Prerequisites for Azure Update Manager

This article summarizes the prerequisites, the extensions for Azure VM extensions and Azure Arc-enabled servers and details on how to prepare your network to support Update Manager.

Prerequisites

Azure Update Manager is an out of the box, zero onboarding service. Before you start using this service, consider the following list:

Arc-enabled servers

Arc-enabled servers must be connected to Azure Arc to use Azure Update Manager. For more information, see how to enable Arc on non-Azure machines.

Support matrix

Refer support matrix to find out about updates and the update sources, VM images and Azure regions that are supported for Azure Update Manager.

Roles and permissions

To manage machines from Azure Update Manager, see roles and permissions.

VM extensions

Azure VM extensions and Azure Arc-enabled VM extensions are required to run on the Azure and Arc-enabled machine respectively for Azure Update Manager to work. But separate installation is not required as the extensions are automatically pushed on the VM the first time you trigger any Update Manager operation on the VM. For more information, see the VM extensions that are pushed on the machines

Network planning

To prepare your network to support Update Manager, you might need to configure some infrastructure components. For more information, see the network requirements for Arc-enabled servers.

For Windows machines, you must allow traffic to any endpoints required by the Windows Update agent. You can find an updated list of required endpoints in issues related to HTTP Proxy. If you have a local WSUS deployment, you must allow traffic to the server specified in your WSUS key.

For Red Hat Linux machines, see IPs for the RHUI content delivery serversfor required endpoints. For other Linux distributions, see your provider documentation.

Configure Windows Update client

Azure Update Manager relies on the Windows Update client to download and install Windows updates. There are specific settings that are used by the Windows Update client when connecting to Windows Server Update Services (WSUS) or Windows Update. For more information, see configure Windows Update client.

Next steps