Appearance
Windows Updates
Windows update rings let operators approve specific Microsoft updates for defined groups of Windows endpoints.
Open Software > Windows Updates to manage the Ordyn repository, rings, and approvals.
An update ring combines three things:
- one or more direct assignments that determine the ring's endpoint scope
- an approval decision for each discovered Microsoft update revision
Approving an update does not install it immediately. Installation starts only when a job containing the Install approved Windows updates task runs against an endpoint.
Requirements and limitations
Windows update rings apply to Windows endpoints and approve exact Microsoft Update revisions. Inventory can be collected from Windows Update or Microsoft's offline scan catalog. The installation job can download approved revisions from Windows Update or use content prepared in the Ordyn repository.
The following limitations apply:
- WSUS is not an installation source for approved-update tasks.
- Offline catalog inventory supports the
Security Updates,Service Packs, andUpdate Rollupsclassifications. Use an online source or WSUS to inventory definition updates, drivers, firmware, feature packs, tools, general updates, and upgrades. - The offline scan catalog does not contain the complete Microsoft Update catalog. Content that Microsoft omits from the offline catalog cannot use the Ordyn repository path.
- Vendor tools and other update channels are outside the ring workflow.
- The endpoint must report update inventory before its missing updates can appear in a ring.
- A ring must be enabled and effective before an installation task can apply.
- The Ordyn repository path requires a Runner pool, a current offline catalog, imported update content, and an active Cache Node for the endpoint.
- Offline catalogs older than 45 days are rejected. A weekly catalog download schedule is recommended when the repository path is used.
Use Update Inventory when you need a fleet-wide view that is not scoped to one ring.
Review the Ordyn repository
Select Ordyn repository above the update-ring tree to review Windows update files prepared for endpoint installation.
The Updates tab lists exact Microsoft Update revisions discovered through offline inventory. It shows each update's import state, required and verified file counts, stored size, associated offline catalog, and import time. Ready updates are shown by default. Use the status filter to include missing files, files awaiting malware verification, detected malware, or failed scans.
Open an update to inspect its Microsoft metadata and required content files. A content file can be downloaded after malware verification marks it as clean.
The Offline catalogs tab lists downloaded wsusscn2.cab files. It shows whether each catalog is current or older than 45 days, its verification state, size, checksum, and import time. A catalog can be downloaded after malware verification marks it as clean. Links from endpoint inventory history filter this table to the exact referenced catalog.
Users with Windows Update management access can select updates or offline catalogs, right-click the selection, and delete the imported repository content.
Deleting an update keeps its endpoint inventory, approval decisions, and history. Deleting an offline catalog moves affected updates to their newest remaining imported catalog when one is available. Inventory history retains the deleted catalog's name, checksum, size, and import time and marks it as no longer available. Files shared by other updates or catalogs are retained. Content referenced by an active job cannot be deleted until that job finishes or is aborted.
Infrastructure jobs can import deleted catalogs and approved update content again.
Organize rings
The tree on the left side of the Windows Updates page contains update-ring folders and rings.
Use the Actions menu to:
- add a folder
- create an update ring
- create nested folders inside an existing ring folder
- rename or delete a ring folder
Ring folders only organize the Windows Updates tree. They do not assign the contained rings to endpoints.
An Endpoint folder assignment refers to a folder from the Endpoints area and includes endpoints in that folder and its descendant folders.
Create a ring
To create a ring:
- Open
Software>Windows Updates. - Select
Actions>New update ring. - Enter a name and optional description.
- Select the ring folder or leave the ring at the root.
- Enter the default automatic approval delay in whole days. The default is
0days. Rules use this value unless they define an override. - Keep
Ring enabledselected when the ring should be eligible to control endpoints and install approved updates. - Save the ring.
A disabled ring remains available for review, but it does not install approved updates on endpoints.
Ring detail tabs
Each ring has four tabs.
Overview
The Overview tab contains the update approval table.
It shows Microsoft updates reported as missing in the ring, revisions scheduled for automatic approval, and recorded decision history. The table includes:
- update title and KB article IDs
- classification
- update type (
Software,Driver, orFirmware) - automatic or optional driver offer type
- Microsoft revision number
- number of effective endpoints reporting the update as missing
- availability (
Current,Installed, orExpired) - decision state
- last-seen time
Use the table controls to search, sort, and filter by decision state, availability, update type, and driver offer type. Current and installed revisions are shown by default. Select Expired in the availability filter to include decision history for revisions that no effective endpoint currently reports as missing or installed.
