Microsoft have rated the ability for non-admin users to stop Windows patching as a moderate issue and closed the case.
EDR providers, including Microsoft, probably want to add signatures for junction points from \inetpub being created on boot drive as it doesn’t look like this will be fixed any time soon.