To patch Azure VMs and Azure Arc-enabled servers on a schedule, enable periodic assessment with Azure Policy, create a maintenance configuration with the Guest (InGuestPatch) scope that defines a recurring window of up to 3 hours 55 minutes, the update classifications and the reboot behavior, and attach machines to it directly or through a dynamic scope based on subscription, resource group, location, OS type or tags. Azure VMs also need patch orchestration set to Customer Managed Schedules; Arc-enabled servers only need to be connected to Azure Arc. Update Manager has no dependency on Azure Automation or Log Analytics, and it honors each machine's update source, including WSUS.
Who this is for and what you will have at the end
This guide is for server teams moving off Azure Automation Update Management, whose support ended on 31 August 2024 together with the Log Analytics agent it depended on, and for teams that patch with WSUS alone. WSUS still works and is supported, but Microsoft lists it as no longer actively developed. If your on-premises servers aren't in Azure yet, connect them first with Azure Arc onboarding at scale.
At the end you will have:
- Periodic assessment running every 24 hours on Azure VMs and Arc-enabled servers.
- Maintenance configurations for each patch ring, with windows sized to the time Update Manager reserves for installs and reboots.
- Machines attached through dynamic scopes, so tagging a server is enough to put it in a ring.
- Resource Graph queries for pending updates and installation results.
How Update Manager works
When you trigger any Update Manager operation, or a schedule runs for the first time, it installs extensions automatically: one on Azure VMs, two on Arc-enabled servers.
| Machine | Extensions |
|---|---|
| Azure VM, Windows | Microsoft.CPlat.Core.WindowsPatchExtension |
| Azure VM, Linux | Microsoft.CPlat.Core.LinuxPatchExtension |
| Arc-enabled server, Windows | Microsoft.CPlat.Core.WindowsPatchExtension (periodic assessment), Microsoft.SoftwareUpdateManagement.WindowsOsUpdateExtension (on-demand and scheduled patching) |
| Arc-enabled server, Linux | Microsoft.CPlat.Core.LinuxPatchExtension (periodic assessment), Microsoft.SoftwareUpdateManagement.LinuxOsUpdateExtension (on-demand and scheduled patching) |
Update Manager doesn't publish updates. On Windows it uses the Windows Update Agent and whatever source it's configured for: Windows Update, Microsoft Update or WSUS. On Linux it uses the package manager and its configured repositories. Results are stored in Azure Resource Graph: pending updates for 7 days, installation results for 30 days.
Patch orchestration modes
Patch orchestration is a setting on Azure VMs. Arc-enabled servers have no patch orchestration prerequisite for scheduled patching; they only need to be associated with a schedule.
| Mode | What it does |
|---|---|
| Customer Managed Schedules | Sets AutomaticByPlatform plus BypassPlatformSafetyChecksOnUserSchedule = true; patches only through your schedules |
| Azure Managed - Safe Deployment | Automatic VM guest patching of Critical and Security updates (not applicable to Arc-enabled servers) |
Windows Automatic Updates (AutomaticByOS) | Windows downloads and installs updates itself and reboots as needed |
| Manual updates | Disables Windows automatic updates; you patch manually or with another tool |
| Image Default | Linux VMs only; uses the patching configuration of the image |
What it costs
Update Manager is free for Azure VMs. Arc-enabled servers are charged per server per month, prorated daily, but only on days when the server is Connected and Update Manager either runs an operation on it (assessment or patching, on demand or scheduled) or it's associated with a schedule. Arc servers enabled for Extended Security Updates, servers in subscriptions with Defender for Servers Plan 2 (not through a security connector), and servers with Software Assurance, a Windows Server subscription license or Windows Server pay-as-you-go aren't charged. Check the pricing page for the current rate.
Prerequisites
- Arc connection for every non-Azure machine. Windows 10 and Windows 11 clients aren't supported; Microsoft recommends Intune for them.
- Resource providers. Register
Microsoft.Computein subscriptions that hold Arc servers, or periodic assessment data isn't generated. Scheduling needsMicrosoft.Maintenance. - Roles. Virtual Machine Contributor (or Owner) on Azure VMs and Azure Connected Machine Resource Administrator on Arc servers cover the machine-side permissions. Creating schedules needs
Microsoft.Maintenance/maintenanceConfigurations/writeand configuration assignment permissions; dynamic scopes need write permission at subscription level to create or modify a schedule. - Update source reachable. Windows machines must reach the Windows Update endpoints or the WSUS server in their
WUServerregistry setting. Linux machines must reach their repositories, have Python 2.7 or later, and allow the root account in/etc/sudoers. - TLS 1.2 or later and outbound HTTPS.
Step 1: Turn on periodic assessment with Azure Policy
Periodic assessment checks every machine for missing updates once every 24 hours, so compliance views stay current without manual scans.
- In the portal, open Policy > Authoring > Definitions and filter Category to Azure Update Manager.
- Assign Configure periodic checking for missing system updates on Azure virtual machines at the subscription or resource group scope.
- On Parameters, clear Only show parameters that need input or review and set OS Type. Windows and Linux need separate assignments.
- On Remediation, select Create a remediation task so existing machines are configured.
- Repeat with Configure periodic checking for missing system updates on Azure Arc-enabled servers.
- Optionally assign the audit policy Machines should be configured to periodically check for missing system updates to monitor coverage.
Specialized, migrated and restored VMs can show as non-compliant after creation; run another remediation task for them.
Step 2: Prepare Azure VMs for schedules
In Azure Update Manager > Overview > Update settings, add the Azure VMs and set Patch orchestration to Customer Managed Schedules. The Azure Policy definition Schedule recurring updates using Azure Update Manager (step 4) also sets this prerequisite for the machines it covers, and the dynamic scope wizard asks for consent to set it.
A useful side effect: a VM set to Customer Managed Schedules with no schedule attached isn't patched at all until you change it. That's the documented way to stop Azure from orchestrating patches on a server you patch by other means.
Step 3: Create maintenance configurations
Create one configuration per ring, for example a pilot ring a few days after Patch Tuesday and a production ring later in the month.
- Open Azure Update Manager > Overview, select the subscription, then Schedule updates.
- On Basics, set the subscription, resource group, name and region, and choose Maintenance scope = Guest (Azure VM, Azure Arc-enabled VMs/servers).
- Select Add a schedule. Set Start on, a Maintenance window of up to 3 hours 55 minutes, and Repeats. For monthly schedules you can repeat on the nth weekday and add an offset of up to six days either way; the second Tuesday with a +4 day offset gives you the Saturday after Patch Tuesday.
- On Machines, add machines now or leave it for dynamic scopes.
- On Updates, choose classifications and any KB IDs or packages to include or exclude. Driver updates aren't supported.
- Add tags, then Review + create.
The same configuration from PowerShell. A RecurEvery value of Month Third Sunday always falls after Patch Tuesday, because the second Tuesday is on day 8 to 14 and the third Sunday on day 15 to 21:
New-AzMaintenanceConfiguration -ResourceGroupName rg-patching -Name mc-prod-ring2 -Location westeurope `
-MaintenanceScope "InGuestPatch" `
-Timezone "W. Europe Standard Time" `
-StartDateTime "2026-10-18 22:00" `
-Duration "03:55" `
-RecurEvery "Month Third Sunday" `
-WindowParameterClassificationToInclude @('Critical', 'Security', 'UpdateRollup') `
-LinuxParameterClassificationToInclude @('Critical', 'Security') `
-InstallPatchRebootSetting "IfRequired" `
-ExtensionProperty @{"InGuestPatchMode"="User"}RecurEvery also accepts daily (Day, 3Days), weekly (Week Saturday, Sunday) and calendar-day monthly forms (Month day23, day24). Time zone names come from [System.TimeZoneInfo]::GetSystemTimeZones(), and the window follows daylight saving rules for that zone. Azure VMs must be in the same subscription as the maintenance configuration.