Assignments
The Assignments tab lists the tenant, endpoint-folder, endpoint-group, and endpoint scopes assigned directly to the ring. Each target links to its corresponding page.
Select Actions > Assign from the ring header to add an assignment. Select assignments with their row checkboxes, then right-click the selection to open targets or remove one or more assignments.
Rules
The Rules tab lists the reusable automatic approval rules assigned to the ring. The Approval delay column shows whether each rule inherits the ring default, approves immediately, or uses a custom number of days.
Select Assign on the right side of the tab row to assign rules. To unassign rules, select them with the table checkboxes, then right-click the selection and select Unassign rule or Unassign selected. Ctrl and Shift selection are supported. Assigning a rule evaluates updates that Ordyn has already discovered as well as future update revisions.
Endpoints
The Endpoints tab lists the endpoints for which the ring is effective.
The table shows:
- endpoint and hostname
- tenant
- operating system
- ring membership status and ring assignment conflicts
- the assignment that selected the ring
- last reconciliation time
Open an endpoint row to inspect that endpoint in the Endpoints area.
Endpoints with an equal-precedence ring conflict appear under every candidate ring with a Conflict status, but they are excluded from the ring's update catalog and cannot run the approved-update installation task.
Set up an update ring workflow
The complete setup uses a Windows Update Policy profile, direct ring assignments, update inventory collection, and an installation job:
- Open
Library>Configuration Profilesand create aWindows Update Policyprofile. - Set
Automatic updates modetoDisabled. - Set
Update sourcetoMicrosoft Update / Windows Update. - Set
Windows Update user accesstoBlockedwhen users must not manually scan for, download, or install updates. This also blocks interactive access for administrators. - Configure any optional schedule or restart settings required by your organization. Ring installation itself does not restart endpoints.
- Assign the policy to the required tenant, endpoint folder, endpoint group, or endpoint scope.
- Use
Remediatebehavior when Ordyn should apply the policy. UseAudit onlywhen GPO or MDM applies the settings and Ordyn should check them. - Run or automate the Windows Update Policy as required for your environment.
- Create or edit an endpoint job with
Collect Windows update inventory. SelectMicrosoft Updatefor the full online catalog orOffline catalogfor disconnected inventory. Offline inventory supportsSecurity Updates,Service Packs, andUpdate Rollups. - When using offline inventory, create an infrastructure job with
Download offline Windows update catalog, select a Runner pool, run it once, and schedule it about once every seven days. - Run or schedule update inventory collection for the intended endpoint scope.
- Open
Software>Windows Updates, create the ring, and configure its default automatic approval delay and rules. - Open the ring's
Actionsmenu, selectAssign, and choose the required tenant, endpoint folder, endpoint group, or endpoint. - Review the ring's
AssignmentsandEndpointstabs and approve the required revisions. - Create a job containing
Install approved Windows updates. - Select
Windows Updateto download approved revisions directly from Microsoft, or selectOrdyn repositoryto deploy imported content through the endpoint's Cache Node. - When using
Ordyn repository, create an infrastructure job withDownload approved Windows updates. Add aWindows update approvedautomation, run it manually after approvals change, or use a recurring schedule. - Run or schedule the installation job for the intended endpoint scope.
The Windows Update Policy and ring assignment scopes can differ. Ring membership does not inspect or enforce the Windows Update Policy.
Assign a ring
To assign a ring:
- Open
Software>Windows Updatesand select the ring. - Select
Actions>Assign. - Select
Tenant,Folder,Group, orEndpointas the destination type. - Search for and select the destination.
- Select
Assign.
Ring assignments are declarative. They change ring membership and do not change Windows Update settings on an endpoint.
An endpoint can match several ring assignments. Ordyn selects the highest-precedence assignment using this order:
- endpoint
- endpoint group
- deepest matching endpoint folder
- tenant
An assignment at a more specific level overrides matching assignments below it. Multiple assignments at the same highest precedence can select the same ring without creating a conflict.
If assignments for different rings match at the same highest precedence, no ring becomes effective and a ring installation job fails until the conflict is resolved. A common example is an endpoint that belongs to two groups assigned to different rings.
Each tenant, folder, group, or endpoint can be assigned directly to only one ring. Assigning the same target to another ring reports a conflict; remove its existing direct assignment first.
Deleting an assigned tenant, endpoint folder, endpoint group, or endpoint also removes its direct ring assignment. Removing an assignment or deleting its target does not change Windows Update settings.
