This FAQ explains how Atera's Configuration Policies help IT admins centrally manage Windows updates and device reboots across all endpoints. If you're seeing a restart prompt you can't postpone, an update option that's greyed out, or a message that a device is "managed by your organization," this is where those settings live - covering restart timing, active hours, and how much control end users get over the prompt.
Overview
Q: What is a Configuration Policy in Atera?
A: A Configuration Policy allows you to centrally control patching and reboot settings for Windows devices. Policies can be applied at the Customer, Folder, or Agent level to maintain consistency and compliance across your environment.
Setting up a Configuration Policy for Windows updates
Q: How do I set up a Configuration Policy for Windows Updates?
A: When creating a policy, you can:
- Enable "Control via Atera's IT Automation Profiles (Recommended)" for full centralized patch management, or
- Choose "Allow automatic Windows local updates" to let devices manage updates independently.
- Create a new policy
How policy inheritance and Group Policy interact
Q: How does policy inheritance work?
A: Configuration Policies follow a hierarchical structure:
- Customer-level policies apply to all Folders and Agents unless overridden.
- Folder-level policies override Customer-level ones.
- Agent-level policies override both.
- Assign a policy
Q: Does Atera override existing Group Policy Objects (GPO)?
A: No. Domain GPOs always take precedence. Atera Configuration Policies do not override or remove GPO settings.
Managing power or sleep settings
Q: Can I manage power or sleep settings with a Configuration Policy?
A: No. Configuration Policies control Windows update behavior and the device restarts that follow patching. They cannot manage a device's general power or sleep settings, and there is no other place in Atera to configure them. Power settings are controlled by the device's local configuration or by a domain Group Policy Object.
Disabling, unassigning, or removing a policy
Q: What happens if I disable, unassign, or delete a policy?
A: Disabling or deleting a policy stops enforcement but does not automatically revert device settings. To restore original configurations, select "Revert to device settings" before removing the policy.
Q: Why do some devices remain locked or have grayed-out Windows Update options after policy removal?
A: If Atera previously managed updates, registry keys may persist. To resolve this:
- Reassign the policy.
- Set it to "Allow automatic Windows local updates."
- Wait for enforcement, then remove it again. You can also manually clear registry entries if needed.
How and when Configuration Policy changes take effect
Q: How often are Configuration Policies enforced?
A: When a Configuration Policy is assigned per device, its settings are applied instantly. However, when assigned at the Customer or Folder level, enforcement occurs approximately every 12 hours to ensure all devices receive the updated settings.
Q: When are changes applied after updating a policy?
A: Updates take effect within 10-12 hours. Offline devices apply changes the next time they check in.
Restart options after updates
Q: What are the restart options after updates?
A: You can customize reboot behavior to:
- Allow user control over restarts
- Set restart delays (15-180 minutes)
- Restrict restarts to outside active hours
- Force reboots after a set number of ignored prompts
- Policy behavior
Confirming whether Atera caused a restart
Q: How can I tell whether Atera caused a device to restart?
A: Atera always initiates restarts using shutdown.exe. To confirm the source of a restart, open Event Viewer on the device and check which process triggered it. If the restart came from a Windows system process such as TrustedInstaller, Windows initiated it, not Atera - Windows can restart a device on its own to complete an operating system upgrade or other maintenance, regardless of which Configuration Policy is assigned to it. A restart triggered by another process, such as StartMenuExperienceHost.exe, points to a problem with Windows on that device rather than to Atera.
How reboot popups and notifications work
Q: How do reboot popups and notifications work?
A: Users receive toast notifications reminding them to restart. After the configured number of ignored prompts, a forced reboot occurs automatically.
Restart prompt countdown
Q: Can the restart prompt show how many days remain before a forced restart?
A: No. The restart notification does not display a day-by-day countdown. You can set how often the prompt is sent and how many prompts appear before a restart is forced, but the prompt itself does not show the number of days remaining.
Letting end users control device restarts
Q: Can I allow end users to control device restarts?
A: Yes. You can let users postpone reboots and only enforce them after multiple missed notifications.
Configuration Policies and IT Automation Profiles
Q: How do Configuration Policies interact with Automation Profiles?
A: Configuration Policies override the "Reboot if needed" setting in IT Automation Profiles. Reboots follow the policy's defined rules, not automation defaults.
Restart delays during Windows version upgrades
Q: Can a Configuration Policy delay the restart after a Windows version upgrade?
A: No. Windows 10 and Windows 11 version upgrade tasks enforce a mandatory restart that overrides Configuration Policies and user notifications. This restart cannot be postponed by "Reboot if needed" or by any Configuration Policy setting. Schedule upgrade tasks outside business hours, and run them in a separate IT Automation profile from regular patching.
Supported devices, operating systems, and restart scheduling limits
Q: Do Configuration Policies affect all device types?
A: Most options apply to Windows 10, Windows 11, and Windows Server 2022+. Some features, such as toast notifications, are not supported on servers.
Q: Do Configuration Policies work on Windows Home editions?
A: No. These settings rely on Group Policy support, which is not available in Windows Home editions.
Q: Why are some Windows restart scheduling options not working on certain Windows Server versions?
A: Some advanced restart scheduling features, such as Active Hours-based restarts or delayed restart timing, are not supported on Windows Server 2016 and Windows Server 2019. Configuration Policies interact directly with the Windows Update Agent (WUA) built into each operating system, and Windows Server 2016 and 2019 are Long-Term Servicing Channel (LTSC) versions based on older Windows 10 core builds (1607 and 1809) that don't include the newer Windows Update for Business capabilities required for granular restart scheduling. Because of this, certain reboot timing options may appear configurable in Atera but will not execute on those server versions. For full restart scheduling functionality, use Windows 10 (newer builds), Windows 11, or Windows Server 2022 and later.
Manually running Windows Updates while a policy is active
Q: Why can't users manually run Windows Updates when a policy is active?
A: When "Control via Atera's IT Automation Profiles" is enabled, manual update access is disabled. Switch to "Allow automatic Windows local updates" to restore it.
Manually reverting a device to default Windows Update behavior
Q: How can I manually revert a device to default Windows Update behavior?
A: First unassign or remove any active Atera configuration policies. Then delete (or set to 0) the registry values SetDisableUXWUAccess in HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate and NoAutoUpdate in HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU. Finally, restart the Windows Update service or reboot the device completely. This restores manual update controls and the standard Windows Update interface for end users.
"Check for updates" button greyed out
Q: What should I do if the "Check for updates" button is still grayed out?
A: Ensure the policy is set to allow updates, wait for it to sync (up to 12 hours), and reboot the device if necessary.
Old "Last checked" date in Windows Update
Q: Why does Windows Update show an old "Last checked" date on a device Atera is patching?
A: When Windows update settings are set to "Control via Atera's IT automation profiles," the local Windows Update interface is disabled and stops refreshing its "Last checked" date. Atera continues to check for and install patches in the background - the date shown in Windows Update does not reflect Atera's patching activity.
Troubleshooting missing user notifications
Q: How can I troubleshoot missing user notifications?
A:
- Confirm Windows notification settings are enabled.
- Verify that local or domain GPOs aren't blocking toast notifications.
- Reboot the device after enabling notifications.
Policy auditing and alerts
Q: How are policy changes tracked or audited in Atera?
A: Every edit, assignment, or deletion of a Configuration Policy is logged under Admin > Users and security > Audit log.
Q: Are policy changes sent as alerts to admins?
A: No. Atera does not generate real-time alerts for policy changes. However, all actions are recorded in the Audit Log for compliance and review.