Skip to content

Windows Updates

Windows update rings let operators approve specific Microsoft updates for defined groups of Windows endpoints.

Open Software > Windows Updates to manage the Ordyn repository, rings, and approvals.

An update ring combines three things:

  • one or more direct assignments that determine the ring's endpoint scope
  • an approval decision for each discovered Microsoft update revision

Approving an update does not install it immediately. Installation starts only when a job containing the Install approved Windows updates task runs against an endpoint.

Requirements and limitations

Windows update rings apply to Windows endpoints and approve exact Microsoft Update revisions. Inventory can be collected from Windows Update or Microsoft's offline scan catalog. The installation job can download approved revisions from Windows Update or use content prepared in the Ordyn repository.

The following limitations apply:

  • WSUS is not an installation source for approved-update tasks.
  • Offline catalog inventory supports the Security Updates, Service Packs, and Update Rollups classifications. Use an online source or WSUS to inventory definition updates, drivers, firmware, feature packs, tools, general updates, and upgrades.
  • The offline scan catalog does not contain the complete Microsoft Update catalog. Content that Microsoft omits from the offline catalog cannot use the Ordyn repository path.
  • Vendor tools and other update channels are outside the ring workflow.
  • The endpoint must report update inventory before its missing updates can appear in a ring.
  • A ring must be enabled and effective before an installation task can apply.
  • The Ordyn repository path requires a Runner pool, a current offline catalog, imported update content, and an active Cache Node for the endpoint.
  • Offline catalogs older than 45 days are rejected. A weekly catalog download schedule is recommended when the repository path is used.

Use Update Inventory when you need a fleet-wide view that is not scoped to one ring.

Review the Ordyn repository

Select Ordyn repository above the update-ring tree to review Windows update files prepared for endpoint installation.

The Updates tab lists exact Microsoft Update revisions discovered through offline inventory. It shows each update's import state, required and verified file counts, stored size, associated offline catalog, and import time. Ready updates are shown by default. Use the status filter to include missing files, files awaiting malware verification, detected malware, or failed scans.

Open an update to inspect its Microsoft metadata and required content files. A content file can be downloaded after malware verification marks it as clean.

The Offline catalogs tab lists downloaded wsusscn2.cab files. It shows whether each catalog is current or older than 45 days, its verification state, size, checksum, and import time. A catalog can be downloaded after malware verification marks it as clean. Links from endpoint inventory history filter this table to the exact referenced catalog.

Users with Windows Update management access can select updates or offline catalogs, right-click the selection, and delete the imported repository content.

Deleting an update keeps its endpoint inventory, approval decisions, and history. Deleting an offline catalog moves affected updates to their newest remaining imported catalog when one is available. Inventory history retains the deleted catalog's name, checksum, size, and import time and marks it as no longer available. Files shared by other updates or catalogs are retained. Content referenced by an active job cannot be deleted until that job finishes or is aborted.

Infrastructure jobs can import deleted catalogs and approved update content again.

Organize rings

The tree on the left side of the Windows Updates page contains update-ring folders and rings.

Use the Actions menu to:

  • add a folder
  • create an update ring
  • create nested folders inside an existing ring folder
  • rename or delete a ring folder

Ring folders only organize the Windows Updates tree. They do not assign the contained rings to endpoints.

An Endpoint folder assignment refers to a folder from the Endpoints area and includes endpoints in that folder and its descendant folders.

Create a ring

To create a ring:

  1. Open Software > Windows Updates.
  2. Select Actions > New update ring.
  3. Enter a name and optional description.
  4. Select the ring folder or leave the ring at the root.
  5. Enter the default automatic approval delay in whole days. The default is 0 days. Rules use this value unless they define an override.
  6. Keep Ring enabled selected when the ring should be eligible to control endpoints and install approved updates.
  7. Save the ring.

A disabled ring remains available for review, but it does not install approved updates on endpoints.

Ring detail tabs

Each ring has four tabs.

Overview

The Overview tab contains the update approval table.

It shows Microsoft updates reported as missing in the ring, revisions scheduled for automatic approval, and recorded decision history. The table includes:

  • update title and KB article IDs
  • classification
  • update type (Software, Driver, or Firmware)
  • automatic or optional driver offer type
  • Microsoft revision number
  • number of effective endpoints reporting the update as missing
  • availability (Current, Installed, or Expired)
  • decision state
  • last-seen time

Use the table controls to search, sort, and filter by decision state, availability, update type, and driver offer type. Current and installed revisions are shown by default. Select Expired in the availability filter to include decision history for revisions that no effective endpoint currently reports as missing or installed.

