Wouldn't it be more accurate to say: If you're using WSUS or SCCM, you have the opportunity to stop this garbage in one place rather than chase it down in every user's computer?
That is, you can filter out selected updates in WSUS, but you still have to configure it to do so -- it's not like simply having the WSUS makes them magically go away.
Right?
No, those KBs were not distributed through the WSUS channel. I just double-checked my home lab and don’t have any of the Windows 10 updates in the subscription repo. Also, WSUS defaults to only installing critical and security patches. Most “important” updates are left for me to approve, and I usually go through them once every 3 months or so.
The default behavior of WSUS and SCCM is to only install critical and security updates. Until Microsoft makes the Win10 nag updates “critical,” it’ll never get pushed down in a corporate environment. And in my experience, MS TAMs notify their EA customers well in advance of anything like that. Hell, our TAM practically pollutes our inboxes with notices.