Don’t do this. Do not disable the Windows Update services. It’s the wrong approach, and it’s a bad idea. Instead change the group policy (or local policy on each computer if there is no domain) for ‘Configure Automatic Updates’ and set it to “2 – Notify for download…” Any machine that is configured for setting 2 will *NOT* automatically download updates anymore. Then you can use BatchPatch for this process.
To do this… In the Group Policy / Local Policy editor (gpedit.msc) go to ‘Computer Configuration > Administrative Templates > Windows Components > Windows Update’. Set the “Configure Automatic Updates” setting to 2.
Also make sure you do not have ‘Dual Scan’ enabled on your computers. More here:
dual-scan-difficulties-with-windows-update-on-windows-10-versions-1607-anniversary-update-and-1703-creators-update
deciphering-dual-scan-behavior-in-windows-10