Assignments

The Assignments tab lists the tenant, endpoint-folder, endpoint-group, and endpoint scopes assigned directly to the ring. Each target links to its corresponding page.

Select Actions > Assign from the ring header to add an assignment. Select assignments with their row checkboxes, then right-click the selection to open targets or remove one or more assignments.

Rules

The Rules tab lists the reusable automatic approval rules assigned to the ring. The Approval delay column shows whether each rule inherits the ring default, approves immediately, or uses a custom number of days.

Select Assign on the right side of the tab row to assign rules. To unassign rules, select them with the table checkboxes, then right-click the selection and select Unassign rule or Unassign selected. Ctrl and Shift selection are supported. Assigning a rule evaluates updates that Ordyn has already discovered as well as future update revisions.

Endpoints

The Endpoints tab lists the endpoints for which the ring is effective.

The table shows:

  • endpoint and hostname
  • tenant
  • operating system
  • ring membership status and ring assignment conflicts
  • the assignment that selected the ring
  • last reconciliation time

Open an endpoint row to inspect that endpoint in the Endpoints area.

Endpoints with an equal-precedence ring conflict appear under every candidate ring with a Conflict status, but they are excluded from the ring's update catalog and cannot run the approved-update installation task.

Set up an update ring workflow

The complete setup uses a Windows Update Policy profile, direct ring assignments, update inventory collection, and an installation job:

  1. Open Library > Configuration Profiles and create a Windows Update Policy profile.
  2. Set Automatic updates mode to Disabled.
  3. Set Update source to Microsoft Update / Windows Update.
  4. Set Windows Update user access to Blocked when users must not manually scan for, download, or install updates. This also blocks interactive access for administrators.
  5. Configure any optional schedule or restart settings required by your organization. Ring installation itself does not restart endpoints.
  6. Assign the policy to the required tenant, endpoint folder, endpoint group, or endpoint scope.
  7. Use Remediate behavior when Ordyn should apply the policy. Use Audit only when GPO or MDM applies the settings and Ordyn should check them.
  8. Run or automate the Windows Update Policy as required for your environment.
  9. Create or edit an endpoint job with Collect Windows update inventory. Select Microsoft Update for the full online catalog or Offline catalog for disconnected inventory. Offline inventory supports Security Updates, Service Packs, and Update Rollups.
  10. When using offline inventory, create an infrastructure job with Download offline Windows update catalog, select a Runner pool, run it once, and schedule it about once every seven days.
  11. Run or schedule update inventory collection for the intended endpoint scope.
  12. Open Software > Windows Updates, create the ring, and configure its default automatic approval delay and rules.
  13. Open the ring's Actions menu, select Assign, and choose the required tenant, endpoint folder, endpoint group, or endpoint.
  14. Review the ring's Assignments and Endpoints tabs and approve the required revisions.
  15. Create a job containing Install approved Windows updates.
  16. Select Windows Update to download approved revisions directly from Microsoft, or select Ordyn repository to deploy imported content through the endpoint's Cache Node.
  17. When using Ordyn repository, create an infrastructure job with Download approved Windows updates. Add a Windows update approved automation, run it manually after approvals change, or use a recurring schedule.
  18. Run or schedule the installation job for the intended endpoint scope.

The Windows Update Policy and ring assignment scopes can differ. Ring membership does not inspect or enforce the Windows Update Policy.

Assign a ring

To assign a ring:

  1. Open Software > Windows Updates and select the ring.
  2. Select Actions > Assign.
  3. Select Tenant, Folder, Group, or Endpoint as the destination type.
  4. Search for and select the destination.
  5. Select Assign.

Ring assignments are declarative. They change ring membership and do not change Windows Update settings on an endpoint.

An endpoint can match several ring assignments. Ordyn selects the highest-precedence assignment using this order:

  1. endpoint
  2. endpoint group
  3. deepest matching endpoint folder
  4. tenant

An assignment at a more specific level overrides matching assignments below it. Multiple assignments at the same highest precedence can select the same ring without creating a conflict.

If assignments for different rings match at the same highest precedence, no ring becomes effective and a ring installation job fails until the conflict is resolved. A common example is an endpoint that belongs to two groups assigned to different rings.

Each tenant, folder, group, or endpoint can be assigned directly to only one ring. Assigning the same target to another ring reports a conflict; remove its existing direct assignment first.

Deleting an assigned tenant, endpoint folder, endpoint group, or endpoint also removes its direct ring assignment. Removing an assignment or deleting its target does not change Windows Update settings.

