Opens in a new tab
vmblog logo 2024 wht (updated)

Windows finally removed update friction – now comes the harder part

Share: 

windows removed update friction

By Howard McNamara, Professional Services Consulting Director, Nexthink

Microsoft is changing how Windows 11 handles updates. Soon users will be able to pause updates for longer, skip them during initial setup, and shut down or restart without being pushed into an install they did not ask for.

It is a welcome move. Forced updates have long interrupted the working day, breaking concentration or stopping a meeting at the worst moment. And updates are not the only thing that can interrupt an employee’s flow. Slow load times, application freezes or crashes all add to the digital friction that chips away at the working day, resulting in a significant cumulative impact on workers. The data confirms this, finding that employees suffer around 14 digital disruptions a week, and a delay of even five seconds can triple the error rate for knowledge workers. Added up across an organization, poor digital experience of this kind can cost the equivalent of 470,000 hours of lost time a year.

Handing the power to control updates to employees, however, changes the job for IT. Every deferred update is a device that can quietly become a security risk, and once those decisions sit with thousands of individual users, keeping a handle on the wider IT estate becomes far harder than it was when updates were enforced centrally.

The harder part is what you cannot see

Removing update friction is the easy win for employees. Managing what the change leaves behind is now the part that must be top of mind for IT, and it is less straightforward.

When thousands of devices update on schedules chosen by individual employees, no two machines are necessarily in the same state at any given moment. Some will be fully patched, others weeks behind, and with no clear line of sight there is no reliable way to tell which is which. A single deferred update on one laptop could be harmless, but the same behavior across an entire department could fundamentally change the exposure level of an organization.

This matters most in compliance-heavy industries such as finance and healthcare, where teams running unpatched software can quickly create significant security and regulatory issues. The danger is that this happens without anyone logging a problem, because a deferred update does not raise a ticket or trigger an alert. The gap tends to surface much later, in an audit or an incident, by which point it has often been open for weeks.

The blind spot you are already paying for

The same visibility gap also hides wastage across the estate. Recent analysis found that, over a single month, only around 20% of installed software was actually used, while one in ten devices were more powerful than the role they were assigned to required. Money is routinely spent on licenses no one opens and hardware no one needs, and without a clear view of what is in use there is no dependable way to find it and reclaim it.

The under-reporting of problems makes the picture even more confusing. The same research found that fewer than half of all IT issues are ever raised with the service desk, so a standard dashboard captures only part of what is happening. In one example, leaders at a 13,500-person organisation estimated around 198,000 lost hours a year, when the true figure was closer to 470,000. What IT cannot see, it cannot fix, secure, or fund correctly.

From flexibility to oversight

The answer is not to wrestle the control back from employees. It is to pair the flexibility Microsoft is offering with a clear, current view of what that flexibility is actually doing across the estate.

This is precisely what a Digital Employee Experience (DEX) model is built to provide. Instead of chasing missed patches after an incident has already happened, IT can see deferral patterns as they form, identifying which devices have held back updates and understanding the risk building up while they do. That same view extends across the wider estate, flagging the compliance gaps and the unused software and hardware that would otherwise stay hidden.

In practice, the work starts with a live view of update status across every device, so that deferred installs become visible rather than assumed. From there, IT can prioritize the machines drifting out of compliance or sitting on known vulnerabilities, and use the same visibility to right-size the software and hardware the business is paying for but not fully using.

Microsoft has made the right call, as employees should not lose time on an update they did not schedule. But more control for users only works in a business setting if IT can still see the whole picture, which is why flexibility and oversight should not be treated as a trade-off. The organizations that pit one against the other will find that more control has quietly become less security, while those that pair the two will get the benefit Microsoft intended without the bill that comes from looking away.

##

ABOUT THE AUTHOR

h mcnamara

Howard McNamara is a Professional Services Consulting Director with over 18 years of experience in IT operations and enterprise technology consulting. Having spent the last 8 years at Nexthink, Howard has played a key role in championing digital employee experience initiatives and helping organizations maximize the value of the Nexthink platform. His background spans a variety of technical and operational roles, bringing deep expertise in IT operations, service improvement, and customer success.