Plenty of Windows fleets still get their Patch Tuesday from a server in the corner that someone set up in 2014 and nobody wants to touch. Microsoft stopped building new features for that server in 2024, so the question now is what to keep, what to move and when. This guide explains what WSUS is, what the deprecation changes in practice, and which replacement fits which devices.
TL;DR
- WSUS (Windows Server Update Services) is a Windows Server role that downloads Microsoft updates once, lets you approve them, and serves them to your own devices.
- Microsoft deprecated WSUS in September 2024. It still ships in Windows Server 2025, still receives updates and is still supported. It gets no new features.
- For Windows clients, Microsoft points to Windows Autopatch and Intune. For servers, it points to Azure Update Manager.
- Configuration Manager isn't affected by the deprecation, and it still uses WSUS under the hood.
- You don't have to move everything at once. The scan source policy lets you pull one update type at a time off WSUS.
- Air-gapped networks are the one place WSUS has no like-for-like cloud replacement. Plan those separately.
What Is WSUS?
WSUS stands for Windows Server Update Services. It's a server role you add to Windows Server, and its job is simple: sit between Microsoft Update and your devices.
Without it, every PC downloads its own updates from Microsoft and installs them on Microsoft's timing. With it, one server downloads each update once. You decide which updates get approved, which groups of computers get them, and by when.
Microsoft's own description puts it well: WSUS lets a company defer updates, approve them selectively, choose when they're delivered and decide which devices get them. That control is why it has lasted more than twenty years.
How WSUS Works
A WSUS setup has four moving parts:
- The upstream sync. The WSUS server connects to Microsoft Update on a schedule and pulls down update metadata, then the update files for anything you approve. In a bigger network, one upstream server syncs with Microsoft and downstream servers sync from it.
- Computer groups. Devices land in "Unassigned Computers" when they first check in. You sort them into groups that match your deployment rings, either by hand in the console (server-side targeting) or through Group Policy (client-side targeting).
- Approvals and deadlines. You approve an update for a group, optionally with an installation deadline. Automatic approval rules can do this for you after each sync.
- Group Policy on the clients. Two settings point each device at your server: Configure Automatic Updates and Specify intranet Microsoft update service location. The defaults are port 8530 for HTTP and 8531 for HTTPS.
Behind all of it sits a database. WSUS installs Windows Internal Database (WID) by default, or you can point it at SQL Server.
If you've ever had to grab a single KB by hand for a machine that WSUS couldn't reach, you've probably also used the Microsoft Update Catalog. WSUS is the same content, delivered on a schedule and under your approvals.
This Server Academy explainer covers the basics if you've never opened the console:
WSUS vs Windows Update Client Policies
The name Microsoft uses has shifted a few times. Windows Update for Business is now documented as Windows Update client policies, and Autopatch builds on top of it. The difference from WSUS comes down to where the updates come from.
With WSUS, your server is the source. Devices download from it, and nothing installs until you approve it there.
With Windows Update client policies, Microsoft's cloud is the source. You don't approve individual updates. You set rules: defer quality updates by a few days, defer feature updates by months, pick a deadline, and assign devices to rings. Each device downloads directly from Windows Update, wherever it is.
That trade is the whole decision in miniature. WSUS gives you per-update control and local downloads, at the cost of a server to maintain. Client policies give you no server and devices that patch from any network, at the cost of per-update approval.
On Windows 10, pointing a device at WSUS and setting deferral policies at the same time used to make it scan Windows Update instead, a behavior called Dual Scan. Microsoft replaced that with the scan source policy covered further down, and Dual Scan isn't supported on Windows 11.
What WSUS Deprecation Means
On September 20, 2024, Microsoft announced it had deprecated WSUS. The wording matters here, because "deprecated" got read as "dead" in a lot of threads.
Microsoft's clarification a few days later spelled it out. It's no longer investing in new capabilities or taking feature requests. It is preserving current functionality, will keep publishing updates through the WSUS channel, and has no current plans to remove WSUS from in-market versions of Windows Server, including Server 2025.
