I've had several users refuse to restart their workstations after updates. One has dozens of browser tabs open and worries about losing them, while another treats nearly three months of uptime like an achievement. I've explained that patches may not take effect until the machine restarts and that browsers can usually restore sessions, but they still argue that IT doesn't understand their workflow. Meanwhile, some of these same machines are experiencing freezes and performance problems. Management also doesn't want to enforce reboot requirements because of possible productivity disruption. Is this a common problem, and what policies or technical solutions have worked for getting users to reboot when security updates require it?
4 Answers
Get management and security leadership to approve the process in writing. Explain that delaying reboots leaves patches pending and increases exposure to vulnerabilities, while an overnight maintenance window limits disruption. Document machines with excessive uptime and the risks involved so the decision is clearly a business and security decision, not an IT preference.
For the tab excuse, show users how to restore their previous browser session, bookmark a group of tabs, or save important research somewhere more durable. Also clarify that choosing Shut Down may not be the same as using Restart when fast startup is enabled. A real restart is often the quickest way to clear update and performance problems.
When troubleshooting, keep the wording simple and procedural: “A restart is required before we can continue.” Check the actual uptime rather than relying on the user’s claim, record the instruction in the ticket, and close or pause the request until the restart is completed. Once users see that the reboot consistently resolves freezes and pending updates, resistance usually decreases.
The most effective approach is to stop making this a user-by-user debate. Set a maintenance policy with warnings and a reasonable postponement window, then force the restart after that window expires. For example, give users several hours or a few days to choose a convenient time, followed by an automatic overnight reboot. Patch-management or device-management tools can usually handle the notifications and enforcement.

That makes sense. The biggest obstacle is getting leadership to formally accept the risk instead of leaving support staff to negotiate with every user.