WSUS is deprecated but still shipped and fully functional on Windows Server 2025, and for many on-premises networks it remains the simplest way to stage updates, control reboots and keep patch traffic off the internet link. The role installs in minutes; the work is in the post-install configuration, the Group Policy that sends clients to it and the maintenance that stops the database and content folder growing without limit. The steps assume a fresh Windows Server 2025 (build 26100) member server with a dedicated data volume.
Applies to Windows Server 2025 (build 26100)
Table of Contents
Short answer: Install the role with Install-WindowsFeature UpdateServices -IncludeManagementTools, run & "C:\Program Files\Update Services\Tools\WsusUtil.exe" postinstall CONTENT_DIR=D:\WSUS, then use the console wizard to choose an upstream of Microsoft Update, the languages, products (Windows 11, Windows Server 2025, Office if needed) and classifications (Critical, Security, Updates, Upgrades). Point clients with Computer Configuration » Policies » Administrative Templates » Windows Components » Windows Update » “Specify intranet Microsoft update service location” set to http://wsus01.corp.example.com:8530, create computer groups, and schedule Invoke-WsusServerCleanup weekly.
Install the role and run the post-install
Use a data disk for content; the default C: location fills up quickly. Windows Internal Database is fine for a few hundred clients; use SQL Server for larger estates.
Install-WindowsFeature UpdateServices, UpdateServices-WidDB, UpdateServices-Services -IncludeManagementTools
New-Item D:\WSUS -ItemType Directory
& "C:\Program Files\Update Services\Tools\WsusUtil.exe" postinstall CONTENT_DIR=D:\WSUS
For SQL Server, install UpdateServices-DB instead of the WID feature and add SQL_INSTANCE_NAME=sql01\wsus to the postinstall line. The post-install creates the SUSDB database, the IIS site on port 8530 (8531 for HTTPS) and the content folder. Open TCP 8530 and 8531 inbound on the server firewall and allow outbound HTTPS to Microsoft’s update endpoints from this server only.
Configure products, classifications and sync
Open the Windows Server Update Services console from Tools in Server Manager and run the configuration wizard: synchronise from Microsoft Update (or an upstream WSUS server for a replica), set the proxy if needed, and run the first connection, which downloads the catalogue. Choose languages carefully, because each one multiplies the download size. Under Products tick only what you have: Windows 11, Windows Server 2025, Windows Server 2022, Microsoft Defender Antivirus and, if you manage them, Microsoft 365 Apps or SQL Server.
Under Classifications tick Critical Updates, Security Updates, Updates, Update Rollups and Definition Updates; add Upgrades only when you plan to deploy feature updates through WSUS, and never tick Drivers on WID, because the driver catalogue swamps the database. Set a daily synchronisation in the early hours. Review the settings from PowerShell:
Get-WsusServer | Get-WsusProduct | Where-Object {$_.Product.Title -like "Windows Server 2025*"}
Get-WsusClassification
(Get-WsusServer).GetSubscription().GetSynchronizationStatus()
Point clients at the server with Group Policy
Create a GPO linked to the workstation and server OUs with these settings under Computer Configuration » Policies » Administrative Templates » Windows Components » Windows Update:
- Manage updates offered from Windows Server Update Service » “Specify intranet Microsoft update service location”: Enabled, both fields
http://wsus01.corp.example.com:8530 - Manage end user experience » “Configure Automatic Updates”: Enabled, option 4 (auto download and schedule the install), with a day and time
- Manage updates offered from Windows Server Update Service » “Enable client-side targeting”: Enabled, target group name matching the WSUS computer group (for example
PilotorServers) - Manage updates offered from Windows Server Update Service » “Do not allow update deferral policies to cause scans against Windows Update”: Enabled, so dual-scan does not bypass WSUS on Windows 11
- Legacy Policies » “No auto-restart with logged on users for scheduled automatic updates installations”: Enabled on servers
On Windows 11 25H2 and 26H1 clients, “Specify source service for specific classes of Windows Updates” can send drivers and feature updates to Windows Update while quality updates stay on WSUS. In the console under Options » Computers choose “Use Group Policy or registry settings on computers” so client-side targeting works.
Approve updates and automate the routine
Create at least three computer groups (Pilot, Workstations, Servers) and an automatic approval rule that approves Critical and Security updates for Pilot when synchronised, then approve the rest manually after a week. In PowerShell:
$wsus = Get-WsusServer
Get-WsusUpdate -Classification Security -Approval Unapproved -Status FailedOrNeeded |
Approve-WsusUpdate -Action Install -TargetGroupName "Pilot"
Run the cleanup weekly with Invoke-WsusServerCleanup -CleanupObsoleteUpdates -CleanupUnneededContentFiles -CompressUpdates -DeclineExpiredUpdates -DeclineSupersededUpdates, and re-index SUSDB periodically; on WID the database is reachable at np:\\.\pipe\MICROSOFT##WID\tsql\query with sqlcmd. Raise the IIS WsusPool private memory limit from 1.8 GB to 4 GB or more and set the queue length to 2000, otherwise clients receive HTTP 503 during large scans.
Verify
On a client, force a check-in and look at the result:
gpupdate /force
Get-ItemProperty "HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" | Select-Object WUServer, TargetGroup
usoclient StartScan
Get-WinEvent -LogName "Microsoft-Windows-WindowsUpdateClient/Operational" -MaxEvents 10
The client should appear in the console under its target group within an hour, with a “Last status report” timestamp. Event ID 26 in the client log records a successful scan against the WSUS URL. A common pitfall is a client that reports to WSUS but installs nothing because a deferral policy triggers dual-scan; the policy above resolves it. For the current patch content, see Windows 11 Patch Tuesday September 2026 KB5124008.
WSUS Windows Server 2025 at a glance

Official documentation: Windows Server documentation.
Related guides: Transfer and seize FSMO roles with PowerShell and ntdsutil · Fix AD replication errors 8453 and 1722 “The RPC server is unavailable” · A basic RMM monitoring policy for small-business endpoints: disk, patching and antivirus.
Frequently asked questions
Does WSUS on Windows Server 2025 still receive updates for Windows 11 and Server 2025?
Yes; the role is deprecated in the sense of no new features, but it continues to synchronise the full catalogue including Windows 11 26H1 and Windows Server 2025 quality updates for the life of the operating system.
How long does the first WSUS synchronisation take?
The initial catalogue sync takes 30 minutes to a few hours depending on the products selected and the link speed; content downloads begin only when updates are approved, so the first approvals can take several more hours to arrive.
Can I undo WSUS and send clients back to Windows Update?
Yes; set the intranet update location policy to Not Configured and remove the target group setting, run gpupdate /force, and clients resume scanning against Microsoft Update at their next cycle without any registry cleanup.
Maintenance record
This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.
- Maintained by
- srvScripts editorial team
- Supported versions
- Windows Server 2025 (build 26100)
- Last full review
- Next review