Configure Windows Update policy
Ordyn recommends an effective, compliant Windows Update Policy that:
- sets automatic updates to
Disabled - sets
Update sourcetoMicrosoft Update / Windows Update
The policy can use Remediate behavior so Ordyn applies the settings, or Audit only behavior when GPO or MDM supplies the effective values.
Ordyn's ring installation job never changes Windows Update policy. Automatic reboot orchestration is disabled by default and can be enabled explicitly in the job step.
The ring workflow installs approved updates only when its job task runs. Set Windows Update user access to Blocked in the effective Windows Update Policy when interactive users must not start Windows Update outside Ordyn. The setting applies to administrators as well as standard users.
Use Windows Update notifications in the same policy to keep the default Windows notifications, show restart warnings only, or turn off all Windows Update notifications. This setting controls notification visibility and does not change installation or restart timing.
Use Quality update deferral to delay quality updates for up to 30 days after release. Set it to 0 to disable the delay, or leave it Not managed when Group Policy, MDM, or another management system controls the value. Online inventory and ordinary Windows Update scans respect the effective deferral.
Removing a ring assignment changes ring membership only. Manage the Windows Update Policy assignment separately when its endpoint configuration should also change.
Update grouping
Ordyn groups discoveries from different endpoints by the Microsoft Update ID and revision number. The update type remains part of each exact installation request.
This means:
- the same revision discovered on many endpoints appears once in the ring table
- the missing count shows how many non-conflicted intended endpoints currently report that revision as missing
- one approval applies that exact revision to all eligible endpoints in the ring
- a newly discovered revision requires its own decision
This prevents endpoint-specific inventory records from creating duplicate approval rows while keeping Microsoft revisions distinct.
Approve or reject updates
Each update has one of these ring-specific decision states:
Eligible: no decision has been recordedApproved: the ring installation job may install this exact revisionRejected: the ring installation job excludes this revision
Use the decision filter in the table header to include approved or rejected updates. Eligible updates include revisions currently missing from ring endpoints and revisions scheduled by an assigned automatic approval rule. An approved or rejected revision is marked Expired when no effective endpoint currently reports it as missing or installed. Expired decisions are hidden by default and remain available through the availability filter.
To update decisions:
- Select one or more rows with the checkboxes.
- Right-click the selection.
- Select
Approve,Reject, orClear decisionfrom the context menu.
You can also use the row context menu. Standard table selection is supported:
CtrlorCommandadds or removes individual rows from the selection.Shiftselects a range from the selection anchor.- The header checkbox selects or clears the loaded rows.
Clearing a decision returns the update to Eligible.
If an active automatic approval rule still matches the update, clearing its decision schedules it again. An overdue update can be approved again during the next automatic approval evaluation. Reject the update to suppress automatic approval for that ring and revision.
Decisions belong to one ring. Approving an update in one ring does not approve it in another ring.
Configure automatic approval rules
Select Automatic approvals above the update-ring tree to manage reusable matching rules.
To create a rule:
- Select
Actions>New automatic approval rule. - Enter a name and optional description.
- Set
Approval delaytoUse ring default,Approve immediately, orCustom delay. A custom delay can be from1through3650whole days. - Select at least one classification. Select
Driversfor Windows Update driver and firmware offers. - Optionally select products or enter an
Update name containsvalue. - For driver rules, optionally select providers, manufacturers, driver classes, device models, or hardware IDs.
- Keep the rule enabled and save it.
- Open a ring's
Rulestab and assign the rule.
To preview a saved rule, right-click that rule and select Preview. The preview opens separately and lists the most recently discovered Microsoft update revisions that currently match the rule.
Classification is required. Product, classification, and driver values are selected from metadata already reported by endpoints. Matching is case-insensitive:
- an update may match any selected product
- an update may match any selected classification
- every populated matcher group must match
- values within one matcher group use OR matching
Update name containsperforms simple substring matching and does not support regular expressions- driver provider, manufacturer, class, model, and hardware ID values use exact matching
Driver applicability can differ between endpoints even when Microsoft gives the update the same ID and revision. Driver and firmware updates discovered through online inventory can use the Windows Update installation source. Microsoft does not include their content in the offline scan catalog, so they cannot use the Ordyn repository source.
The approval date is calculated from the time Ordyn first discovered the Microsoft Update ID and revision. A rule's custom delay takes precedence over the ring default:
First discovered + effective rule delay = automatic approval date
A rule set to Use ring default uses the delay configured on each assigned ring. For example, the same inherited rule assigned to rings with defaults of 0, 3, and 5 days schedules the exact revision immediately for the first ring, after three days for the second ring, and after five days for the third ring. A rule set to Approve immediately is eligible during the next automatic approval evaluation in every assigned ring. A custom delay uses the same number of days in every assigned ring.
