Skip to content

Windows Update

Franck SALLET edited this page Sep 5, 2026 · 1 revision

Windows Update

Windows Update inspection and control: pending/installed updates, history, hide/install/uninstall/download actions, cache cleanup, and component reset.

10 function(s) in Public/windowsupdate/.

Functions

Reference

Clear-WindowsUpdateCache

Clears the Windows Update download cache to free disk space.

Stops the Windows Update (wuaserv) and BITS services, removes all files from the SoftwareDistribution\Download folder, then restarts both services. Reports the amount of disk space freed. This is useful when the cache becomes corrupted, takes up excessive space, or when troubleshooting Windows Update failures. The cache is automatically rebuilt on the next update scan.

Syntax

Clear-WindowsUpdateCache [-ComputerName <string[]>] [-IncludeDataStore]

Examples

Clear-WindowsUpdateCache

Clears the download cache on the local computer.

Clear-WindowsUpdateCache -ComputerName 'SRV01' -IncludeDataStore

Clears both the download cache and the DataStore on SRV01.

'SRV01', 'SRV02' | Clear-WindowsUpdateCache

Clears the download cache on SRV01 and SRV02 via pipeline.

Output: PSWinOps.WindowsUpdateCacheResult

Returns objects with ComputerName, CachePath, FileCount, SizeFreedMB, DataStoreCleared, Result, and Timestamp properties.


Get-WindowsUpdate

Lists available Windows Updates on local or remote computers.

Scans for available (not yet installed) Windows Updates using the COM API (Microsoft.Update.Session). Returns each pending update with its classification, product categories, download status, size, reboot requirement, MSRC severity, CVE identifiers, EULA status, and more. By default all classifications and products are returned. Use the Classification, Product, and KBArticleID parameters to filter results. Hidden updates are excluded unless the IncludeHidden switch is specified. By default, the machine's configured update source is used (WSUS, WUFB, or Windows Update). Use the MicrosoftUpdate switch to query the full Microsoft Update catalog instead.

Syntax

Get-WindowsUpdate [-ComputerName <string[]>] [-MicrosoftUpdate] [-KBArticleID <string[]>] [-Classification <string[]>] [-Product <string[]>] [-IncludeHidden]

Examples

Get-WindowsUpdate

Lists all available updates on the local computer using the configured source.

Get-WindowsUpdate -ComputerName 'SRV01' -KBArticleID 'KB5034441'

Checks if a specific KB is available on SRV01.

'SRV01', 'SRV02' | Get-WindowsUpdate -MicrosoftUpdate -Classification 'Security Updates'

Lists security updates from the full Microsoft Update catalog on SRV01 and SRV02.

Output: PSWinOps.WindowsUpdate

Returns objects with ComputerName, Title, KBArticle, Classification, Products, IsDownloaded, IsHidden, IsInstalled, IsMandatory, IsUninstallable, RebootRequired, MsrcSeverity, Description, ReleaseNotes, CveIDs, EulaAccepted, Deadline, SizeMB, UpdateId, RevisionNumber, and Timestamp properties.


Get-WindowsUpdateConfiguration

Retrieves Windows Update configuration from local or remote computers.

Reads Windows Update configuration from the registry on local or remote computers. The function queries two registry paths under HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate to retrieve WSUS, Windows Update for Business (WUFB), and Auto Update GPO settings. When the WindowsUpdate policy key exists, the computer is considered GPO-configured. The UpdateSource property is determined by analyzing UseWUServer, WUServer, and deferral settings to classify the source as WSUS, WUFB, WindowsUpdate, or Unknown.

Syntax

Get-WindowsUpdateConfiguration [-ComputerName <string[]>]

Examples

Get-WindowsUpdateConfiguration

Retrieves Windows Update configuration from the local computer.

Get-WindowsUpdateConfiguration -ComputerName 'SRV01' -Credential (Get-Credential)

Retrieves Windows Update configuration from SRV01 using explicit credentials.

'SRV01', 'SRV02' | Get-WindowsUpdateConfiguration | Where-Object -Property UpdateSource -NE -Value 'WSUS'

Queries multiple servers via pipeline and filters for those not using WSUS.

Output: PSWinOps.WindowsUpdateConfiguration

Returns an object per computer with UpdateSource, WSUS URLs, auto-update settings, deferral policies, branch readiness level, target group, and GPO configuration status.


Get-WindowsUpdateHistory

Retrieves Windows Update installation history from local or remote computers.

Queries the Windows Update Agent COM API (Microsoft.Update.Session) to retrieve the installation history of Windows Updates. Results include update title, KB article, operation type, result status, classification, products, client application, HResult error code, update source, date, description, and support URL. Output is sorted by date descending (most recent first) and limited by MaxResults.

Syntax

Get-WindowsUpdateHistory [-ComputerName <string[]>] [-MaxResults <int>]

Examples

Get-WindowsUpdateHistory

Retrieves the 50 most recent Windows Update history entries from the local computer.

Get-WindowsUpdateHistory -ComputerName 'SRV01' -Credential (Get-Credential) -MaxResults 100

Retrieves the 100 most recent update history entries from SRV01 using alternate credentials.

'SRV01', 'SRV02' | Get-WindowsUpdateHistory -MaxResults 10

Retrieves the 10 most recent update history entries from SRV01 and SRV02 via pipeline.

Output: PSWinOps.WindowsUpdateHistory

Returns objects with ComputerName, Title, KBArticle, Operation, Result, HResult, Classification, Products, ClientApplicationID, ServerSelection, ServiceID, Date, Description, SupportUrl, UpdateId, RevisionNumber, and Timestamp properties.


Hide-WindowsUpdate

Hides one or more Windows Updates to prevent them from being installed.

Hides (declines) specified Windows Updates by setting the IsHidden property to true on matching IUpdate COM objects. Hidden updates are excluded from automatic installation and from Get-WindowsUpdate results unless -IncludeHidden is specified. Use Show-WindowsUpdate to unhide them later. Searches both visible and already-hidden updates to accurately report AlreadyHidden status.

Syntax

Hide-WindowsUpdate [-ComputerName <string[]>] -KBArticleID <string[]> [-MicrosoftUpdate]

Examples

Hide-WindowsUpdate -KBArticleID 'KB5034441'

Hides KB5034441 on the local computer.

Hide-WindowsUpdate -ComputerName 'SRV01' -KBArticleID 'KB5034441', 'KB5035432'

Hides two updates on SRV01.

'SRV01', 'SRV02' | Hide-WindowsUpdate -KBArticleID 'KB5034441'

Hides KB5034441 on SRV01 and SRV02 via pipeline.

Output: PSWinOps.WindowsUpdateHideResult

Returns objects with ComputerName, Title, KBArticle, Result, and Timestamp. Result is one of: Hidden, AlreadyHidden, NotFound.


Install-WindowsUpdate

Installs available Windows Updates on local or remote computers.

Scans for available Windows Updates, downloads them if not already cached, then installs them using the COM API (Microsoft.Update.Session). Internally calls Get-WindowsUpdate to discover available updates, downloads any that are not yet cached, then installs each one using IUpdateInstaller. A progress bar displays installation status with estimated time remaining. Returns detailed results for each update including success/failure status and whether a reboot is required.

Syntax

Install-WindowsUpdate [-ComputerName <string[]>] [-MicrosoftUpdate] [-KBArticleID <string[]>] [-Classification <string[]>] [-Product <string[]>] [-IncludeHidden] [-AcceptEula] [-AutoReboot]

Examples

Install-WindowsUpdate -AcceptEula

Installs all available updates on the local computer, accepting EULAs.

Install-WindowsUpdate -ComputerName 'SRV01' -KBArticleID 'KB5034441' -AcceptEula

Installs a specific update on SRV01, accepting the EULA automatically.

'SRV01', 'SRV02' | Install-WindowsUpdate -Classification 'Security Updates' -AcceptEula -AutoReboot

Installs security updates on SRV01 and SRV02 with automatic reboot if required.

Output: PSWinOps.WindowsUpdateInstallResult

Returns objects with ComputerName, Title, KBArticle, SizeMB, Result, HResult, RebootRequired, and Timestamp properties.


Reset-WindowsUpdateComponent

Resets the Windows Update service stack to a clean state.

Stops the Windows Update related services, deletes the BITS queue, backs up the SoftwareDistribution and Catroot2 folders, resets the BITS and wuauserv service security descriptors, and reregisters the Windows Update DLLs before restarting the services and triggering a fresh detection. Optionally resets the Winsock and WinHTTP proxy network stack. This is the PSWinOps equivalent of PSWindowsUpdate's Reset-WUComponents and is used to recover a corrupted Windows Update client.

Syntax

Reset-WindowsUpdateComponent [-ComputerName <string[]>] [-IncludeNetworkReset]

Examples

Reset-WindowsUpdateComponent

Resets the Windows Update component stack on the local computer.