Configure Windows Update policy

Ordyn recommends an effective, compliant Windows Update Policy that:

  • sets automatic updates to Disabled
  • sets Update source to Microsoft Update / Windows Update

The policy can use Remediate behavior so Ordyn applies the settings, or Audit only behavior when GPO or MDM supplies the effective values.

Ordyn's ring installation job never changes Windows Update policy. Automatic reboot orchestration is disabled by default and can be enabled explicitly in the job step.

The ring workflow installs approved updates only when its job task runs. Set Windows Update user access to Blocked in the effective Windows Update Policy when interactive users must not start Windows Update outside Ordyn. The setting applies to administrators as well as standard users.

Use Windows Update notifications in the same policy to keep the default Windows notifications, show restart warnings only, or turn off all Windows Update notifications. This setting controls notification visibility and does not change installation or restart timing.

Use Quality update deferral to delay quality updates for up to 30 days after release. Set it to 0 to disable the delay, or leave it Not managed when Group Policy, MDM, or another management system controls the value. Online inventory and ordinary Windows Update scans respect the effective deferral.

Removing a ring assignment changes ring membership only. Manage the Windows Update Policy assignment separately when its endpoint configuration should also change.

Update grouping

Ordyn groups discoveries from different endpoints by the Microsoft Update ID and revision number. The update type remains part of each exact installation request.

This means:

  • the same revision discovered on many endpoints appears once in the ring table
  • the missing count shows how many non-conflicted intended endpoints currently report that revision as missing
  • one approval applies that exact revision to all eligible endpoints in the ring
  • a newly discovered revision requires its own decision

This prevents endpoint-specific inventory records from creating duplicate approval rows while keeping Microsoft revisions distinct.

Approve or reject updates

Each update has one of these ring-specific decision states:

  • Eligible: no decision has been recorded
  • Approved: the ring installation job may install this exact revision
  • Rejected: the ring installation job excludes this revision

Use the decision filter in the table header to include approved or rejected updates. Eligible updates include revisions currently missing from ring endpoints and revisions scheduled by an assigned automatic approval rule. An approved or rejected revision is marked Expired when no effective endpoint currently reports it as missing or installed. Expired decisions are hidden by default and remain available through the availability filter.

To update decisions:

  1. Select one or more rows with the checkboxes.
  2. Right-click the selection.
  3. Select Approve, Reject, or Clear decision from the context menu.

You can also use the row context menu. Standard table selection is supported:

  • Ctrl or Command adds or removes individual rows from the selection.
  • Shift selects a range from the selection anchor.
  • The header checkbox selects or clears the loaded rows.

Clearing a decision returns the update to Eligible.

If an active automatic approval rule still matches the update, clearing its decision schedules it again. An overdue update can be approved again during the next automatic approval evaluation. Reject the update to suppress automatic approval for that ring and revision.

Decisions belong to one ring. Approving an update in one ring does not approve it in another ring.

Configure automatic approval rules

Select Automatic approvals above the update-ring tree to manage reusable matching rules.

To create a rule:

  1. Select Actions > New automatic approval rule.
  2. Enter a name and optional description.
  3. Set Approval delay to Use ring default, Approve immediately, or Custom delay. A custom delay can be from 1 through 3650 whole days.
  4. Select at least one classification. Select Drivers for Windows Update driver and firmware offers.
  5. Optionally select products or enter an Update name contains value.
  6. For driver rules, optionally select providers, manufacturers, driver classes, device models, or hardware IDs.
  7. Keep the rule enabled and save it.
  8. Open a ring's Rules tab and assign the rule.

To preview a saved rule, right-click that rule and select Preview. The preview opens separately and lists the most recently discovered Microsoft update revisions that currently match the rule.

Classification is required. Product, classification, and driver values are selected from metadata already reported by endpoints. Matching is case-insensitive:

  • an update may match any selected product
  • an update may match any selected classification
  • every populated matcher group must match
  • values within one matcher group use OR matching
  • Update name contains performs simple substring matching and does not support regular expressions
  • driver provider, manufacturer, class, model, and hardware ID values use exact matching

Driver applicability can differ between endpoints even when Microsoft gives the update the same ID and revision. Driver and firmware updates discovered through online inventory can use the Windows Update installation source. Microsoft does not include their content in the offline scan catalog, so they cannot use the Ordyn repository source.

