The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Record OS buildGet-ComputerInfo | Select-Object WindowsProductName, WindowsVersion, OsBuildNumber, OsArchitectureView examples
List reported hotfixesGet-HotFix | Sort-Object InstalledOn -DescendingView examples
List servicing packagesdism.exe /Online /Get-Packages /Format:TableView examples
Inspect update servicesGet-Service wuauserv, bits, cryptsvc | Select-Object Name, Status, StartTypeView examples
Read Windows Update policyGet-ItemProperty ` 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate' ` -ErrorAction SilentlyContinueView examples
Create WUA searcher$searcher = (New-Object -ComObject ` Microsoft.Update.Session).CreateUpdateSearcher()View examples
Scan for missing updates$result = ` $searcher.Search("IsInstalled=0 and IsHidden=0")View examples
Review scan results$result.Updates | Select-Object Title, MsrcSeverity, IsDownloaded, RebootRequiredView examples
Query WUA history$searcher.QueryHistory(0, 30) | Select-Object Date, Title, Operation, ResultCode, HResultView examples
Read operational eventsGet-WinEvent -LogName ` 'Microsoft-Windows-WindowsUpdateClient/Operational' ` -MaxEvents 50View examples
Build readable update logGet-WindowsUpdateLog -LogPath (Join-Path $PWD ` 'WindowsUpdate.log')View examples
Scan component-store healthdism.exe /Online /Cleanup-Image /ScanHealthView examples
Hash a staged packageGet-FileHash -LiteralPath 'C:\Staging\KB0000000.msu' ` -Algorithm SHA256View examples
Install a staged MSUdism.exe /Online /Add-Package ` /PackagePath:"C:\Staging\KB0000000.msu" ` /PreventPending /NoRestartView examples
Schedule controlled restartshutdown.exe /r /t 900 /d p:2:17 /c ` "Approved Windows Update maintenance"View examples
Cancel scheduled restartshutdown.exe /aView examples

Reliable patching is a change-management workflow, not a single install command. Establish the exact Windows build and policy source, scan without changing the machine, stage updates through the approved service, test a representative ring, preserve logs and rollback options, and schedule any required restart. Local commands do not override organizational Windows Update for Business, Intune, Configuration Manager, or WSUS policy.

Step by step

Detailed examples

01

Baseline the exact device, servicing state, and dependencies

Record edition, build, architecture, disk capacity, uptime, and workload role before deciding applicability. Get-HotFix reads Win32_QuickFixEngineering and omits some MSI and Windows Update records, so corroborate it with DISM packages, Windows Update history, and the organization's compliance service. DISM against /Online and many service operations require an elevated console; discovery should precede any service restart or package action.

Capture a read-only servicing baseline
Get-ComputerInfo | Select-Object WindowsProductName, WindowsVersion, OsBuildNumber, OsArchitecture, OsLastBootUpTime
Get-Volume -DriveLetter C | Select-Object DriveLetter, Size, SizeRemaining
Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 20
Get-Service wuauserv, bits, cryptsvc | Select-Object Name, Status, StartType
dism.exe /Online /Get-Packages /Format:Table
Back to quick reference ↑
02

Identify the authority and rollout ring before acting locally

A device can receive policy through MDM, Group Policy, Configuration Manager, or WSUS. Registry output is evidence, not a complete effective-policy model, and deleting policy keys is not a supported way to escape management. Confirm the approved update source, deadlines, active hours, safeguards, pause state, and ring membership centrally. WSUS remains supported but is deprecated and receives no new features; plan management architecture accordingly.

Collect classic policy evidence without modifying it
$policyPath = 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate'
Get-ItemProperty -LiteralPath $policyPath -ErrorAction SilentlyContinue | Format-List
Get-ItemProperty -LiteralPath "$policyPath\AU" -ErrorAction SilentlyContinue | Format-List
# Correlate this evidence with the device's MDM/Intune, Configuration Manager, or WSUS record.
Back to quick reference ↑
03

Scan the configured service without turning discovery into installation

The Windows Update Agent API searches the source already selected by device policy. A search can use network, CPU, and service capacity, but it does not download or install results. Preserve update identity and revision, not title alone, and evaluate supersedence, prerequisites, EULAs, and deployment approval. Microsoft's full search/download/install sample is illustrative rather than supported production automation, so production code needs explicit selection, logging, timeout, error, and restart handling.

