How do I choose the updates I want to install?

Salves 501 Reputation points
2022-07-06T20:07:02.337+00:00

Hi,

In the past until Windows Server 2012 we were able to choose the updates we wanted to install by selecting the checkbox.

I think from 2016 onwards we do the search and automatically everything that Microsoft decides to install is installed.

Recently we are participating in some incompatibilities with windows updates and I want to know if it is possible to select what we want to be installed.

For example:

Case 1

During the update process some VMware update was installed where the server lost network connectivity, but we didn't know that Windows would download these updates.

Case 2

During the update process KB501466 was installed which to my surprise is not security, but I swore that Windows Update only installed security updates unless I chose any of the advanced options.

Given these scenarios, what solutions can I apply to prevent this from happening in the manual process where I don't have a WSUS?

Below are my current Windows Update settings:

218255-screenshot-2022-07-06-170224.png

218332-screenshot-2022-07-06-170250.png

218333-screenshot-2022-07-06-171854.png

Thanks.

Windows for business | Windows Server | User experience | Other
0 comments No comments
{count} votes

Accepted answer
  1. Anonymous
    2022-07-06T20:52:41.337+00:00

    KB5014669 Is a cumulative update preview. Yes a rollup contains both security and non-security updates.
    https://www.catalog.update.microsoft.com/Search.aspx?q=KB5014669

    as far as preventing them; the best way may be to have your own WSUS at site where you can review and approve them.

    --please don't forget to upvote and Accept as answer if the reply is helpful--


2 additional answers

Sort by: Most helpful
  1. Anonymous
    2022-07-06T20:17:30.243+00:00

    The short answer is you don't unless you choose security only updates.
    https://support.microsoft.com/en-us/topic/windows-8-1-and-windows-server-2012-r2-update-history-47d81dd2-6804-b6ae-4112-20089467c7a6

    Security-only update
    An update that collects all the new security updates for a given month and for a given product, addressing security-related vulnerabilities. It's distributed through Windows Server Update Services (WSUS), System Center Configuration Manager and Microsoft Update Catalog. Security vulnerabilities are rated by their severity. The severity rating is indicated in the Microsoft security bulletin as critical, important, moderate, or low. This Security-only update would be displayed under the title Security Only Quality Update when you download or install the update. It will be classified as an Important update.

    Monthly Rollup
    The Monthly Rollup is product-specific and addresses both new security issues and nonsecurity issues in a single update. It will proactively include updates that were released in the past. Security vulnerabilities are rated by their severity. The severity rating is indicated in the Microsoft security bulletin as critical, important, moderate, or low. This Monthly Rollup would be displayed under the title Security Monthly Quality Rollup when you download or install. This Monthly Rollup will be classified as an Important update on Windows Update. It will automatically download and install if your Windows Update settings are configured to automatically download and install Important updates.

    --please don't forget to upvote and Accept as answer if the reply is helpful--


  2. Adam J. Marshall 10,356 Reputation points MVP
    2022-07-06T21:04:03.297+00:00

    Manual approval on a WSUS server is the only way. Realistically it doesn't take much effort each month to review them - 5-15 minutes per month to review and approve to a test group, and then to production a few days later after your 'testing-in-production' test systems are showing no signs of issues.

    https://www.ajtek.ca/wsus/how-to-setup-manage-and-maintain-wsus-part-1-choosing-your-server-os/


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.