline and grace period.
    • Once a configured deadline and grace period expire, Windows can enforce a restart regardless of active hours.

    Therefore, while the observed restart between October 2 and October 5 is consistent with Windows Update's normal restart management behavior, Microsoft does not publish a specific "restart after X days" rule for feature updates when no deadline policy is configured.

    3. Recommendation

    If you would like more predictable restart behavior during future feature update deployments, consider configuring Specify deadline for automatic updates and restarts for feature updates along with an appropriate grace period. It is a recommendation using the modern deadline policies for Windows 11 version 22H2 and later because they provide clearer control over installation and restart timelines.

    References:

    Manage device restarts after updates | Microsoft Learn

    Configure Windows Update client policies via Group Policy | Microsoft Learn

    Keep your PC up to date with active hours | Microsoft Support

    Windows Update: FAQ | Microsoft Support

    Enforce compliance deadlines with policies | Microsoft Learn

    Policies for update compliance and user experience | Microsoft Learn

    Configure Windows Update client policies via Group Policy | Microsoft Learn

    Step 4 - Configure Group Policy Settings for Automatic Updates | Microsoft Learn

    If you find it useful, please click Accept Answer.

    Thank you for choosing Microsoft Q&A.

    Was this answer helpful?


  2. AI answer

    2026-10-06T02:08:34.76+00:00

    Yes. Based on the documented default behavior, Windows can automatically download, install, and restart for updates even when deadline policies are not configured.

    The relevant behavior is:

    1. If an automatic update policy is not set, the device attempts to download, install, and restart at the best times for the user by using built-in intelligence such as intelligent active hours.
    2. If Turn off auto-restart for updates during active hours is configured, that limits automatic restarts during the configured active hours, but it does not prevent automatic restarts outside active hours.
    3. Microsoft states that to update outside active hours, no additional settings are required: simply do not disable automatic restarts.
    4. If deadline policies are disabled or not configured, devices restart according to the default schedule.

    Applied to the described case, the observed Event ID 1074 from winlogon.exe with reason Operating System: Upgrade (Planned) is consistent with Windows completing the feature update by restarting automatically outside the configured active hours. The configured policy protects 08:00-19:00, but it does not block restart behavior outside that window.

    For the second question, the documentation provided does not describe a separate special mechanism that waits an arbitrary long time and then forces a feature update restart when deadline policies are not configured. What it does document is the default restart model:

    • updates install and restart according to the default schedule when deadline policies are not configured
    • automatic restarts are attempted outside active hours
    • if deadline policies are configured, then restart behavior becomes more strict and can occur regardless of active hours after the deadline passes

    So the supported conclusion is:

    • Yes, Windows Update can automatically restart for a feature update under default behavior even without deadline policies.
    • Yes, a device in pending restart can still be restarted automatically as part of the normal default update orchestration, typically outside active hours.
    • The provided documentation does not state a separate guaranteed timeout-based forced restart mechanism for feature updates when no deadline policy is configured; only the default scheduling behavior is documented.

    If tighter control is required for future feature update deployments, the documented policy to use is:

    • Computer Configuration > Administrative Templates > Windows Components > Windows Update > Specify deadline for automatic updates and restarts

    For Windows 11 policy CSP documentation, the deadline settings for feature and quality updates state that if the policy is disabled or not configured, devices get updates and restart according to the default schedule.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.