Start typing to search across invoices, services, domains, tickets, and more...
Nothing hurts a production Windows server more than an automatic update reboot in the middle of the night. This guide covers Windows Update management on Windows Server 2016/2019/2022: controlling automatic updates and restarts with sconfig, Group Policy or the registry, setting active hours, installing updates with the PSWindowsUpdate PowerShell module, checking update history and scheduling the reboot yourself.
Open an elevated PowerShell or Command Prompt and run sconfig. Choose the Windows Update settings entry (usually option 5) and pick Automatic, Download only or Manual. For production servers we recommend Download only: patches are fetched automatically but you decide when to install and reboot.
sconfigIn gpedit.msc go to Computer Configuration → Administrative Templates → Windows Components → Windows Update. Enable "Configure Automatic Updates" with option "3 - Auto download and notify for install", then enable "No auto-restart with logged on users for scheduled automatic updates installations". On Server Core or in scripts, write the equivalent registry values:
$au = "HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU"
New-Item -Path $au -Force | Out-Null
# 3 = download automatically, notify before install
Set-ItemProperty -Path $au -Name NoAutoUpdate -Type DWord -Value 0
Set-ItemProperty -Path $au -Name AUOptions -Type DWord -Value 3
# Never auto-restart while a user is signed in
Set-ItemProperty -Path $au -Name NoAutoRebootWithLoggedOnUsers -Type DWord -Value 1
gpupdate /forceWindows will not restart for updates during active hours. Set them in Settings → Update & Security → Windows Update → Change active hours, or with the registry commands below (maximum 18 hours).
$ux = "HKLM:\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings"
# Active hours 08:00-23:00 (no automatic restart in this window)
Set-ItemProperty -Path $ux -Name ActiveHoursStart -Type DWord -Value 8
Set-ItemProperty -Path $ux -Name ActiveHoursEnd -Type DWord -Value 23
Get-ItemProperty -Path $ux | Select-Object ActiveHoursStart,ActiveHoursEndPSWindowsUpdate is a popular module for listing, installing and hiding patches from the command line, perfect for Server Core and automation. On Windows Server 2016 enable TLS 1.2 first so PowerShell Gallery downloads work. The -IgnoreReboot switch makes sure nothing restarts automatically.
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
Install-PackageProvider -Name NuGet -Force
Install-Module -Name PSWindowsUpdate -Force
Import-Module PSWindowsUpdate
# List available updates
Get-WindowsUpdate
# Install everything but do NOT reboot automatically
Install-WindowsUpdate -AcceptAll -IgnoreReboot
# Install a single KB only
Install-WindowsUpdate -KBArticleID KB5005112 -AcceptAll -IgnoreRebootWhen you need to know why a server restarted or whether a specific KB is installed, review the history and check for a pending reboot flag.
Get-WUHistory -Last 20 | Format-Table Date,KB,Result,Title -AutoSize
Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 10
# Is a reboot pending?
Get-WURebootStatus
Test-Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\RebootRequired"After installing patches, reboot during your quietest hour. The command below calculates the seconds until 03:00 tomorrow and schedules a restart, which you can cancel at any time.
# Reboot at 03:00 tonight (time in seconds from now)
$t = (Get-Date).Date.AddDays(1).AddHours(3)
shutdown /r /t ([int]($t - (Get-Date)).TotalSeconds) /c "Planned update reboot"
# Cancel a scheduled reboot
shutdown /aTechnically yes, but an unpatched server leaves RDP, SMB and other services exposed to known exploits. Use Download only / notify instead and patch on a fixed monthly schedule.
The sconfig menu changes slightly between versions and cumulative updates. Follow the on-screen labels for Windows Update settings and Install updates.
Verify internet and DNS access, run sfc /scannow and DISM /Online /Cleanup-Image /RestoreHealth to repair system components, then retry the installation.
Still stuck after following these steps? Open a support ticket and the IMIDC 24/7 technical team will help. Please include the server IP, OS version, the commands you ran and a screenshot of the error so we can pinpoint the issue faster.