The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Record OS build | Get-ComputerInfo |
Select-Object WindowsProductName, WindowsVersion, OsBuildNumber, OsArchitecture | View examples |
| List reported hotfixes | Get-HotFix | Sort-Object InstalledOn -Descending | View examples |
| List servicing packages | dism.exe /Online /Get-Packages /Format:Table | View examples |
| Inspect update services | Get-Service wuauserv, bits, cryptsvc |
Select-Object Name, Status, StartType | View examples |
| Read Windows Update policy | Get-ItemProperty `
'HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate' `
-ErrorAction SilentlyContinue | View examples |
| Create WUA searcher | $searcher = (New-Object -ComObject `
Microsoft.Update.Session).CreateUpdateSearcher() | View examples |
| Scan for missing updates | $result = `
$searcher.Search("IsInstalled=0 and IsHidden=0") | View examples |
| Review scan results | $result.Updates |
Select-Object Title, MsrcSeverity, IsDownloaded, RebootRequired | View examples |
| Query WUA history | $searcher.QueryHistory(0, 30) |
Select-Object Date, Title, Operation, ResultCode, HResult | View examples |
| Read operational events | Get-WinEvent -LogName `
'Microsoft-Windows-WindowsUpdateClient/Operational' `
-MaxEvents 50 | View examples |
| Build readable update log | Get-WindowsUpdateLog -LogPath (Join-Path $PWD `
'WindowsUpdate.log') | View examples |
| Scan component-store health | dism.exe /Online /Cleanup-Image /ScanHealth | View examples |
| Hash a staged package | Get-FileHash -LiteralPath 'C:\Staging\KB0000000.msu' `
-Algorithm SHA256 | View examples |
| Install a staged MSU | dism.exe /Online /Add-Package `
/PackagePath:"C:\Staging\KB0000000.msu" `
/PreventPending /NoRestart | View examples |
| Schedule controlled restart | shutdown.exe /r /t 900 /d p:2:17 /c `
"Approved Windows Update maintenance" | View examples |
| Cancel scheduled restart | shutdown.exe /a | View examples |
Reliable patching is a change-management workflow, not a single install command. Establish the exact Windows build and policy source, scan without changing the machine, stage updates through the approved service, test a representative ring, preserve logs and rollback options, and schedule any required restart. Local commands do not override organizational Windows Update for Business, Intune, Configuration Manager, or WSUS policy.
Step by step
Detailed examples
Baseline the exact device, servicing state, and dependencies
Record edition, build, architecture, disk capacity, uptime, and workload role before deciding applicability. Get-HotFix reads Win32_QuickFixEngineering and omits some MSI and Windows Update records, so corroborate it with DISM packages, Windows Update history, and the organization's compliance service. DISM against /Online and many service operations require an elevated console; discovery should precede any service restart or package action.
Get-ComputerInfo | Select-Object WindowsProductName, WindowsVersion, OsBuildNumber, OsArchitecture, OsLastBootUpTime
Get-Volume -DriveLetter C | Select-Object DriveLetter, Size, SizeRemaining
Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 20
Get-Service wuauserv, bits, cryptsvc | Select-Object Name, Status, StartType
dism.exe /Online /Get-Packages /Format:Table Identify the authority and rollout ring before acting locally
A device can receive policy through MDM, Group Policy, Configuration Manager, or WSUS. Registry output is evidence, not a complete effective-policy model, and deleting policy keys is not a supported way to escape management. Confirm the approved update source, deadlines, active hours, safeguards, pause state, and ring membership centrally. WSUS remains supported but is deprecated and receives no new features; plan management architecture accordingly.
$policyPath = 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate'
Get-ItemProperty -LiteralPath $policyPath -ErrorAction SilentlyContinue | Format-List
Get-ItemProperty -LiteralPath "$policyPath\AU" -ErrorAction SilentlyContinue | Format-List
# Correlate this evidence with the device's MDM/Intune, Configuration Manager, or WSUS record. Scan the configured service without turning discovery into installation
The Windows Update Agent API searches the source already selected by device policy. A search can use network, CPU, and service capacity, but it does not download or install results. Preserve update identity and revision, not title alone, and evaluate supersedence, prerequisites, EULAs, and deployment approval. Microsoft's full search/download/install sample is illustrative rather than supported production automation, so production code needs explicit selection, logging, timeout, error, and restart handling.