Reset-WindowsUpdateComponent -ComputerName 'SRV01'

Resets the Windows Update component stack on the remote server SRV01.

Reset-WindowsUpdateComponent -ComputerName 'SRV01' -IncludeNetworkReset

Resets the Windows Update stack on SRV01 and additionally resets the Winsock catalog and WinHTTP proxy. A reboot will be required on SRV01 after this runs.

'SRV01', 'SRV02' | Reset-WindowsUpdateComponent

Resets the Windows Update component stack on SRV01 and SRV02 via pipeline.

Output: PSWinOps.WindowsUpdateResetResult

Returns one object per machine with ComputerName, Status, ServicesStopped, ServicesStarted, backup paths, DLL counts, network reset flags, Failures, Notes, and Timestamp.


Save-WindowsUpdate

Downloads available Windows Updates without installing them.

Scans for available Windows Updates and downloads them to the local cache without installing. Uses the COM API (Microsoft.Update.Session) to find and download updates. Internally calls Get-WindowsUpdate to discover available updates, then downloads each one using IUpdateDownloader. A progress bar displays download status with speed, percentage based on total size, and estimated time remaining. Updates are downloaded one at a time for granular progress tracking. Use this function to pre-stage updates before a maintenance window, then install them later with Install-WindowsUpdate.

Syntax

Save-WindowsUpdate [-ComputerName <string[]>] [-MicrosoftUpdate] [-KBArticleID <string[]>] [-Classification <string[]>] [-Product <string[]>] [-IncludeHidden] [-AcceptEula]

Examples

Save-WindowsUpdate

Downloads all available updates on the local computer.

Save-WindowsUpdate -ComputerName 'SRV01' -KBArticleID 'KB5034441' -AcceptEula

Downloads a specific update on SRV01, accepting the EULA automatically.

'SRV01', 'SRV02' | Save-WindowsUpdate -MicrosoftUpdate -Classification 'Security Updates'

Downloads security updates from Microsoft Update on SRV01 and SRV02.

Output: PSWinOps.WindowsUpdateDownloadResult

Returns objects with ComputerName, Title, KBArticle, SizeMB, Result, HResult, and Timestamp properties.


Show-WindowsUpdate

Unhides previously hidden Windows Updates to allow installation.

Reverses the hiding of Windows Updates by setting the IsHidden property to false on matching IUpdate COM objects. This function searches only hidden, non-installed updates and restores visibility for those matching the specified KB article IDs. Use this after Hide-WindowsUpdate to re-enable updates for installation.

Syntax

Show-WindowsUpdate [-ComputerName <string[]>] -KBArticleID <string[]> [-MicrosoftUpdate]

Examples

Show-WindowsUpdate -KBArticleID 'KB5034441'

Unhides KB5034441 on the local computer.

Show-WindowsUpdate -ComputerName 'SRV01' -KBArticleID 'KB5034441', 'KB5035432'

Unhides two updates on SRV01.

'SRV01', 'SRV02' | Show-WindowsUpdate -KBArticleID 'KB5034441'

Unhides KB5034441 on SRV01 and SRV02 via pipeline.

Output: PSWinOps.WindowsUpdateShowResult

Returns objects with ComputerName, Title, KBArticle, Result, and Timestamp. Result is one of: Shown, NotFound.


Uninstall-WindowsUpdate

Uninstalls previously installed Windows Updates by KB article ID.

Removes one or more Windows Updates from local or remote computers using wusa.exe in quiet mode. Each KB is validated as installed via Get-HotFix before attempting uninstallation. Provides detailed exit code mapping for troubleshooting. Use this function to rollback problematic updates that cause issues in your environment.

Syntax

Uninstall-WindowsUpdate [-ComputerName <string[]>] -KBArticleID <string[]> [-AutoReboot]

Examples

Uninstall-WindowsUpdate -KBArticleID 'KB5034441'

Uninstalls KB5034441 from the local computer without automatic reboot.

Uninstall-WindowsUpdate -ComputerName 'SRV01' -KBArticleID 'KB5034441' -AutoReboot

Uninstalls KB5034441 from SRV01 with automatic reboot.

'SRV01', 'SRV02' | Uninstall-WindowsUpdate -KBArticleID 'KB5034441', 'KB5035432'

Uninstalls two KBs from two servers via pipeline.

Output: PSWinOps.WindowsUpdateUninstallResult

Returns objects with ComputerName, KBArticle, Result, ExitCode, RebootRequired, and Timestamp properties.


PSWinOps Wiki

Home

Domains

Clone this wiki locally