Hi Piot Nowak,
To protect your accounting department from disruptive interface changes during the end-of-year audit, you can precisely isolate major OS upgrades from monthly security patches using a Group Policy Object. In your Group Policy Management Editor, navigate to Computer Configuration, Administrative Templates, Windows Components, Windows Update, and open the folder named Manage updates offered from Windows Update. Within this directory, double-click the policy titled Select when Feature Updates are received, set it to Enabled, and enter 90 in the options pane to defer the major annual build.
This configuration instructs the local Windows Update engine to calculate a strict 90-day delay from Microsoft's public release date before the upgrade becomes visible to the client machines. By leaving the companion policy for quality updates unconfigured, monthly security fixes will continue to download and install on their normal schedule, maintaining your required security posture without risking any sudden changes to the operating system layout.
Domic V.