Disable Security and Critical Updates in UMC when Maintenance Configurations are assigned to VM

Moritz von Witzleben 5 Reputation points
2023-01-26T10:50:08.49+00:00

Hello,

I have a question regarding the Maintenance Configurations in the UMC.

To assign VMs to a Maintenance Configuration, the VM requires the following property "osProfile.windowsConfiguration.patchSettings.patchMode": "AutomaticByPlatform".

As I understand this article, this setting also means that Security and Critical Updates are automatically installed by Azure. What happens if I want to postpone a Security or Critical Update and therefore don't inlcude it in my Maintenance Configuration? Will this Update still be installed by Azure?

Kind regards

Moritz

Azure Update Manager
Azure Update Manager
An Azure service to centrally manages updates and compliance at scale.
219 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Moritz von Witzleben 5 Reputation points
    2023-01-27T09:28:19.89+00:00

    Ok I found the answer: Scheduling recurring updates in Update management center (preview) | Microsoft Learn

    => If a VM is assigned to maintenance configuration, security and critical updates are only managed by the maintenance configuration.

    Can be closed.

    1 person found this answer helpful.