You could be correct, but imho, I don't think the MS server would know you needed updates until the machine was logged in?
As Ms are now only sending UUps, it is necessary for them to have access so that they can se what is needed. Mybe (?) they can do this instantly from the registration at the boot stage - no idea on that.