-
Notifications
You must be signed in to change notification settings - Fork 0
Windows Update
Windows Update inspection and control: pending/installed updates, history, hide/install/uninstall/download actions, cache cleanup, and component reset.
10 function(s) in Public/windowsupdate/.
-
Clear-WindowsUpdateCache— Clears the Windows Update download cache to free disk space -
Get-WindowsUpdate— Lists available Windows Updates on local or remote computers -
Get-WindowsUpdateConfiguration— Retrieves Windows Update configuration from local or remote computers -
Get-WindowsUpdateHistory— Retrieves Windows Update installation history from local or remote computers -
Hide-WindowsUpdate— Hides one or more Windows Updates to prevent them from being installed -
Install-WindowsUpdate— Installs available Windows Updates on local or remote computers -
Reset-WindowsUpdateComponent— Resets the Windows Update service stack to a clean state -
Save-WindowsUpdate— Downloads available Windows Updates without installing them -
Show-WindowsUpdate— Unhides previously hidden Windows Updates to allow installation -
Uninstall-WindowsUpdate— Uninstalls previously installed Windows Updates by KB article ID
Clears the Windows Update download cache to free disk space.
Stops the Windows Update (wuaserv) and BITS services, removes all files from the SoftwareDistribution\Download folder, then restarts both services. Reports the amount of disk space freed. This is useful when the cache becomes corrupted, takes up excessive space, or when troubleshooting Windows Update failures. The cache is automatically rebuilt on the next update scan.
Syntax
Clear-WindowsUpdateCache [-ComputerName <string[]>] [-IncludeDataStore]Examples
Clear-WindowsUpdateCacheClears the download cache on the local computer.
Clear-WindowsUpdateCache -ComputerName 'SRV01' -IncludeDataStoreClears both the download cache and the DataStore on SRV01.
'SRV01', 'SRV02' | Clear-WindowsUpdateCacheClears the download cache on SRV01 and SRV02 via pipeline.
Output: PSWinOps.WindowsUpdateCacheResult
Returns objects with ComputerName, CachePath, FileCount, SizeFreedMB, DataStoreCleared, Result, and Timestamp properties.
Lists available Windows Updates on local or remote computers.
Scans for available (not yet installed) Windows Updates using the COM API (Microsoft.Update.Session). Returns each pending update with its classification, product categories, download status, size, reboot requirement, MSRC severity, CVE identifiers, EULA status, and more. By default all classifications and products are returned. Use the Classification, Product, and KBArticleID parameters to filter results. Hidden updates are excluded unless the IncludeHidden switch is specified. By default, the machine's configured update source is used (WSUS, WUFB, or Windows Update). Use the MicrosoftUpdate switch to query the full Microsoft Update catalog instead.
Syntax
Get-WindowsUpdate [-ComputerName <string[]>] [-MicrosoftUpdate] [-KBArticleID <string[]>] [-Classification <string[]>] [-Product <string[]>] [-IncludeHidden]Examples
Get-WindowsUpdateLists all available updates on the local computer using the configured source.
Get-WindowsUpdate -ComputerName 'SRV01' -KBArticleID 'KB5034441'Checks if a specific KB is available on SRV01.
'SRV01', 'SRV02' | Get-WindowsUpdate -MicrosoftUpdate -Classification 'Security Updates'Lists security updates from the full Microsoft Update catalog on SRV01 and SRV02.
Output: PSWinOps.WindowsUpdate
Returns objects with ComputerName, Title, KBArticle, Classification, Products, IsDownloaded, IsHidden, IsInstalled, IsMandatory, IsUninstallable, RebootRequired, MsrcSeverity, Description, ReleaseNotes, CveIDs, EulaAccepted, Deadline, SizeMB, UpdateId, RevisionNumber, and Timestamp properties.
Retrieves Windows Update configuration from local or remote computers.
Reads Windows Update configuration from the registry on local or remote computers. The function queries two registry paths under HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate to retrieve WSUS, Windows Update for Business (WUFB), and Auto Update GPO settings. When the WindowsUpdate policy key exists, the computer is considered GPO-configured. The UpdateSource property is determined by analyzing UseWUServer, WUServer, and deferral settings to classify the source as WSUS, WUFB, WindowsUpdate, or Unknown.
Syntax
Get-WindowsUpdateConfiguration [-ComputerName <string[]>]Examples
Get-WindowsUpdateConfigurationRetrieves Windows Update configuration from the local computer.
Get-WindowsUpdateConfiguration -ComputerName 'SRV01' -Credential (Get-Credential)Retrieves Windows Update configuration from SRV01 using explicit credentials.
'SRV01', 'SRV02' | Get-WindowsUpdateConfiguration | Where-Object -Property UpdateSource -NE -Value 'WSUS'Queries multiple servers via pipeline and filters for those not using WSUS.
Output: PSWinOps.WindowsUpdateConfiguration
Returns an object per computer with UpdateSource, WSUS URLs, auto-update settings, deferral policies, branch readiness level, target group, and GPO configuration status.
Retrieves Windows Update installation history from local or remote computers.
Queries the Windows Update Agent COM API (Microsoft.Update.Session) to retrieve the installation history of Windows Updates. Results include update title, KB article, operation type, result status, classification, products, client application, HResult error code, update source, date, description, and support URL. Output is sorted by date descending (most recent first) and limited by MaxResults.
Syntax
Get-WindowsUpdateHistory [-ComputerName <string[]>] [-MaxResults <int>]Examples
Get-WindowsUpdateHistoryRetrieves the 50 most recent Windows Update history entries from the local computer.
Get-WindowsUpdateHistory -ComputerName 'SRV01' -Credential (Get-Credential) -MaxResults 100Retrieves the 100 most recent update history entries from SRV01 using alternate credentials.
'SRV01', 'SRV02' | Get-WindowsUpdateHistory -MaxResults 10Retrieves the 10 most recent update history entries from SRV01 and SRV02 via pipeline.
Output: PSWinOps.WindowsUpdateHistory
Returns objects with ComputerName, Title, KBArticle, Operation, Result, HResult, Classification, Products, ClientApplicationID, ServerSelection, ServiceID, Date, Description, SupportUrl, UpdateId, RevisionNumber, and Timestamp properties.
Hides one or more Windows Updates to prevent them from being installed.
Hides (declines) specified Windows Updates by setting the IsHidden property to true on matching IUpdate COM objects. Hidden updates are excluded from automatic installation and from Get-WindowsUpdate results unless -IncludeHidden is specified. Use Show-WindowsUpdate to unhide them later. Searches both visible and already-hidden updates to accurately report AlreadyHidden status.
Syntax
Hide-WindowsUpdate [-ComputerName <string[]>] -KBArticleID <string[]> [-MicrosoftUpdate]Examples
Hide-WindowsUpdate -KBArticleID 'KB5034441'Hides KB5034441 on the local computer.
Hide-WindowsUpdate -ComputerName 'SRV01' -KBArticleID 'KB5034441', 'KB5035432'Hides two updates on SRV01.
'SRV01', 'SRV02' | Hide-WindowsUpdate -KBArticleID 'KB5034441'Hides KB5034441 on SRV01 and SRV02 via pipeline.
Output: PSWinOps.WindowsUpdateHideResult
Returns objects with ComputerName, Title, KBArticle, Result, and Timestamp. Result is one of: Hidden, AlreadyHidden, NotFound.
Installs available Windows Updates on local or remote computers.
Scans for available Windows Updates, downloads them if not already cached, then installs them using the COM API (Microsoft.Update.Session). Internally calls Get-WindowsUpdate to discover available updates, downloads any that are not yet cached, then installs each one using IUpdateInstaller. A progress bar displays installation status with estimated time remaining. Returns detailed results for each update including success/failure status and whether a reboot is required.
Syntax
Install-WindowsUpdate [-ComputerName <string[]>] [-MicrosoftUpdate] [-KBArticleID <string[]>] [-Classification <string[]>] [-Product <string[]>] [-IncludeHidden] [-AcceptEula] [-AutoReboot]Examples
Install-WindowsUpdate -AcceptEulaInstalls all available updates on the local computer, accepting EULAs.
Install-WindowsUpdate -ComputerName 'SRV01' -KBArticleID 'KB5034441' -AcceptEulaInstalls a specific update on SRV01, accepting the EULA automatically.
'SRV01', 'SRV02' | Install-WindowsUpdate -Classification 'Security Updates' -AcceptEula -AutoRebootInstalls security updates on SRV01 and SRV02 with automatic reboot if required.
Output: PSWinOps.WindowsUpdateInstallResult
Returns objects with ComputerName, Title, KBArticle, SizeMB, Result, HResult, RebootRequired, and Timestamp properties.
Resets the Windows Update service stack to a clean state.
Stops the Windows Update related services, deletes the BITS queue, backs up the SoftwareDistribution and Catroot2 folders, resets the BITS and wuauserv service security descriptors, and reregisters the Windows Update DLLs before restarting the services and triggering a fresh detection. Optionally resets the Winsock and WinHTTP proxy network stack. This is the PSWinOps equivalent of PSWindowsUpdate's Reset-WUComponents and is used to recover a corrupted Windows Update client.
Syntax
Reset-WindowsUpdateComponent [-ComputerName <string[]>] [-IncludeNetworkReset]Examples
Reset-WindowsUpdateComponentResets the Windows Update component stack on the local computer.