The approval date is calculated from the time Ordyn first discovered the Microsoft Update ID and revision. A rule's custom delay takes precedence over the ring default:

First discovered + effective rule delay = automatic approval date

A rule set to Use ring default uses the delay configured on each assigned ring. For example, the same inherited rule assigned to rings with defaults of 0, 3, and 5 days schedules the exact revision immediately for the first ring, after three days for the second ring, and after five days for the third ring. A rule set to Approve immediately is eligible during the next automatic approval evaluation in every assigned ring. A custom delay uses the same number of days in every assigned ring.

Discovery on any endpoint starts the shared delay calculation. A rule is scheduled for a ring only while at least one effective endpoint in that ring reports the update as missing and satisfies its applicability matchers. When several assigned rules match the same update, the matching rule with the earliest effective approval date is used. Equal dates are resolved consistently.

The update table shows scheduled automatic approvals with the rule name and approval date. Disabled rings show their schedules as paused. When a ring is enabled, an overdue update becomes approved during the next evaluation.

Before approval, a scheduled entry is removed when no effective endpoint in the ring reports the revision as missing or when the assigned rules do not match it. An Approved decision remains recorded until an operator changes or clears it.

Manual decisions take precedence. A manual rejection prevents a matching rule from approving that ring and revision. Editing, disabling, unassigning, or deleting a rule does not revoke approvals already created by the rule.

Automatic approval changes the ring decision. It does not start an endpoint installation job or reboot an endpoint. A Windows update approved infrastructure automation can react to the decision separately.

Prepare approved update content

Run Download approved Windows updates in an infrastructure job after approving updates that will use the Ordyn repository source. The task:

  • resolves the content referenced by current offline inventory from eligible ring endpoints
  • downloads missing files on a Runner from Microsoft
  • imports the files into Ordyn
  • submits the files to for malware-verification

The task skips files that Ordyn has already imported. A repository installation remains blocked until every required file for the exact approved update revision is available and verified as clean.

Content resolution uses each eligible endpoint's newest offline-catalog snapshot. A later online Microsoft Update or WSUS scan can become the endpoint's current inventory view without discarding the catalog and content evidence needed by the repository workflow.

Run this job whenever approvals change. You can add a Windows update approved event automation to the infrastructure job so manual and automatic approvals from enabled rings start it automatically. Configure a debounce to combine a burst of approvals into one run. Existing approvals in a disabled ring trigger when the ring is enabled.

A recurring schedule remains useful as a periodic safety net.

Install approved updates with a job

Use the dedicated job task for ring installations:

  1. Open Operations > Endpoint Jobs.
  2. Create or edit a job.
  3. Add the Install approved Windows updates task.
  4. Select the update source:
    • Windows Update downloads the exact approved revisions directly from Microsoft. This is the default.
    • Ordyn repository uses update content imported into Ordyn and delivered through the endpoint's Cache Node.
  5. Optionally select classifications or products to limit this job to a subset of the ring's approved updates. Ordyn repository supports Security Updates, Service Packs, and Update Rollups; the editor disables other classifications. Leave classifications empty to include all three.
  6. Save the job.
  7. Run the job manually or configure a time automation.

When an endpoint reaches the task, Ordyn checks that:

  • the endpoint has an effective ring
  • the effective ring is enabled
  • the endpoint has no equal-precedence ring conflict
  • the endpoint reports the approved revisions as missing

With Windows Update, the endpoint contacts Microsoft Update and requests the exact approved IDs and revisions. This source does not use WSUS or the update source configured by endpoint policy.

With Ordyn repository, Ordyn also checks the endpoint's newest offline-catalog snapshot and requires its catalog to be no more than 45 days old. Every required file must be imported and verified, and the endpoint must have an assigned Cache Node. Ordyn synchronizes the required files to that Cache Node and the agent verifies every staged download.

Repository installation uses the endpoint system variable windows.update.ordyn_repository_install_strategy:

  • unset or automatic installs an approved revision with Windows servicing when its imported content contains one MSU package that unambiguously matches the update's KB number; additional MSU prerequisite packages are staged with it
  • automatic uses the offline catalog and Windows Update cache for revisions that do not have that unambiguous MSU shape
  • copy_to_cache requires the offline-catalog and Windows Update cache method for every approved revision

One task can install direct MSU revisions and Windows Update cache revisions together. A failed direct MSU installation is reported as a failure and is not retried through the cache method.

Both sources request the exact Microsoft Update IDs and revisions approved for the endpoint's effective ring and matching the job filters. Rejected, eligible, and nonmatching approved updates are not included. Windows performs its normal applicability checks before installing the content. Ordyn does not switch sources automatically when the selected source is unavailable.

Filters are inclusive. Multiple selected classifications match any selected classification, and multiple selected products match any selected product. When both filters contain values, an update must match both groups. With Windows Update, an empty classification filter includes all approved classifications. With Ordyn repository, it includes all supported offline-catalog classifications. To run a frequent Defender-only job through Windows Update, select Microsoft Defender Antivirus under products and leave classifications empty to include all Defender update classifications.

While the task is running, its details list the approved updates sent to the endpoint. After Windows finishes, the details separate successfully installed updates from updates that failed to download or install. Failed entries include the Windows error code when one is available.

A successful task can report that no approved updates were applicable. This means Windows did not offer any of the requested revisions to that endpoint at execution time; it is not an installation failure. The task details show the requested, discovered, and matched update counts to make that outcome explicit.

One job can target endpoints from multiple rings. Ordyn resolves every endpoint independently, so each endpoint receives only the approvals from its own effective ring. An endpoint without an effective ring, with a disabled effective ring, or with an equal-precedence conflict fails safely without installing updates.

An approval changes what a later endpoint job execution can install; it does not modify an already delivered endpoint task. A configured Windows update approved automation can start an infrastructure job, but it never starts the endpoint installation job.

See Available Tasks for the job task reference.

Reboot behavior

Automatic reboot orchestration is disabled by default. With the default setting, an update that requires a reboot remains pending until the user restarts the device or Windows completes its normal restart handling.

When automatic reboot orchestration is enabled explicitly, the job can restart after Windows reports that a reboot is required, wait for the endpoint to reconnect, check Windows Update readiness, and optionally rerun the same approved identities until clean. Enable this only for scopes where job-initiated restarts are acceptable.

Delivery Optimization and peer sharing

Windows Delivery Optimization is configured as a normal configuration profile. It can apply when approved updates use the Windows Update source. Content installed from the Ordyn repository is delivered through the endpoint's assigned Cache Node.

To configure peer sharing:

  1. Open Library > Configuration Profiles.
  2. Create a profile with type Windows Delivery Optimization.
  3. Select a download mode:
    • HTTP only (no peer sharing)
    • Local network peers
    • Private peer group
  4. For a private peer group, enter the peer group ID used by endpoints that may share content.
  5. Configure optional cache age, cache size, minimum cached file size, and VPN peer-sharing settings.
  6. Assign the profile to the required Windows endpoint scopes and configure remediation behavior.

Delivery Optimization profiles can be assigned independently of rings. Use the same private peer group ID on endpoints that should share content across the selected group boundary.

If Delivery Optimization is already controlled by GPO, MDM, or another provider, remediation reports an error and makes no policy changes.

See Configuration Profiles for the complete profile behavior.

Permissions

Windows Updates uses separate permissions for:

  • reading rings, assignments, endpoints, and decisions
  • managing rings
  • approving, rejecting, or clearing update decisions
  • managing reusable automatic approval rules and settings

Windows Updates: Settings manages reusable rule definitions. Windows Updates: Manage configures ring delays and rule assignments.

Creating a job also requires the normal job-design permissions. Running or scheduling the job requires the corresponding job-operation permissions for the target scope.

Creating, editing, assigning, or deleting a ring requires Windows Updates: Manage.

In the fixed-role catalog, Platform Admin has all Windows Updates management and approval permissions. A super admin bypasses normal permission checks.

Troubleshooting

The ring has no eligible updates

Check that:

  • the ring is enabled
  • the ring has intended, non-conflicted endpoints
  • those endpoints have reported update inventory
  • at least one intended endpoint reports a Microsoft update of a collected type as missing
  • or an enabled assigned automatic approval rule matches a discovered revision
  • the decision filter includes Eligible

For offline inventory, confirm that the update is included in Microsoft's offline scan catalog. Drivers, firmware, tools, and other content omitted from that catalog require online inventory and the Windows Update installation source.

An intended endpoint is missing from the Endpoints tab

The assignment may be overridden by a more specific assignment. Equal-precedence conflicts appear under every candidate ring rather than disappearing from the tab.

Review all matching tenant, endpoint-folder, group, and endpoint ring assignments.

The job task fails because no ring is effective

The endpoint must have one enabled effective ring at execution time. Check the ring's Assignments and Endpoints tabs for a missing assignment, a disabled ring, or equal-precedence assignments to different rings.

A repository installation reports missing catalog or update content

Run the infrastructure job that downloads the offline catalog, then collect offline Windows update inventory from the endpoint again. Approve the required revisions and run Download approved Windows updates.

Also confirm that the catalog and content files have completed malware verification and that the endpoint's assigned Cache Node is active.

An installed update still requires a restart

This is expected for updates that require reboot completion. Ordyn does not actively restart ring-managed endpoints.