And make the updates opt-in. Sure, it's better for security to stay fully up-to-date, but if someone wants to never update their desktop, it's on him if he gets hacked.
In commercial systems, the sysadmins should be responsible for validating and determining the necessity of updates.