Hi Miller,
For your 100 Azure Arc–connected Windows Server 2012 systems, you can automate patching using Azure Update Management.
You can find detailed configuration steps here: Configure Windows update settings for Azure Update Manager
However, may I confirm whether all of your Windows Server 2012 R2 machines have Extended Security Updates (ESU) in place? Since the OS is past its end of support, ESU is essential to continue receiving security patches.
More information is available here: Windows Server 2012/R2: Extended Security Updates