Size the window to the reserved time
Update Manager checks the remaining window before each step. Microsoft's Windows timeline lists 15 minutes left for a normal update, 20 minutes for a service pack and 10 minutes to start a reboot; because 10 minutes stay reserved for the reboot, the troubleshooting guidance puts the practical cut-off at 25 minutes remaining (30 for a service pack). On Linux it installs in batches and needs 15 minutes left to reboot an Azure VM. After a reboot it waits up to 15 minutes for Azure VMs and 25 minutes for Arc servers before marking the run failed. An update already installing isn't stopped when the window ends, but nothing new starts, and the run reports Maintenance window exceeded.
Step 4: Attach machines
Dynamic scopes (recommended)
- Open Azure Update Manager > Machines > Maintenance configurations and select the configuration.
- Select Dynamic scopes > Add a dynamic scope and choose the subscription.
- Under Filter by, set any of resource group, resource type, location, tags and OS type, for example the tag
PatchRing = Prod2. - Review Preview of machines based on above scope. The list is re-evaluated at run time, so it can differ later.
- On Configure Azure VMs for schedule updates, choose Change the required options to ensure schedule supportability to set Customer Managed Schedules on matching Azure VMs, then Save.
Removing the tag from a server removes it from the ring without editing the schedule. For policy-driven assignment, assign the built-in Schedule recurring updates using Azure Update Manager with the configuration's resource ID, and use a system-assigned managed identity for remediation.
Static assignments
For an Azure VM:
az maintenance assignment create \
--resource-group rg-app \
--location westeurope \
--resource-name vm-app01 \
--resource-type virtualMachines \
--provider-name Microsoft.Compute \
--configuration-assignment-name mc-prod-ring2 \
--maintenance-configuration-id "/subscriptions/<subscription-id>/resourcegroups/rg-patching/providers/Microsoft.Maintenance/maintenanceConfigurations/mc-prod-ring2"For an Arc-enabled server, use the documented REST call:
az rest --method put \
--url "https://management.azure.com/subscriptions/<subscription-id>/resourceGroups/rg-arc-servers-weu/providers/Microsoft.HybridCompute/machines/srv-file01/providers/Microsoft.Maintenance/configurationAssignments/mc-prod-ring2?api-version=2021-09-01-preview" \
--body '{"location":"westeurope","properties":{"maintenanceConfigurationId":"/subscriptions/<subscription-id>/resourcegroups/rg-patching/providers/Microsoft.Maintenance/maintenanceConfigurations/mc-prod-ring2"}}'Step 5: Test before the first scheduled run
Run an on-demand assessment and a one-time install on pilot machines. This also installs the extensions ahead of the schedule.
# Azure VM
az vm assess-patches -g rg-app -n vm-app01
# Arc-enabled server
az rest --method post \
--url "https://management.azure.com/subscriptions/<subscription-id>/resourceGroups/rg-arc-servers-weu/providers/Microsoft.HybridCompute/machines/srv-file01/assessPatches?api-version=2020-08-15-preview" \
--body '{}'In the portal, go to Azure Update Manager > Machines, select the pilot machines and choose One-time updates to install a chosen set of updates; give on-demand runs a generous maximum duration. Keep machines powered on at least 15 minutes before a scheduled window; shut-down machines aren't patched.
Verification
History. Azure Update Manager > History shows each run by maintenance run ID with per-machine status. A run is Succeeded only when every selected update installed and the reboot and final assessment completed. Never reboot with updates that need one gives Completed with warnings.
Pending updates by classification:
patchassessmentresources
| where type !has "softwarepatches"
| extend prop = parse_json(properties)
| project lastTime = prop.lastModifiedDateTime, id, OS = prop.osType,
critical = prop.availablePatchCountByClassification.critical,
security = prop.availablePatchCountByClassification.security,
other = prop.availablePatchCountByClassification.otherInstallation results for the last seven days:
patchinstallationresources
| where type !has "softwarepatches"
| extend prop = parse_json(properties)
| extend lTime = todatetime(prop.lastModifiedDateTime)
| where lTime > ago(7d)
| project lTime, RunID = name, machine = tostring(split(id, "/", 8)), OS = tostring(prop.osType),
installed = tostring(prop.installedPatchCount), failed = tostring(prop.failedPatchCount),
pending = tostring(prop.pendingPatchCount)Which machines a schedule covers:
maintenanceresources
| where type =~ 'microsoft.maintenance/configurationassignments'
| where properties.maintenanceConfigurationId =~ '/subscriptions/<subscription-id>/resourcegroups/rg-patching/providers/Microsoft.Maintenance/maintenanceConfigurations/mc-prod-ring2'
| project MachineId = properties.resourceId, AssignmentName = nameTroubleshooting
Machine shows Not assessed with an HRESULT. The update agent is misconfigured. 0x8024402C, 0x8024401C and 0x8024402F are network problems; 0x80072EE2 points to connectivity or a WSUS server the client can't reach; 0x8024002E and 0x80070422 mean the Windows Update service (wuauserv) is disabled; 0x80070005 is access denied. If you use WSUS, check WUServer and WUStatusServer under HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate.
Maintenance window exceeded although time was left. Ten minutes are always reserved for reboot, so a normal update needs 25 minutes remaining and a service pack 30. With less, the run skips installation and reports failure. Lengthen the window or split large rings.
No assessment data for Arc servers. Register Microsoft.Compute in the Arc servers' subscription.
Arc server can't be patched. The OS update extension isn't installed or didn't succeed. Trigger an on-demand assessment to install it; if it's present but not Succeeded, remove the extension and trigger an operation again.
Linux: root is not in the sudoers file with Extension returned non-zero exit code for Install: 88. Add root ALL=(ALL) ALL with sudo visudo.
ShutdownOrUnresponsive. Known limitation for machines deleted and re-created with the same resource ID within 8 hours; it clears after that period.
Schedule stopped after moving a VM. Assignments don't follow moves across resource groups or subscriptions. Remove the static assignment, move the resource, and re-create it.
A server rebooted with Never Reboot. Windows Update registry settings for automatic updates and restarts can still trigger reboots; review them on servers with strict reboot rules.
Two schedules on one machine. Only one runs at a time; the other starts when the first finishes.
Service limits
| Item | Public cloud limit |
|---|---|
| Schedules per subscription per region | 250 |
| Resource associations per schedule | 3,000 |
| Resource associations per dynamic scope | 1,000 |
| Dynamic scopes per schedule | 200 |
Checklist
- Arc connected for every on-premises server;
Microsoft.ComputeandMicrosoft.Maintenanceregistered. - Periodic assessment policies assigned for Azure VMs and Arc servers, Windows and Linux, with remediation tasks.
- Azure VMs set to Customer Managed Schedules.
- One maintenance configuration per ring, windows sized for reboot reservations, monthly offset after Patch Tuesday.
- Dynamic scopes on tags; static assignments only for exceptions.
- Pilot ring tested with on-demand assessment and one-time updates.
- History and Resource Graph queries reviewed after the first run.
- Automation Update Management solution and Log Analytics agent removed once all machines are on schedules.
If you also collect guest logs from the same servers, Azure Monitor Agent and data collection rules uses the same Arc connection.
References
- Azure Update Manager overview
- Schedule recurring updates in Azure Update Manager
- Manage update configuration settings
- Overview of dynamic scoping
- Manage a dynamic scope
- Enable periodic assessment using policy
- Programmatically manage updates for Azure VMs
- Programmatically manage updates for Azure Arc-enabled servers
- Azure Update Manager operations
- Prerequisites for Azure Update Manager
- Roles and permissions in Azure Update Manager
- Azure Update Manager FAQ
- Sample query logs from Azure Update Manager
- Troubleshoot known issues with Azure Update Manager
- New-AzMaintenanceConfiguration
- Features removed or no longer developed in Windows Server
- Retirement announcement: Azure Automation Update Management (Microsoft Q&A)