Manage Windows Updates on devices
When you create Windows Update Configurations and Windows Feature Update Configurations in the Security Library, you can apply these settings to your managed devices either directly, or through a policy. Each type of configuration can include various options that control many aspects of Windows OS updates on managed devices, such as whether a Windows Feature Update can be rolled back, ability to pause or defer updates, or to allow users to install preview releases, if applicable.
|
|
NOTE: Windows Feature Update Configurations require a separate KACE Cloud Secure license. This license also covers patch management, available in the Patching Library. Windows Update Configurations are covered by your KACE Cloud license. To obtain a KACE Cloud Secure license, contact KACE Cloud Sales. A free 14-day KACE Cloud Secure trial license is available and can be started directly from KACE Cloud. For more information about KACE Cloud licensing, see About subscriptions and licensing. |
To apply a Windows Update or Feature Update Configuration to managed devices:
- To apply a Windows Update or Feature Update Configuration to one or more Windows devices using the Devices tab:
- Select the Devices tab in top navigation.
- Select one or more Windows devices in the list.
- In the right panel, click Security.
- Windows Updates only.
- In the Security area that appears, in the Updates section, under Windows Updates, on the right of Configuration, click Set.
- In the Security Configuration Library view that appears, select a Windows Update Configuration, and click Apply to Device.

NOTE: You can only apply a single Windows Update Configuration to a device.
- Windows Feature Updates only.
- In the Security area that appears, in the Updates section, under Windows Updates, on the right of Feature Updates, click Set.
- In the Security Configuration Library view that appears, select a Windows Feature Update configuration, and click Apply to Device.

NOTE: You can only apply a single Windows Feature Update Configuration to a device.
For more information about working with devices using the Devices tab, see Managing devices.
- To apply a Windows Update or Feature Update Configuration to one or more devices using policies:
- Select the Policies tab in top navigation.
- Complete one of the following steps:
- To create a policy, click Add New.
- To edit an existing policy, click an individual policy to open the policy details.
- In the Applies Tosection, select one or more labels associated with target devices. For more details about labels, see Using labels to group similar items.
- In the right pane, in the Resources tab, click Add Resources to open the drop-down list, and then click Security to open a dialog.
- Slide the Link toggle to link/unlink a Windows Update or Feature Update configuration, as applicable.
- To link a Windows Update or Feature Update configuration to policy, slide the Link toggle to right. The color of the toggle changes to green indicating the resource is linked.
- To unlink a previously linked a Windows Update or Feature Update configuration, slide the Link toggle to left. The color of the toggle changes to red indicating the resource is unlinked.

NOTE: You cannot associate multiple Windows Update Configurations or Windows Feature Update Configurations with a policy.
- (Optional) In the Options column, click the icon to open Resource Options dialog. Select one of the following Compliance Type:
- Include - Select this option to include the resource when determining the compliance status.

NOTE: By default, all the Resources in a policy are included in compliance checks.
- Exclude - Select this option to exclude the Resource when determining the compliance status.
- Include - Select this option to include the resource when determining the compliance status.
- Click Add Resources to associate the Windows Update or Feature Update configuration to the policy. You can view the resource in the Resources pane.
- Click Push Resource to deploy the added the Windows Update or Feature Update configuration to the target devices or users.
For more information about policies, see Using policies to manage device configurations.