Cloud & infrastructure

Azure Update Manager: Schedule Patching for Azure VMs and Arc Servers

Replace Automation Update Management or WSUS-only patching with Azure Update Manager: periodic assessment, maintenance configurations, dynamic scopes and scheduled patching for Azure and Arc servers.

12 min read
On this page

To patch Azure VMs and Azure Arc-enabled servers on a schedule, enable periodic assessment with Azure Policy, create a maintenance configuration with the Guest (InGuestPatch) scope that defines a recurring window of up to 3 hours 55 minutes, the update classifications and the reboot behavior, and attach machines to it directly or through a dynamic scope based on subscription, resource group, location, OS type or tags. Azure VMs also need patch orchestration set to Customer Managed Schedules; Arc-enabled servers only need to be connected to Azure Arc. Update Manager has no dependency on Azure Automation or Log Analytics, and it honors each machine's update source, including WSUS.

Who this is for and what you will have at the end

This guide is for server teams moving off Azure Automation Update Management, whose support ended on 31 August 2024 together with the Log Analytics agent it depended on, and for teams that patch with WSUS alone. WSUS still works and is supported, but Microsoft lists it as no longer actively developed. If your on-premises servers aren't in Azure yet, connect them first with Azure Arc onboarding at scale.

At the end you will have:

  • Periodic assessment running every 24 hours on Azure VMs and Arc-enabled servers.
  • Maintenance configurations for each patch ring, with windows sized to the time Update Manager reserves for installs and reboots.
  • Machines attached through dynamic scopes, so tagging a server is enough to put it in a ring.
  • Resource Graph queries for pending updates and installation results.

How Update Manager works

When you trigger any Update Manager operation, or a schedule runs for the first time, it installs extensions automatically: one on Azure VMs, two on Arc-enabled servers.

MachineExtensions
Azure VM, WindowsMicrosoft.CPlat.Core.WindowsPatchExtension
Azure VM, LinuxMicrosoft.CPlat.Core.LinuxPatchExtension
Arc-enabled server, WindowsMicrosoft.CPlat.Core.WindowsPatchExtension (periodic assessment), Microsoft.SoftwareUpdateManagement.WindowsOsUpdateExtension (on-demand and scheduled patching)
Arc-enabled server, LinuxMicrosoft.CPlat.Core.LinuxPatchExtension (periodic assessment), Microsoft.SoftwareUpdateManagement.LinuxOsUpdateExtension (on-demand and scheduled patching)

Update Manager doesn't publish updates. On Windows it uses the Windows Update Agent and whatever source it's configured for: Windows Update, Microsoft Update or WSUS. On Linux it uses the package manager and its configured repositories. Results are stored in Azure Resource Graph: pending updates for 7 days, installation results for 30 days.

Patch orchestration modes

Patch orchestration is a setting on Azure VMs. Arc-enabled servers have no patch orchestration prerequisite for scheduled patching; they only need to be associated with a schedule.

ModeWhat it does
Customer Managed SchedulesSets AutomaticByPlatform plus BypassPlatformSafetyChecksOnUserSchedule = true; patches only through your schedules
Azure Managed - Safe DeploymentAutomatic VM guest patching of Critical and Security updates (not applicable to Arc-enabled servers)
Windows Automatic Updates (AutomaticByOS)Windows downloads and installs updates itself and reboots as needed
Manual updatesDisables Windows automatic updates; you patch manually or with another tool
Image DefaultLinux VMs only; uses the patching configuration of the image

What it costs

Update Manager is free for Azure VMs. Arc-enabled servers are charged per server per month, prorated daily, but only on days when the server is Connected and Update Manager either runs an operation on it (assessment or patching, on demand or scheduled) or it's associated with a schedule. Arc servers enabled for Extended Security Updates, servers in subscriptions with Defender for Servers Plan 2 (not through a security connector), and servers with Software Assurance, a Windows Server subscription license or Windows Server pay-as-you-go aren't charged. Check the pricing page for the current rate.

Prerequisites

  • Arc connection for every non-Azure machine. Windows 10 and Windows 11 clients aren't supported; Microsoft recommends Intune for them.
  • Resource providers. Register Microsoft.Compute in subscriptions that hold Arc servers, or periodic assessment data isn't generated. Scheduling needs Microsoft.Maintenance.
  • Roles. Virtual Machine Contributor (or Owner) on Azure VMs and Azure Connected Machine Resource Administrator on Arc servers cover the machine-side permissions. Creating schedules needs Microsoft.Maintenance/maintenanceConfigurations/write and configuration assignment permissions; dynamic scopes need write permission at subscription level to create or modify a schedule.
  • Update source reachable. Windows machines must reach the Windows Update endpoints or the WSUS server in their WUServer registry setting. Linux machines must reach their repositories, have Python 2.7 or later, and allow the root account in /etc/sudoers.
  • TLS 1.2 or later and outbound HTTPS.

Step 1: Turn on periodic assessment with Azure Policy

Periodic assessment checks every machine for missing updates once every 24 hours, so compliance views stay current without manual scans.

  1. In the portal, open Policy > Authoring > Definitions and filter Category to Azure Update Manager.
  2. Assign Configure periodic checking for missing system updates on Azure virtual machines at the subscription or resource group scope.
  3. On Parameters, clear Only show parameters that need input or review and set OS Type. Windows and Linux need separate assignments.
  4. On Remediation, select Create a remediation task so existing machines are configured.
  5. Repeat with Configure periodic checking for missing system updates on Azure Arc-enabled servers.
  6. Optionally assign the audit policy Machines should be configured to periodically check for missing system updates to monitor coverage.

Specialized, migrated and restored VMs can show as non-compliant after creation; run another remediation task for them.

Step 2: Prepare Azure VMs for schedules

In Azure Update Manager > Overview > Update settings, add the Azure VMs and set Patch orchestration to Customer Managed Schedules. The Azure Policy definition Schedule recurring updates using Azure Update Manager (step 4) also sets this prerequisite for the machines it covers, and the dynamic scope wizard asks for consent to set it.

A useful side effect: a VM set to Customer Managed Schedules with no schedule attached isn't patched at all until you change it. That's the documented way to stop Azure from orchestrating patches on a server you patch by other means.

Step 3: Create maintenance configurations

Create one configuration per ring, for example a pilot ring a few days after Patch Tuesday and a production ring later in the month.

  1. Open Azure Update Manager > Overview, select the subscription, then Schedule updates.
  2. On Basics, set the subscription, resource group, name and region, and choose Maintenance scope = Guest (Azure VM, Azure Arc-enabled VMs/servers).
  3. Select Add a schedule. Set Start on, a Maintenance window of up to 3 hours 55 minutes, and Repeats. For monthly schedules you can repeat on the nth weekday and add an offset of up to six days either way; the second Tuesday with a +4 day offset gives you the Saturday after Patch Tuesday.
  4. On Machines, add machines now or leave it for dynamic scopes.
  5. On Updates, choose classifications and any KB IDs or packages to include or exclude. Driver updates aren't supported.
  6. Add tags, then Review + create.

The same configuration from PowerShell. A RecurEvery value of Month Third Sunday always falls after Patch Tuesday, because the second Tuesday is on day 8 to 14 and the third Sunday on day 15 to 21:

New-AzMaintenanceConfiguration -ResourceGroupName rg-patching -Name mc-prod-ring2 -Location westeurope `
  -MaintenanceScope "InGuestPatch" `
  -Timezone "W. Europe Standard Time" `
  -StartDateTime "2026-10-18 22:00" `
  -Duration "03:55" `
  -RecurEvery "Month Third Sunday" `
  -WindowParameterClassificationToInclude @('Critical', 'Security', 'UpdateRollup') `
  -LinuxParameterClassificationToInclude @('Critical', 'Security') `
  -InstallPatchRebootSetting "IfRequired" `
  -ExtensionProperty @{"InGuestPatchMode"="User"}

RecurEvery also accepts daily (Day, 3Days), weekly (Week Saturday, Sunday) and calendar-day monthly forms (Month day23, day24). Time zone names come from [System.TimeZoneInfo]::GetSystemTimeZones(), and the window follows daylight saving rules for that zone. Azure VMs must be in the same subscription as the maintenance configuration.

Size the window to the reserved time

Update Manager checks the remaining window before each step. Microsoft's Windows timeline lists 15 minutes left for a normal update, 20 minutes for a service pack and 10 minutes to start a reboot; because 10 minutes stay reserved for the reboot, the troubleshooting guidance puts the practical cut-off at 25 minutes remaining (30 for a service pack). On Linux it installs in batches and needs 15 minutes left to reboot an Azure VM. After a reboot it waits up to 15 minutes for Azure VMs and 25 minutes for Arc servers before marking the run failed. An update already installing isn't stopped when the window ends, but nothing new starts, and the run reports Maintenance window exceeded.

Step 4: Attach machines

  1. Open Azure Update Manager > Machines > Maintenance configurations and select the configuration.
  2. Select Dynamic scopes > Add a dynamic scope and choose the subscription.
  3. Under Filter by, set any of resource group, resource type, location, tags and OS type, for example the tag PatchRing = Prod2.
  4. Review Preview of machines based on above scope. The list is re-evaluated at run time, so it can differ later.
  5. On Configure Azure VMs for schedule updates, choose Change the required options to ensure schedule supportability to set Customer Managed Schedules on matching Azure VMs, then Save.

Removing the tag from a server removes it from the ring without editing the schedule. For policy-driven assignment, assign the built-in Schedule recurring updates using Azure Update Manager with the configuration's resource ID, and use a system-assigned managed identity for remediation.

Static assignments

For an Azure VM:

az maintenance assignment create \
  --resource-group rg-app \
  --location westeurope \
  --resource-name vm-app01 \
  --resource-type virtualMachines \
  --provider-name Microsoft.Compute \
  --configuration-assignment-name mc-prod-ring2 \
  --maintenance-configuration-id "/subscriptions/<subscription-id>/resourcegroups/rg-patching/providers/Microsoft.Maintenance/maintenanceConfigurations/mc-prod-ring2"

For an Arc-enabled server, use the documented REST call:

az rest --method put \
  --url "https://management.azure.com/subscriptions/<subscription-id>/resourceGroups/rg-arc-servers-weu/providers/Microsoft.HybridCompute/machines/srv-file01/providers/Microsoft.Maintenance/configurationAssignments/mc-prod-ring2?api-version=2021-09-01-preview" \
  --body '{"location":"westeurope","properties":{"maintenanceConfigurationId":"/subscriptions/<subscription-id>/resourcegroups/rg-patching/providers/Microsoft.Maintenance/maintenanceConfigurations/mc-prod-ring2"}}'

Step 5: Test before the first scheduled run

Run an on-demand assessment and a one-time install on pilot machines. This also installs the extensions ahead of the schedule.

# Azure VM
az vm assess-patches -g rg-app -n vm-app01
 
# Arc-enabled server
az rest --method post \
  --url "https://management.azure.com/subscriptions/<subscription-id>/resourceGroups/rg-arc-servers-weu/providers/Microsoft.HybridCompute/machines/srv-file01/assessPatches?api-version=2020-08-15-preview" \
  --body '{}'

In the portal, go to Azure Update Manager > Machines, select the pilot machines and choose One-time updates to install a chosen set of updates; give on-demand runs a generous maximum duration. Keep machines powered on at least 15 minutes before a scheduled window; shut-down machines aren't patched.

Verification

History. Azure Update Manager > History shows each run by maintenance run ID with per-machine status. A run is Succeeded only when every selected update installed and the reboot and final assessment completed. Never reboot with updates that need one gives Completed with warnings.

Pending updates by classification:

patchassessmentresources
| where type !has "softwarepatches"
| extend prop = parse_json(properties)
| project lastTime = prop.lastModifiedDateTime, id, OS = prop.osType,
          critical = prop.availablePatchCountByClassification.critical,
          security = prop.availablePatchCountByClassification.security,
          other = prop.availablePatchCountByClassification.other

Installation results for the last seven days:

patchinstallationresources
| where type !has "softwarepatches"
| extend prop = parse_json(properties)
| extend lTime = todatetime(prop.lastModifiedDateTime)
| where lTime > ago(7d)
| project lTime, RunID = name, machine = tostring(split(id, "/", 8)), OS = tostring(prop.osType),
          installed = tostring(prop.installedPatchCount), failed = tostring(prop.failedPatchCount),
          pending = tostring(prop.pendingPatchCount)

Which machines a schedule covers:

maintenanceresources
| where type =~ 'microsoft.maintenance/configurationassignments'
| where properties.maintenanceConfigurationId =~ '/subscriptions/<subscription-id>/resourcegroups/rg-patching/providers/Microsoft.Maintenance/maintenanceConfigurations/mc-prod-ring2'
| project MachineId = properties.resourceId, AssignmentName = name

Troubleshooting

Machine shows Not assessed with an HRESULT. The update agent is misconfigured. 0x8024402C, 0x8024401C and 0x8024402F are network problems; 0x80072EE2 points to connectivity or a WSUS server the client can't reach; 0x8024002E and 0x80070422 mean the Windows Update service (wuauserv) is disabled; 0x80070005 is access denied. If you use WSUS, check WUServer and WUStatusServer under HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate.

