I’m trying to figure out which products I need to select in WSUS to get updates for our Server 2022 Standard machines. I’ve looked at some guide and seen different answers. Does anyone know for certain which products to select? We don’t have anything in Azure, all standard on prem VM’s.

10 Spice ups

Overdrive has a complete multistep guide for this. Check it out.

@overdrive

1 Spice up

You’ll want

Microsoft Server operating system-21H2
Microsoft Server Operating System-22H2

Selected for Server 2022

2 Spice ups

Oh dang :rofl: I misread his post. I thought he was asking what to select when installing WSUS.

1 Spice up

21H2 has the bulk of the updates, 22H2 only has 7 updates that I can see in mine… I’m not 100% sure 22H2 needs to be checked… I think that’s for the container-based server operating system path… memory fart right now so I can’t think of the path.

1 Spice up

Thanks! I had those selected in addition to “server 2022 hotpatch category” because I saw a guide that said to enable it and one that said not to, I unchecked that one now.

I have a fresh 2022 server, well an in place upgrade from 2012 R2 (I know, I know), that’s saying it’s up to date. I’d think a fresh install would need updates? WSUS isn’t showing any are needed for that machine. I wonder if the in place upgrade downloaded all of the latest updates from MSFT when it was installing? I used the latest 2022 ISO in the VLSC. I haven’t checked for updates from MSFT yet, only the WSUS server, should I check from MSFT or wait a while and see if anything shows up on the WSUS server? I did synchronize now and it found 72 updates or something like that.

1 Spice up

I believe there are Products:

Windows Server, version 1903 and later
Microsoft Server operating system-21H2
Microsoft Server Operating System-22H2

1 Spice up

I let the 2022 VM and WSUS server sit over the weekend with just 21H2 and 22H2 selected (didn’t see your message), the VM didn’t pick up any updates from the WSUS server. I checked online for updates from MSFT today and it found a few.

I just added the version 1903 and later product and the WSUS server is downloading ~35GBs of updates now. Hopefully these are what it needs… though I can’t test now since it’s fully up to date.

Does anyone know if there’s an easy way to figure out which product classification an update would be under? Ex. how would I figure out which product update KB5022842 (one that downloaded from MSFT rather than the WSUS server) would fall under? From what I found it doesn’t look like there’s an easy way?

https://support.microsoft.com/en-us/topic/february-14-2023-kb5022842-os-build-20348-1547-be155955-29f7-47c4-855c-34bd43895940

Bottom of the document under the heading: Install this update

Release Channel

Available

Next Step

Windows Update and Microsoft Update

Yes

None. This update will be downloaded and installed automatically from Windows Update.

Windows Update for Business

Yes

None. This update will be downloaded and installed automatically from Windows Update in accordance with configured policies.

Microsoft Update Catalog

Yes

To get the standalone package for this update, go to the Microsoft Update Catalog website.

Windows Server Update Services (WSUS)

Yes

This update will automatically sync with WSUS if you configure Products and Classifications as follows:

Product: Microsoft Server operating system-21H2

Classification: Security Updates

If only I had scrolled down a bit more lol… thanks!

I wonder why the VM wouldn’t have pulled that update from the WSUS server after a couple days? I do have 21H2 and security updates selected.

1 Spice up

I know this is from 2023 but I’m experiencing something similar. @overdrive , if I may ask, what if a product is displayed in the KB article (in this case, for 5058500) but it’s not specifically in the list in WSUS? For example…

Does “Server 2022 Hotpatch Category” apply without specifically stating “Azure Edition Hotpatch”?

I really appreciate your help!

EDIT to add: Our vulnerability scanner flags this 2022 Datacenter server in Azure as needing 5058500, but WSUS shows its “Needed Count” as 0, even though the server is showing in WSUS.

1 Spice up

Depends on how recently you picked up the ISO you built the server with, but walk through your WSUS options list. They usually stand out once you really read what each one is.

Pingged my contacts in Microsoft. I’m guessing this was a mistake with their webpage naming.

1 Spice up

I didn’t catch this until I got a reply from my Microsoft contacts - Hotpatches are not published to WSUS or the Windows Update Catalog. This should be stating that it’s not available through WSUS. I’ve asked them to update their page.

1 Spice up

But this is from WSUS itself. It just shows as not being needed by any servers. Is that what you mean?

image

Hotpatch patches are ‘not supposed’ to be on WSUS at all. WSUS does not have the capabilities required for Hotpatching.

Thank you very much for your help. :slightly_smiling_face: