Corporate policy can continue to control the machine even when not connected
to the corporate lan.
WindowsUpdate and AutoUpdate operations are recorded in
\%windir%\windowsupdate.log, so
notepad %windir%\windowsupdate.log
should open the log, which can be very large.
If you do an attempted update, you might take a look at the tail end of the
log file that records that attempt and see what you find there. If you need
help interpreting, you can post just that last snippet here. I don't have
much experience in interpreting them, but what will be of interest is what
server AutoUpdate is connecting to.
If your corporate network is distributing patches and updates via WSUS, the
administrator can enable Windows Update definitions to be distributed via
that mechanism.
--