What’s New in Deep Freeze Enterprise 10.20
Happy to announce that Deep Freeze now runs on Windows on ARM. Windows Update category selection has been rebuilt from the ground up, which is the change most likely to show up in your next maintenance window. And four Windows features that interact with the Frozen state — Fast Startup, Daylight Saving Time, Event Log sizing and LAPS timing — are now handled by Deep Freeze itself. A range of fixes ships alongside them.
Release Snapshot
- Windows ARM support
- Windows Update categories redesigned — all categories retrieved by default, with opt-in Feature, Driver and Microsoft Product Updates
- New Turn on Windows Fast Startup option
- New Set Hardware Clock to UTC option for Daylight Saving Time
- Event Log ThawSpace now sizes itself automatically
- Manage LAPS settings applied while the workstation is still Thawed
- LDAP Groups now work against servers with TLS 1.0 disabled
- Cloud Connector resolves your assigned server at sign-in
- Fixes across the Console, workstation and update handling
Deep Freeze Now Runs on Windows ARM
ARM-based Windows machines have been arriving in fleets for a few years now: Surface Pro X, Surface Laptop and Snapdragon-based systems.
Deep Freeze Enterprise 10.20 adds support for these devices, so they can be protected under the same configurations and scheduled tasks as the rest of your fleet.
Windows Updates: Everything by Default, Exceptions by Choice
This is the change I would look at first, because it will alter what Windows Updates actually install on your workstations.
Windows 10 and 11 classify updates differently than Windows 7 did. Alongside Security and Critical updates, Microsoft now delivers quality updates, monthly cumulative updates, servicing stack updates and update stack packages, and many Security and Critical updates list those newer categories as prerequisites. A category selection limited to Security and Critical updates no longer maps to the way Microsoft delivers updates today, and 10.20 brings Deep Freeze in line with the current model.
In 10.20, selecting the Microsoft Windows Update service retrieves all Software Updates by default. There is no category selection to get wrong. Three checkboxes let you add back what you actually want to control:
- Include Feature Updates — the version upgrades, such as 24H2 to 25H2. Off by default, so you decide when to move.DF Windows Update Categories Change Document
- Include Driver Updates — new in 10.20, covering drivers that install without user interaction.
- Include Microsoft Product Updates — also new, and a direct result of customer requests. Office, OneDrive and other Microsoft products.
The Security & Critical Updates option has been retired. It reflected the Windows 7 classification model, which no longer matches how Windows 10 and 11 categorize updates.
What to do after upgrading: plan for a longer first maintenance window, because updates outside the previously selected categories will now be retrieved together. Schedule the Windows Update task with When Windows Update completes so the task is not cut short. Then decide whether you want drivers and Microsoft product updates turned on — neither was ever applied by earlier versions, so leaving them off keeps your current behavior. Full details are in this post.Â
Four Windows Features That Now Work With Deep Freeze
Windows Fast Startup, the hardware clock, Event Log retention and LAPS password rotation all interact with the Frozen state. In 10.20, Deep Freeze manages each of them directly, so they behave the way you expect on a protected workstation instead of having to be worked around.
- Windows Fast Startup. A new Turn on Windows Fast Startup option brings the setting into the Configuration Administrator. Fast Startup saves the session to disk instead of performing a full shutdown, so having it under Deep Freeze keeps a Frozen workstation predictable across a power cycle.
- Daylight Saving Time. A new Set Hardware Clock to UTC option keeps a Frozen machine on the correct time through a DST change, when the hardware clock and the operating system can otherwise disagree briefly at startup. Not applicable in regions that do not observe DST.
- Event Log sizing. Â The Event Log ThawSpace now sizes itself to your configured log limits and grows automatically when those limits change, so retained logs always have the space Windows expects.
- LAPS timing. Deep Freeze applies LAPS settings while the workstation is still Thawed, just before the Frozen reboot, keeping password rotation in step with AD and Entra ID.
Console and Directory Connections
Two changes to how the Console reaches directory servers and Deep Freeze Cloud:
- LDAP over modern TLS. LDAP Groups in the Enterprise Console now connect to directory servers over current TLS versions, including servers with TLS 1.0 disabled.
- Cloud Connector server discovery. The Cloud Connector now resolves your assigned Deep Freeze Cloud web server when you sign in, instead of pointing at a hard-coded one.
Fixes
This build resolves a range of issues. Below are some key ones, but review the full release notes for more details:
- LDAP Groups failing when TLS 1.0 is disabled. Multiple organizations reported the Enterprise Console returning “Unable to extract data from LDAP Server” after hardening their directory servers. This was the oldest open item on the list.
- Explorer crashing when Event Log space ran out. Explorer.exe could crash or hang once the Thawed folder holding the Event Logs filled up. The auto-sizing change above is the permanent fix.
- Fast Startup retaining data through a shutdown. On Windows 10 and 11, Frozen workstations could keep changes across a shutdown because Fast Startup meant Windows never fully shut down.
- Windows Updates not installing. Reports covered updates not detected or installed at all, .NET updates handled incorrectly, and Windows 11 25H2 downloading but never applying. The category redesign addresses the root cause.
For the complete list, see the Deep Freeze Enterprise release notes.
How to Get 10.20
Deep Freeze 10.20 is being made available in phases, with accounts enabled on a rolling basis. If you would like it sooner, contact Faronics Technical Support, and we will provide access.