$session = New-Object -ComObject Microsoft.Update.Session
$session.ClientApplicationID = 'CmdMemo.ScanOnly'
$searcher = $session.CreateUpdateSearcher()
$result = $searcher.Search("IsInstalled=0 and IsHidden=0")
$result.Updates | ForEach-Object {
[pscustomobject]@{ Title = $_.Title; UpdateId = $_.Identity.UpdateID; Revision = $_.Identity.RevisionNumber; Downloaded = $_.IsDownloaded; Reboot = $_.RebootRequired }
} Stage one approved package with an explicit maintenance boundary
Manual package servicing is an elevated, state-changing operation that can interrupt applications, consume significant disk space, and leave a reboot pending. Confirm the package comes from an approved Microsoft or enterprise channel, validate its signature and hash, read its KB prerequisites and known issues, back up recoverable data, drain clustered or replicated workloads, and test the same build and architecture first. Online MSU servicing with DISM requires Windows 11 version 21H2 or later; older targets and checkpoint cumulative updates have different sequencing requirements. Never use /IgnoreCheck to bypass applicability casually.
$package = 'C:\Staging\KB0000000.msu'
Get-Item -LiteralPath $package | Select-Object FullName, Length, LastWriteTimeUtc
Get-AuthenticodeSignature -LiteralPath $package | Format-List Status, StatusMessage, SignerCertificate
Get-FileHash -LiteralPath $package -Algorithm SHA256
# In an elevated maintenance window, after validating the KB and recovery plan:
# dism.exe /Online /Add-Package /PackagePath:$package /PreventPending /NoRestart
# $dismExit = $LASTEXITCODE; if ($dismExit -ne 0) { throw "DISM failed: $dismExit" } Treat restart as a separate production change
An update can report success while still requiring restart-time servicing. Coordinate users, transactions, failover, encryption recovery material, and monitoring before rebooting; do not infer safety from /NoRestart. A scheduled restart is disruptive and requires elevation on protected systems. After boot, verify build, package state, application health, event logs, and compliance instead of assuming the restart completed the update correctly.
# After change approval, workload drain, and user notification:
# shutdown.exe /r /t 900 /d p:2:17 /c "Approved Windows Update maintenance"
# Abort during the timeout if validation fails:
# shutdown.exe /a
# After the machine returns:
Get-ComputerInfo | Select-Object OsBuildNumber, OsLastBootUpTime
Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 10
Get-Service wuauserv, bits | Select-Object Name, Status Correlate history, events, traces, and servicing logs
WUA history, Windows Update Client events, ETL-derived WindowsUpdate.log, DISM.log, and CBS.log describe different layers. ResultCode and HRESULT values need decoding and may represent search, download, or installation separately. Get-WindowsUpdateLog converts ETL data to a readable snapshot; it is not the live log. Capture UTC timestamps, update identity, activity IDs, policy source, and servicing exit code before retrying.
$searcher = (New-Object -ComObject Microsoft.Update.Session).CreateUpdateSearcher()
$searcher.QueryHistory(0, 30) | Select-Object Date, Title, Operation, ResultCode, HResult
Get-WinEvent -LogName 'Microsoft-Windows-WindowsUpdateClient/Operational' -MaxEvents 50 |
Select-Object TimeCreated, Id, LevelDisplayName, Message
Get-WindowsUpdateLog -LogPath (Join-Path $PWD 'WindowsUpdate.log')
Get-Item 'C:\Windows\Logs\DISM\dism.log', 'C:\Windows\Logs\CBS\CBS.log' -ErrorAction SilentlyContinue Diagnose the failing layer before repair or rollback
First distinguish policy/source failure, scan metadata, download, signature, applicability, component servicing, disk space, or restart completion. /ScanHealth is diagnostic; /RestoreHealth changes the component store and may contact a repair source. Do not delete SoftwareDistribution, reset services, remove packages, or edit pending-operation registry values as a generic first response. Those actions can discard evidence or damage servicing state. Preserve logs and use a tested backup, documented uninstall path, recovery environment, or Microsoft support when the device cannot boot or the servicing stack is inconsistent.
Get-Volume -DriveLetter C | Select-Object Size, SizeRemaining
Get-Service wuauserv, bits, cryptsvc | Select-Object Name, Status, StartType
dism.exe /Online /Cleanup-Image /ScanHealth
Get-WinEvent -LogName 'Microsoft-Windows-WindowsUpdateClient/Operational' -MaxEvents 30 |
Where-Object LevelDisplayName -in 'Error', 'Warning' | Select-Object TimeCreated, Id, Message
# Preserve CBS.log, DISM.log, the ETL-derived update log, and the exact HRESULT before repair. Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
- MicrosoftSearching, Downloading, and Installing Updateslearn.microsoft.com
- MicrosoftGet-WindowsUpdateLoglearn.microsoft.com
- MicrosoftGet-HotFixlearn.microsoft.com
- MicrosoftDISM Operating System Package Servicing Command-Line Optionslearn.microsoft.com
- MicrosoftWindows Server Update Services overviewlearn.microsoft.com
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