Discovery on any endpoint starts the shared delay calculation. A rule is scheduled for a ring only while at least one effective endpoint in that ring reports the update as missing and satisfies its applicability matchers. When several assigned rules match the same update, the matching rule with the earliest effective approval date is used. Equal dates are resolved consistently.
The update table shows scheduled automatic approvals with the rule name and approval date. Disabled rings show their schedules as paused. When a ring is enabled, an overdue update becomes approved during the next evaluation.
Before approval, a scheduled entry is removed when no effective endpoint in the ring reports the revision as missing or when the assigned rules do not match it. An Approved decision remains recorded until an operator changes or clears it.
Manual decisions take precedence. A manual rejection prevents a matching rule from approving that ring and revision. Editing, disabling, unassigning, or deleting a rule does not revoke approvals already created by the rule.
Automatic approval changes the ring decision. It does not start an endpoint installation job or reboot an endpoint. A Windows update approved infrastructure automation can react to the decision separately.
Prepare approved update content
Run Download approved Windows updates in an infrastructure job after approving updates that will use the Ordyn repository source. The task:
- resolves the content referenced by current offline inventory from eligible ring endpoints
- downloads missing files on a Runner from Microsoft
- imports the files into Ordyn
- submits the files to for malware-verification
The task skips files that Ordyn has already imported. A repository installation remains blocked until every required file for the exact approved update revision is available and verified as clean.
Content resolution uses each eligible endpoint's newest offline-catalog snapshot. A later online Microsoft Update or WSUS scan can become the endpoint's current inventory view without discarding the catalog and content evidence needed by the repository workflow.
Run this job whenever approvals change. You can add a Windows update approved event automation to the infrastructure job so manual and automatic approvals from enabled rings start it automatically. Configure a debounce to combine a burst of approvals into one run. Existing approvals in a disabled ring trigger when the ring is enabled.
A recurring schedule remains useful as a periodic safety net.
Install approved updates with a job
Use the dedicated job task for ring installations:
- Open
Operations>Endpoint Jobs. - Create or edit a job.
- Add the
Install approved Windows updatestask. - Select the update source:
Windows Updatedownloads the exact approved revisions directly from Microsoft. This is the default.Ordyn repositoryuses update content imported into Ordyn and delivered through the endpoint's Cache Node.
- Optionally select classifications or products to limit this job to a subset of the ring's approved updates.
Ordyn repositorysupportsSecurity Updates,Service Packs, andUpdate Rollups; the editor disables other classifications. Leave classifications empty to include all three. - Save the job.
- Run the job manually or configure a time automation.
When an endpoint reaches the task, Ordyn checks that:
- the endpoint has an effective ring
- the effective ring is enabled
- the endpoint has no equal-precedence ring conflict
- the endpoint reports the approved revisions as missing
With Windows Update, the endpoint contacts Microsoft Update and requests the exact approved IDs and revisions. This source does not use WSUS or the update source configured by endpoint policy.
With Ordyn repository, Ordyn also checks the endpoint's newest offline-catalog snapshot and requires its catalog to be no more than 45 days old. Every required file must be imported and verified, and the endpoint must have an assigned Cache Node. Ordyn synchronizes the required files to that Cache Node and the agent verifies every staged download.
Repository installation uses the endpoint system variable windows.update.ordyn_repository_install_strategy:
- unset or
automaticinstalls an approved revision with Windows servicing when its imported content contains one MSU package that unambiguously matches the update's KB number; additional MSU prerequisite packages are staged with it automaticuses the offline catalog and Windows Update cache for revisions that do not have that unambiguous MSU shapecopy_to_cacherequires the offline-catalog and Windows Update cache method for every approved revision
One task can install direct MSU revisions and Windows Update cache revisions together. A failed direct MSU installation is reported as a failure and is not retried through the cache method.
Both sources request the exact Microsoft Update IDs and revisions approved for the endpoint's effective ring and matching the job filters. Rejected, eligible, and nonmatching approved updates are not included. Windows performs its normal applicability checks before installing the content. Ordyn does not switch sources automatically when the selected source is unavailable.