Run and summarize a scan-only WUA session
$session = New-Object -ComObject Microsoft.Update.Session
$session.ClientApplicationID = 'CmdMemo.ScanOnly'
$searcher = $session.CreateUpdateSearcher()
$result = $searcher.Search("IsInstalled=0 and IsHidden=0")
$result.Updates | ForEach-Object {
  [pscustomobject]@{ Title = $_.Title; UpdateId = $_.Identity.UpdateID; Revision = $_.Identity.RevisionNumber; Downloaded = $_.IsDownloaded; Reboot = $_.RebootRequired }
}
Back to quick reference ↑
04

Stage one approved package with an explicit maintenance boundary

Manual package servicing is an elevated, state-changing operation that can interrupt applications, consume significant disk space, and leave a reboot pending. Confirm the package comes from an approved Microsoft or enterprise channel, validate its signature and hash, read its KB prerequisites and known issues, back up recoverable data, drain clustered or replicated workloads, and test the same build and architecture first. Online MSU servicing with DISM requires Windows 11 version 21H2 or later; older targets and checkpoint cumulative updates have different sequencing requirements. Never use /IgnoreCheck to bypass applicability casually.

Review, then deliberately service one approved package
$package = 'C:\Staging\KB0000000.msu'
Get-Item -LiteralPath $package | Select-Object FullName, Length, LastWriteTimeUtc
Get-AuthenticodeSignature -LiteralPath $package | Format-List Status, StatusMessage, SignerCertificate
Get-FileHash -LiteralPath $package -Algorithm SHA256
# In an elevated maintenance window, after validating the KB and recovery plan:
# dism.exe /Online /Add-Package /PackagePath:$package /PreventPending /NoRestart
# $dismExit = $LASTEXITCODE; if ($dismExit -ne 0) { throw "DISM failed: $dismExit" }
Back to quick reference ↑
05

Treat restart as a separate production change

An update can report success while still requiring restart-time servicing. Coordinate users, transactions, failover, encryption recovery material, and monitoring before rebooting; do not infer safety from /NoRestart. A scheduled restart is disruptive and requires elevation on protected systems. After boot, verify build, package state, application health, event logs, and compliance instead of assuming the restart completed the update correctly.

Schedule, cancel if needed, and verify after restart
# After change approval, workload drain, and user notification:
# shutdown.exe /r /t 900 /d p:2:17 /c "Approved Windows Update maintenance"
# Abort during the timeout if validation fails:
# shutdown.exe /a
# After the machine returns:
Get-ComputerInfo | Select-Object OsBuildNumber, OsLastBootUpTime
Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 10
Get-Service wuauserv, bits | Select-Object Name, Status
Back to quick reference ↑
06

Correlate history, events, traces, and servicing logs

WUA history, Windows Update Client events, ETL-derived WindowsUpdate.log, DISM.log, and CBS.log describe different layers. ResultCode and HRESULT values need decoding and may represent search, download, or installation separately. Get-WindowsUpdateLog converts ETL data to a readable snapshot; it is not the live log. Capture UTC timestamps, update identity, activity IDs, policy source, and servicing exit code before retrying.

Build a layered diagnostic bundle
$searcher = (New-Object -ComObject Microsoft.Update.Session).CreateUpdateSearcher()
$searcher.QueryHistory(0, 30) | Select-Object Date, Title, Operation, ResultCode, HResult
Get-WinEvent -LogName 'Microsoft-Windows-WindowsUpdateClient/Operational' -MaxEvents 50 |
  Select-Object TimeCreated, Id, LevelDisplayName, Message
Get-WindowsUpdateLog -LogPath (Join-Path $PWD 'WindowsUpdate.log')
Get-Item 'C:\Windows\Logs\DISM\dism.log', 'C:\Windows\Logs\CBS\CBS.log' -ErrorAction SilentlyContinue
Back to quick reference ↑
07

Diagnose the failing layer before repair or rollback

First distinguish policy/source failure, scan metadata, download, signature, applicability, component servicing, disk space, or restart completion. /ScanHealth is diagnostic; /RestoreHealth changes the component store and may contact a repair source. Do not delete SoftwareDistribution, reset services, remove packages, or edit pending-operation registry values as a generic first response. Those actions can discard evidence or damage servicing state. Preserve logs and use a tested backup, documented uninstall path, recovery environment, or Microsoft support when the device cannot boot or the servicing stack is inconsistent.

Perform non-destructive first-line triage
Get-Volume -DriveLetter C | Select-Object Size, SizeRemaining
Get-Service wuauserv, bits, cryptsvc | Select-Object Name, Status, StartType
dism.exe /Online /Cleanup-Image /ScanHealth
Get-WinEvent -LogName 'Microsoft-Windows-WindowsUpdateClient/Operational' -MaxEvents 30 |
  Where-Object LevelDisplayName -in 'Error', 'Warning' | Select-Object TimeCreated, Id, Message
# Preserve CBS.log, DISM.log, the ETL-derived update log, and the exact HRESULT before repair.
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. MicrosoftSearching, Downloading, and Installing Updateslearn.microsoft.com
  2. MicrosoftGet-WindowsUpdateLoglearn.microsoft.com
  3. MicrosoftGet-HotFixlearn.microsoft.com
  4. MicrosoftDISM Operating System Package Servicing Command-Line Optionslearn.microsoft.com
  5. MicrosoftWindows Server Update Services overviewlearn.microsoft.com

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback