Its been a nightmare with this new feature!
We have windows update managed by a different system and not interested to enable this feature (as its consumes one additional lic per server). As our tenant has auto discovery enabled (e.g. for IIS, SQL, AD server etc we want them to be discovered), its also adding windows update.
I know the configuration rule above is a workaround, but the better and more elegant solution would be to provide a global configuration option in the tenant in the admin section something like "Auto discover service options" and allow to enable/disable such auto discovery, and should have been disabled by default.
Why you release a product and then ask your customer to go through the pain to tackle it! Product team should have considered this fact, specifically when its a lic component and it costs money!