Filters are inclusive. Multiple selected classifications match any selected classification, and multiple selected products match any selected product. When both filters contain values, an update must match both groups. With Windows Update, an empty classification filter includes all approved classifications. With Ordyn repository, it includes all supported offline-catalog classifications. To run a frequent Defender-only job through Windows Update, select Microsoft Defender Antivirus under products and leave classifications empty to include all Defender update classifications.
While the task is running, its details list the approved updates sent to the endpoint. After Windows finishes, the details separate successfully installed updates from updates that failed to download or install. Failed entries include the Windows error code when one is available.
A successful task can report that no approved updates were applicable. This means Windows did not offer any of the requested revisions to that endpoint at execution time; it is not an installation failure. The task details show the requested, discovered, and matched update counts to make that outcome explicit.
One job can target endpoints from multiple rings. Ordyn resolves every endpoint independently, so each endpoint receives only the approvals from its own effective ring. An endpoint without an effective ring, with a disabled effective ring, or with an equal-precedence conflict fails safely without installing updates.
An approval changes what a later endpoint job execution can install; it does not modify an already delivered endpoint task. A configured Windows update approved automation can start an infrastructure job, but it never starts the endpoint installation job.
See Available Tasks for the job task reference.
Reboot behavior
Automatic reboot orchestration is disabled by default. With the default setting, an update that requires a reboot remains pending until the user restarts the device or Windows completes its normal restart handling.
When automatic reboot orchestration is enabled explicitly, the job can restart after Windows reports that a reboot is required, wait for the endpoint to reconnect, check Windows Update readiness, and optionally rerun the same approved identities until clean. Enable this only for scopes where job-initiated restarts are acceptable.
Delivery Optimization and peer sharing
Windows Delivery Optimization is configured as a normal configuration profile. It can apply when approved updates use the Windows Update source. Content installed from the Ordyn repository is delivered through the endpoint's assigned Cache Node.
To configure peer sharing:
- Open
Library>Configuration Profiles. - Create a profile with type
Windows Delivery Optimization. - Select a download mode:
HTTP only (no peer sharing)Local network peersPrivate peer group
- For a private peer group, enter the peer group ID used by endpoints that may share content.
- Configure optional cache age, cache size, minimum cached file size, and VPN peer-sharing settings.
- Assign the profile to the required Windows endpoint scopes and configure remediation behavior.
Delivery Optimization profiles can be assigned independently of rings. Use the same private peer group ID on endpoints that should share content across the selected group boundary.
If Delivery Optimization is already controlled by GPO, MDM, or another provider, remediation reports an error and makes no policy changes.
See Configuration Profiles for the complete profile behavior.
Permissions
Windows Updates uses separate permissions for:
- reading rings, assignments, endpoints, and decisions
- managing rings
- approving, rejecting, or clearing update decisions
- managing reusable automatic approval rules and settings
Windows Updates: Settings manages reusable rule definitions. Windows Updates: Manage configures ring delays and rule assignments.
Creating a job also requires the normal job-design permissions. Running or scheduling the job requires the corresponding job-operation permissions for the target scope.
Creating, editing, assigning, or deleting a ring requires Windows Updates: Manage.
In the fixed-role catalog, Platform Admin has all Windows Updates management and approval permissions. A super admin bypasses normal permission checks.
Troubleshooting
The ring has no eligible updates
Check that:
- the ring is enabled
- the ring has intended, non-conflicted endpoints
- those endpoints have reported update inventory
- at least one intended endpoint reports a Microsoft update of a collected type as missing
- or an enabled assigned automatic approval rule matches a discovered revision
- the decision filter includes
Eligible
For offline inventory, confirm that the update is included in Microsoft's offline scan catalog. Drivers, firmware, tools, and other content omitted from that catalog require online inventory and the Windows Update installation source.
An intended endpoint is missing from the Endpoints tab
The assignment may be overridden by a more specific assignment. Equal-precedence conflicts appear under every candidate ring rather than disappearing from the tab.
Review all matching tenant, endpoint-folder, group, and endpoint ring assignments.
The job task fails because no ring is effective
The endpoint must have one enabled effective ring at execution time. Check the ring's Assignments and Endpoints tabs for a missing assignment, a disabled ring, or equal-precedence assignments to different rings.
A repository installation reports missing catalog or update content
Run the infrastructure job that downloads the offline catalog, then collect offline Windows update inventory from the endpoint again. Approve the required revisions and run Download approved Windows updates.
Also confirm that the catalog and content files have completed malware verification and that the endpoint's assigned Cache Node is active.
An installed update still requires a restart
This is expected for updates that require reboot completion. Ordyn does not actively restart ring-managed endpoints.