User at $location: We bought a new module for this horrible software we use, can you install for us please? IT: *reads module requirements*

A lot of them can be. But it's inconvenient, and often enough the users will want to move data on and off them with USB drives, so the air gap breaks down, and now somebody's got to clean up a mess of persistent infected USB drives.

But if you keep it online and updated, sometimes you'll hit the other problem: being unable to (programmatically) prevent updates unprivileged. If you've got an overnight run on a high duty cycle system like an autosampled HPLC, the first step of the win10 instructions is often "set windows to delay updates for 7 days." This is usually not a problem when the user-side's IT department has scheduled updates and maintenance windows, but a ton of places don't.

/r/sysadmin Thread Parent