Maintenance window exceeded although time was left. Ten minutes are always reserved for reboot, so a normal update needs 25 minutes remaining and a service pack 30. With less, the run skips installation and reports failure. Lengthen the window or split large rings.

No assessment data for Arc servers. Register Microsoft.Compute in the Arc servers' subscription.

Arc server can't be patched. The OS update extension isn't installed or didn't succeed. Trigger an on-demand assessment to install it; if it's present but not Succeeded, remove the extension and trigger an operation again.

Linux: root is not in the sudoers file with Extension returned non-zero exit code for Install: 88. Add root ALL=(ALL) ALL with sudo visudo.

ShutdownOrUnresponsive. Known limitation for machines deleted and re-created with the same resource ID within 8 hours; it clears after that period.

Schedule stopped after moving a VM. Assignments don't follow moves across resource groups or subscriptions. Remove the static assignment, move the resource, and re-create it.

A server rebooted with Never Reboot. Windows Update registry settings for automatic updates and restarts can still trigger reboots; review them on servers with strict reboot rules.

Two schedules on one machine. Only one runs at a time; the other starts when the first finishes.

Service limits

ItemPublic cloud limit
Schedules per subscription per region250
Resource associations per schedule3,000
Resource associations per dynamic scope1,000
Dynamic scopes per schedule200

Checklist

  • Arc connected for every on-premises server; Microsoft.Compute and Microsoft.Maintenance registered.
  • Periodic assessment policies assigned for Azure VMs and Arc servers, Windows and Linux, with remediation tasks.
  • Azure VMs set to Customer Managed Schedules.
  • One maintenance configuration per ring, windows sized for reboot reservations, monthly offset after Patch Tuesday.
  • Dynamic scopes on tags; static assignments only for exceptions.
  • Pilot ring tested with on-demand assessment and one-time updates.
  • History and Resource Graph queries reviewed after the first run.
  • Automation Update Management solution and Log Analytics agent removed once all machines are on schedules.

If you also collect guest logs from the same servers, Azure Monitor Agent and data collection rules uses the same Arc connection.

References

Questions people ask

Is Azure Update Manager free?

It's available at no extra charge for Azure VMs and for Azure Arc-enabled Azure Local VMs created through an Arc resource bridge. Other Arc-enabled servers are billed per server per month, prorated daily, for days on which the server is connected and managed by Update Manager. Servers enabled for Extended Security Updates through Arc, covered by Defender for Servers Plan 2, or licensed with Software Assurance or Windows Server pay-as-you-go aren't charged.

Can Azure Update Manager use my existing WSUS server?

Yes. Update Manager relies on the Windows Update client and honors its configuration, so machines pointed at WSUS get their updates from WSUS while Update Manager controls the schedule. Results can differ from Microsoft Update depending on when WSUS last synchronized.

Do Azure VMs need any setting before scheduled patching works?

Yes. Azure VMs must have patch orchestration set to Customer Managed Schedules, which sets Patch mode to AutomaticByPlatform and BypassPlatformSafetyChecksOnUserSchedule to true. Arc-enabled servers have no patch orchestration prerequisite, but they must be associated with a schedule.

What is the longest maintenance window I can set?

The portal documents an upper limit of 3 hours 55 minutes for a guest maintenance window. Update Manager reserves time inside the window for reboots and stops starting new updates when too little time remains, so size the window for your slowest machines.

Azure Update ManagerAzure ArcAzure Virtual MachinesMaintenance ConfigurationsAzure Policy
  1. Onboard Servers to Azure Arc at Scale with a Service Principal

    Connect hundreds of on-premises Windows and Linux servers to Azure Arc with a least-privilege service principal, a scripted azcmagent install and connect, and a repeatable verification step.

  2. A practical Azure landing zone for small and mid-size companies

    Set up Azure management groups, subscriptions, hub-and-spoke networking, Azure Policy, RBAC and budgets the right way from day one, scaled down from Microsoft's landing zone architecture.

  3. Azure Bastion SKUs compared: choose Developer, Basic, Standard or Premium

    Compare the four Azure Bastion SKUs on features, capacity and requirements, then deploy the right one to RDP and SSH into VMs that have no public IP address.