Reset-WindowsUpdateComponent -ComputerName 'SRV01'Resets the Windows Update component stack on the remote server SRV01.
Reset-WindowsUpdateComponent -ComputerName 'SRV01' -IncludeNetworkResetResets the Windows Update stack on SRV01 and additionally resets the Winsock catalog and WinHTTP proxy. A reboot will be required on SRV01 after this runs.
'SRV01', 'SRV02' | Reset-WindowsUpdateComponentResets the Windows Update component stack on SRV01 and SRV02 via pipeline.
Output: PSWinOps.WindowsUpdateResetResult
Returns one object per machine with ComputerName, Status, ServicesStopped, ServicesStarted, backup paths, DLL counts, network reset flags, Failures, Notes, and Timestamp.
Downloads available Windows Updates without installing them.
Scans for available Windows Updates and downloads them to the local cache without installing. Uses the COM API (Microsoft.Update.Session) to find and download updates. Internally calls Get-WindowsUpdate to discover available updates, then downloads each one using IUpdateDownloader. A progress bar displays download status with speed, percentage based on total size, and estimated time remaining. Updates are downloaded one at a time for granular progress tracking. Use this function to pre-stage updates before a maintenance window, then install them later with Install-WindowsUpdate.
Syntax
Save-WindowsUpdate [-ComputerName <string[]>] [-MicrosoftUpdate] [-KBArticleID <string[]>] [-Classification <string[]>] [-Product <string[]>] [-IncludeHidden] [-AcceptEula]Examples
Save-WindowsUpdateDownloads all available updates on the local computer.
Save-WindowsUpdate -ComputerName 'SRV01' -KBArticleID 'KB5034441' -AcceptEulaDownloads a specific update on SRV01, accepting the EULA automatically.
'SRV01', 'SRV02' | Save-WindowsUpdate -MicrosoftUpdate -Classification 'Security Updates'Downloads security updates from Microsoft Update on SRV01 and SRV02.
Output: PSWinOps.WindowsUpdateDownloadResult
Returns objects with ComputerName, Title, KBArticle, SizeMB, Result, HResult, and Timestamp properties.
Unhides previously hidden Windows Updates to allow installation.
Reverses the hiding of Windows Updates by setting the IsHidden property to false on matching IUpdate COM objects. This function searches only hidden, non-installed updates and restores visibility for those matching the specified KB article IDs. Use this after Hide-WindowsUpdate to re-enable updates for installation.
Syntax
Show-WindowsUpdate [-ComputerName <string[]>] -KBArticleID <string[]> [-MicrosoftUpdate]Examples
Show-WindowsUpdate -KBArticleID 'KB5034441'Unhides KB5034441 on the local computer.
Show-WindowsUpdate -ComputerName 'SRV01' -KBArticleID 'KB5034441', 'KB5035432'Unhides two updates on SRV01.
'SRV01', 'SRV02' | Show-WindowsUpdate -KBArticleID 'KB5034441'Unhides KB5034441 on SRV01 and SRV02 via pipeline.
Output: PSWinOps.WindowsUpdateShowResult
Returns objects with ComputerName, Title, KBArticle, Result, and Timestamp. Result is one of: Shown, NotFound.
Uninstalls previously installed Windows Updates by KB article ID.
Removes one or more Windows Updates from local or remote computers using wusa.exe in quiet mode. Each KB is validated as installed via Get-HotFix before attempting uninstallation. Provides detailed exit code mapping for troubleshooting. Use this function to rollback problematic updates that cause issues in your environment.
Syntax
Uninstall-WindowsUpdate [-ComputerName <string[]>] -KBArticleID <string[]> [-AutoReboot]Examples
Uninstall-WindowsUpdate -KBArticleID 'KB5034441'Uninstalls KB5034441 from the local computer without automatic reboot.
Uninstall-WindowsUpdate -ComputerName 'SRV01' -KBArticleID 'KB5034441' -AutoRebootUninstalls KB5034441 from SRV01 with automatic reboot.
'SRV01', 'SRV02' | Uninstall-WindowsUpdate -KBArticleID 'KB5034441', 'KB5035432'Uninstalls two KBs from two servers via pipeline.
Output: PSWinOps.WindowsUpdateUninstallResult
Returns objects with ComputerName, KBArticle, Result, ExitCode, RebootRequired, and Timestamp properties.
Domains
- Active Directory (22)
- Certificate (1)
- Event Log (9)
- Health Check (16)
- IIS (9)
- Network (26)
- NTP (5)
- Proxy (4)
- RDP (6)
- Security (1)
- System (20)
- Utils (4)
- VSS (Shadow Copy) (6)
- Windows Update (10)