In plain terms, the WSUS role still ships in Windows Server 2016, 2019, 2022 and 2025, still gets monthly content, and is still supported for production. What's gone is any new feature, any feature request, and any reason to expect a roadmap.
One related change is easy to miss. Windows Internal Database, the default WSUS database, is also on Microsoft's deprecated list for Windows Server, with a note to consider SQL Server instead. WID still works today. But a WSUS box on WID is now a deprecated role sitting on a deprecated database.
The r/sysadmin thread from the week of the announcement is a good read on how admins took the news:
Why Teams Still Run WSUS
WSUS stuck around because it solves a few problems well, and some of them have no clean cloud answer.
Approval control. Nothing installs until someone approves it. For a team that got burned by a bad cumulative update, that gate is the whole point.
Bandwidth. One server downloads each update once instead of every device pulling it separately. On a thin branch-office link, that still matters.
Disconnected networks. WSUS can run disconnected: you export updates from a connected server and import them on the isolated one. Labs, OT networks and classified environments depend on this.
No extra license. WSUS comes with Windows Server. Cloud replacements sit behind specific Microsoft 365 or Azure licensing.
Servers. Some teams keep servers on WSUS because they want a human deciding when a domain controller reboots.
None of those reasons went away in 2024. What changed is that they now come with a deprecated tool attached.
Where WSUS Costs You Time
The other side of the ledger is maintenance. WSUS keeps working as long as someone keeps it tidy, and tidying it is a recurring chore.
- Database bloat. The update catalog grows every month. Superseded and expired updates pile up until the console times out.
- Cleanup that nobody schedules. The Server Cleanup Wizard and
Invoke-WsusServerCleanupin PowerShell exist for exactly this. On a neglected server, the first run can take hours. - Devices that never check in. A laptop that works from home and never touches the VPN never reaches an on-premises WSUS server. It either falls behind or gets updates from Windows Update with none of your approvals applied.
- Reporting. WSUS reports show what a client said it installed. Pulling that into anything a client or auditor wants to read takes exports and spreadsheets.
If you already script cleanup, the cmdlets in our PowerShell commands guide cover the basics of running them on a schedule.
Keep WSUS Healthy While You Transition
A migration can take months, and the old server still has to patch devices in the meantime. Three habits keep it usable until the day you switch it off.
First, sync less. In the WSUS console under Options > Products and Classifications, untick products you don't run and the Drivers classification. Driver metadata is the fastest way to bloat the database.
Second, clean up on a schedule. The UpdateServices PowerShell module handles the whole job in one line, and it's worth running monthly from Task Scheduler:
powershellGet-WsusServer | Invoke-WsusServerCleanup -DeclineSupersededUpdates ` -DeclineExpiredUpdates -CleanupObsoleteUpdates ` -CleanupObsoleteComputers -CleanupUnneededContentFiles
Third, decline what you'll never approve. Superseded updates, ARM64 builds on an all-x64 fleet and old feature updates only slow down the console and every client scan.
What Replaces WSUS
Microsoft named its replacements in the deprecation post: Windows Autopatch and Microsoft Intune for client update management, and Azure Update Manager for servers. Each covers a different slice of what WSUS did.
Windows Autopatch and Intune (Windows Clients)
Windows Autopatch runs inside the Intune admin center. It handles quality updates, feature updates, and driver and firmware updates through update rings and Autopatch groups. You can set each content type to deploy automatically or wait for manual approval, which is the part WSUS admins miss first.
Microsoft says Autopatch aims to update 95% of devices by their target compliance date. Reporting refreshes in under four hours.
The catch is prerequisites. Autopatch needs Microsoft 365 Business Premium, Windows Enterprise E3 or E5 (including through Microsoft 365 F3, E3 or E5), or Education A3 or A5. Devices must be corporate-owned, enrolled in Intune or co-managed with Configuration Manager, and able to reach the internet. Our Intune review covers what the rest of the Intune license buys.
Azure Update Manager (Servers)
Azure Update Manager patches Windows and Linux servers in Azure, on-premises and in other clouds. On-premises servers need to be connected through Azure Arc first. It schedules updates in maintenance windows, runs assessments every 24 hours and reports compliance in one view.
