SHARE
Facebook X Pinterest WhatsApp

Windows Patch Management, Options in Windows Update

Written By
thumbnail Marcin Policht
Marcin Policht
Jul 20, 2010
ServerWatch content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More



The previous article in this series presented a number of solutions using scripting and third-party freeware utilities to enable remote query registry and patch deployment. We continue our coverage of free patching methodologies with a focus on Microsoft’s operating system enhancements and products.

The most basic patch-related technology available in Windows 2000 and above is Windows Update. The functionality relies on cooperation between client and server components, but gives administrators a host of options for configuring the tool. We continue our patching series with a focus on these choices.

The most basic patch-related technology available in Windows ME, 2000, XP, and 2003 is Windows Update. Its mechanism is based on the cooperation between a client and server components. The client operates as the Automatic Updates service running in the security context of the Local System account (with the exception of Windows ME, where it is implemented as an executable loaded at the time of a user’s logon). The service starts at the operating system startup (although you can disable it or use various customization options to alter this default behavior).

Clients are configured to connect to Windows Update servers automatically and receive a list of missing updates, based on a comparison of the client configuration data (such as operating system and Internet Explorer versions, hardware plug-and-play information, regional and language settings, and patch-level status) against Windows Update Catalog (located at http://windowsupdate.microsoft.com).

Updates for the legacy operating systems (not supporting Windows Update functionality) are available through the Microsoft Download Center at the following locations:

Windows Update evolved from Critical Update Notification utility available for Windows 98 and pre-SP3 Windows 2000. The first version was released around the same time as Windows 2000 SP3; however, it also works on Windows 2000 SP2 computers. The most significant improvement between the two was the Automatic Update feature, which allows custom scheduling that can be configured in several ways:

  • In a graphical interface via a Control Panel applet (i.e., the Automatic Updates tab in the Properties dialog box of System applet in Windows XP and 2003 or the Automatic Updates applet in Windows 2000 and ME) the interface presents the option in a checkbox format. Its state (checked vs. unchecked) determines whether you want to use automatic updates. This also affects whether the remaining options on the same page are relevant. Assuming the checkbox is enabled, you will need to choose from three options that control the level of automating download and installation.

     

    1. Manual Download and Installation — The user is notified (via an icon appearing in the notification area, in the right corner of the Windows taskbar) when updates are ready for download, and again when they are downloaded and ready for installation.
    2. Automatic Download and Manual Installation — The user is notified when a (automatically initiated) download is completed, and at that point he or she can select updates to be installed.
    3. Automatic Download and Installation — Both download and installation are transparent to a logged-on user (although, to be exact, the level of this transparency depends on the user’s security privileges). Both actions are performed according to a customizable schedule (daily at a specified time or weekly on a given day of the week and at a specific time).

     

  • In Windows 2000, XP, and 2003 local group policy is another option. To manage Windows Update with group policies, WUAU.ADM must be part of the Administrative Template. The most up-to-date version of this template (including features required for Software Update Services SP1) is available for download from the Microsoft Web site at http://www.microsoft.com/downloads/details.aspx?FamilyId=D26A0AEA-D274-42E6-8025-8C667B4C94E9&displaylang=en.

    After downloading the template, copy it to the inf subfolder in the Windows installation directory (typically C:WINDOWSinf). Next, launch the local Group Policy Editor (gpedit.msc), expand the Computer Configuration node, right-click on Administrative Templates, and select Add/Remove Templates. If WUAU is not already listed there, add the one copied to the WINDOWSinf subfolder.

thumbnail Marcin Policht

Marcin Policht obtained his Master of Computer Science degree about 20 years ago and has been since then working in the Information Technology field, handling variety of responsibilities, but focusing primarily on the areas of identity and access management, virtualization, system management, and, more recently private, hybrid, and public cloud services. He has authored the first book dedicated to Windows Management Instrumentation and co-written several others dealing with subjects ranging from core operating system features to high-availability solutions. His articles have been published on such Web sites as ServerWatch.com and DatabaseJournal.com. For his contributions to the Microsoft technical community, he has been awarded the title of Microsoft MVP over the last ten years.

Recommended for you...

What Is a Container? Understanding Containerization
What Is a Print Server? | How It Works and What It Does
Nisar Ahmad
Dec 8, 2023
What Is a Network Policy Server (NPS)? | Essential Guide
Virtual Servers vs. Physical Servers: Comparison and Use Cases
Ray Fernandez
Nov 14, 2023
ServerWatch Logo

ServerWatch is a top resource on servers. Explore the latest news, reviews and guides for server administrators now.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.