- Thread Author
- #1
We are in the process of upgrading endpoints in our environment to Windows 11. We have over 150 to do, with around 40 complete so far. Of the 40 we’ve done to date, we’ve have the following issue with 4 of them.
MPSSVC (Windows Defender Firewall Service) is ‘Running’ as intended before running the upgrade. ((Upgrade being ran via Windows 11 Upgrade Assistant)). Post-reboot following a successful upgrade the MPSSVC is stuck in a ‘Stopping’ state, can’t be interacted with via elevated services.msc / CMD / PowerShell or PSExec.
The symptoms are no contact with Intune, issues with AzureAD sync, MS store installs unable to complete, some MS Apps no longer working (SnippingTool, Photos). Windows Updates fail after installation stage, pre-boot error “Something didn’t go as intended — Not to worry, we’re undoing changes”. Most updates seem to go fine, the one causing the issue SEEMS to be KB5062553.
The workaround is mounting the W11 24H2 ISO, running setup.exe and running a repair to restore system files and keys. After this repair the MPSSVC runs as intended, Intune contact restored, Azure / work account issues disappear, MS Store apps install and work as expected. However, despite having auto-updates disabled via GPO’s (working for all other devices except newly upgraded ones) and a third party patching application installed that applies local GP’s preventing manual or automatic updates, rebooting the device following the repair pushes the KB5062553 update again, causing the issues to recur upon reboot.
Have attempted stopping Windows Update authority service, background intelligent transfer service and clearing the update cache. Have attempted clean manager to clear Windows Update. Have tried disabling scheduled tasks that run scans and trigger updates.
Is anyone else experiencing this heart ache?
MPSSVC (Windows Defender Firewall Service) is ‘Running’ as intended before running the upgrade. ((Upgrade being ran via Windows 11 Upgrade Assistant)). Post-reboot following a successful upgrade the MPSSVC is stuck in a ‘Stopping’ state, can’t be interacted with via elevated services.msc / CMD / PowerShell or PSExec.
The symptoms are no contact with Intune, issues with AzureAD sync, MS store installs unable to complete, some MS Apps no longer working (SnippingTool, Photos). Windows Updates fail after installation stage, pre-boot error “Something didn’t go as intended — Not to worry, we’re undoing changes”. Most updates seem to go fine, the one causing the issue SEEMS to be KB5062553.
The workaround is mounting the W11 24H2 ISO, running setup.exe and running a repair to restore system files and keys. After this repair the MPSSVC runs as intended, Intune contact restored, Azure / work account issues disappear, MS Store apps install and work as expected. However, despite having auto-updates disabled via GPO’s (working for all other devices except newly upgraded ones) and a third party patching application installed that applies local GP’s preventing manual or automatic updates, rebooting the device following the repair pushes the KB5062553 update again, causing the issues to recur upon reboot.
Have attempted stopping Windows Update authority service, background intelligent transfer service and clearing the update cache. Have attempted clean manager to clear Windows Update. Have tried disabling scheduled tasks that run scans and trigger updates.
Is anyone else experiencing this heart ache?