One detail makes the transition easier. Azure Update Manager can apply updates that are published to WSUS, so a server can keep its WSUS source while Update Manager handles scheduling and reporting.
Configuration Manager
Configuration Manager (still widely called SCCM) uses a WSUS server as its software update point. Microsoft said the deprecation doesn't affect Configuration Manager's capabilities or support. If you run ConfigMgr today, you aren't forced off WSUS. You're on the same slow road as everyone else, just with more tooling around it.
RMM and Third-Party Patching
An RMM or a dedicated patch tool is the fourth path, and for MSPs it's often the first. These tools talk to the Windows Update agent directly, apply their own approval policies, and usually patch third-party apps too, which WSUS doesn't handle out of the box. Our patch management tools roundup compares the main options.
How to Choose a WSUS Alternative
Pick by device and license first, then by how much control you need.
Start with the network. If a network can't reach the internet, none of the cloud tools can patch it. Keep WSUS there, move it to SQL Server if it's still on WID, and document it as a deliberate exception.
Then check licenses. A client already on Business Premium or E3 has Autopatch included. Paying for an upgrade just to replace WSUS is a harder sell for a 20-seat office.
Then look at who owns the tooling. For an MSP, one patching tool across every client usually beats a different Microsoft console per tenant. For an internal IT team with Microsoft 365 E3, Autopatch keeps everything in Intune.
Then decide on servers separately. Servers carry more risk per reboot. Azure Update Manager, ConfigMgr, an RMM with maintenance windows or a kept WSUS server can all be reasonable here, depending on what the rest of the estate uses.
Whatever you pick, keep an approval step for feature updates and a pilot ring for everything. That's the part of WSUS worth keeping.
How to Move Off WSUS Without a Patching Gap
The migration risk sits in the handover week, when devices get updates from nowhere, or from two places at once.
1. Find What Still Points at WSUS
Every device managed by WSUS carries its server address in the registry, written there by Group Policy. This one-liner shows it on a single machine:
powershellGet-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate' | Select-Object WUServer, WUStatusServer
An empty result means the device isn't pointed at WSUS. Run it across the fleet and you have your real inventory, which can differ from what the WSUS console shows. OpenFrame can run a script like this across every device in a client's environment and collect the output in one place.
2. Move One Update Type at a Time
Windows 10 version 2004 and later, and Windows 11, support the scan source policy. In Group Policy it's Specify source service for specific classes of Windows Updates, under Computer Configuration > Administrative Templates > Windows Components > Windows Update > Manage updates offered from Windows Server Update Service.
It splits updates into four classes: feature updates, quality updates, driver and firmware updates, and updates for other Microsoft products. You choose WSUS or Windows Update for each class. Microsoft's own advice is to move step by step, for example drivers first, then quality updates.
Two cautions from Microsoft's documentation. The old "Dual Scan" policy isn't supported on Windows 11 and conflicts with the scan source policy on Windows 10. And if you use Intune, set all four CSP policies, not just one. Our guide to Windows Update group policy covers the deferral settings that sit alongside it.
3. Pilot, Then Widen
Build a pilot ring in the new tool that mirrors your WSUS pilot group. Run it for at least one full Patch Tuesday cycle. Compare what installed with what WSUS would have approved.
An admin on r/Intune asked how to do exactly this move from WSUS to Intune-managed updates:
4. Remove the WSUS Policy, Then the Server
Unlink the WSUS Group Policy objects only after the new tool shows devices reporting in. Then re-run the registry check to confirm nothing still points at the old server. Keep the WSUS server read-only for a month in case you need to roll back, then decommission it.
Should You Replace WSUS Now?
WSUS isn't going to stop working next Patch Tuesday. Microsoft says it's supported, patched and shipping in Server 2025. That gives you time to move on your schedule instead of in a hurry.
Use that time. Move the clients that can reach the cloud, split servers into their own decision, and keep WSUS only where the network leaves no other choice. For the wider picture of how updates fit into your security routine, read our patch management tools roundup next.
Content Marketing Lead
Ohayo! I run content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.
