Azure Update Manager KBIDs inclusions in a maintenance configurations for a VM Patching

Garg,Srishti 40 Reputation points
2025-04-17T10:15:50.9733333+00:00

I have onboarded Azure Update Manager to patch windows/linux servers based on customer managed schedule as per different maintenance configurations. Now as I am doing patching after microsoft release its updates so previous months updates are getting superseded by new updates. To resolve this, I want to include specific previous months patches to the existing schedule using either powershell or maintenance configurations (used below powershell cmdlet for).
I tried testing it manually, adding KBIDs, to include in an existing schedule and also through one time update but it didn't worked.
I need help to understand if it is feasible to implement. Can we do these inclusions ?If yes, help me with the ideal process.

Also I have enabled periodic assessment on the VMs. How can we reduce the frequency of VM patching assessments?User's image

Azure Update Manager
Azure Update Manager
An Azure service to centrally manages updates and compliance at scale.
368 questions
{count} votes

Accepted answer
  1. Ashok Gandhi Kotnana 7,410 Reputation points Microsoft External Staff Moderator
    2025-04-23T12:17:17.77+00:00

    Hi Garg,Srishti

    1. Will KBIDs inclusion work on an existing maintenance configuration?

    Yes, it will. Go to the maintenance configuration, click on Updates, and include the required KBID(s).

    1. Should KBIDs be included in the pending updates catalog or will it install even if not in the catalog?

    Once the KBID is added to the maintenance configuration, it will be installed during the next scheduled run, along with other pending updates—even if it’s not currently listed in the catalog. (as long as it's still applicable and available from Windows Update or WSUS).

     3. Is there an alternative to install missing updates that were superseded by newer patches released on Patch Tuesday?

    If you’re noticing gaps or missing updates from previous months, there are two approaches:

     

    Recommended: Schedule your maintenance configuration after the second Tuesday of every month (Patch Tuesday) to ensure all updates, including superseded ones, are considered.

     Alternative: Refer to the official Microsoft documentation for monthly updates. Then, check the update history on the VM and manually include any missing KBIDs in the existing maintenance configuration. 

    User's image

    Please let me know if you face any challenge here, I can help you to resolve this issue further

    Please provide your valuable comments User's image

    Please do not forget to "Accept the answer” and “upvote it” wherever the information provided helps you, this can be beneficial to other community members.it would be greatly appreciated and helpful to others.

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.