Hi @fsdg ,
I agree with Andy, you could do the update follow the procedures of these articles.
To update the DAG members with new patches, the update process should be managed to prevent all of the DAG members from being offline at the same time. So you need to run the Move-ActiveMailboxDatabase -Server “ExchangeServerYouAreUpdating” cmdlet to perform server switchover to prevent activity on the server you are going to install updates. Perform a Server Switchover
And after the update and verify, run the same cmdlet on the second server then reboot, check the state and update.
In addition, this article Performing maintenance on DAG members has a detailed description for maintenance methods, and Installing updates on DAG members provides the steps to install updates on DAG members.
If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.