Updates and declined Updates

Last modified by Sabrina V. on 2025/09/29 09:06

The Updates section displays all available updates that match your previously set settings (selected products, classifications and languages). This requires that the metadata download has been completed successfully (see Download Types in Windows Update Management). The updates are listed according to the sorting of the grid. If individual updates are to be excluded from the distribution process (e.g. because they are no longer relevant to you), they can be explicitly rejected (Declined Updates).

Working with updates

The available updates are listed in a grid. As a rule, only updates that are current or may expire are displayed here (see expiry status).

Tip: Read the chapter Structure of a grid in ACMP to find out what individueal editing options (filtering, sorting or grouping results) are available to you. The chapter Grid optimisations in Windows Update Management contains further tips on how to group columns.

The ribbon bar can be used to assign 1747373593711-339.pngsync profiles and 1747373608196-936.png  accept EULAs if this is a prerequistite for update distribution. If an update is already in a distribution ring (1747373614472-578.png), this can be changed and adjusted manually. In addition, you can navigate directly from the updates to the 1747373620038-623.png settings and make changes (e.g. deselect or select products or classifications). The 1747373625736-313.png MS Catalog takes you to the official Microsoft Update catalogue, where you can search for individual updates and select them for import.

Tip: The Microsoft Update Catalog is particularly useful for updates that are only available through the catalog.

To give you a better understanding of the updates in Windows Update Management, the individual areas are broken down below and explained in more detail. These are as follows:

  • 1. Process status and update type
  • 2. Properties of the updates
  • 3. Detailed view of a selected update
67_CAWUM_Updates bearbeitete Übersicht_1676.png

Structuring the areas of the updates

1. Expiry status and update type

As soon as metadata is updated, new updates may be added, existing ones replaced, or updates already published by Microsoft withdrawn and thus disappear from the list. These dynamic updates are collected using the expiry status and listed under Updates. The release cycle also affects the status (e.g. an update may still have the status "May expire" at the beginning of the release process and have expired at the end of the process).

67_CAWUM_Ablaufstatus_777.png

Expiry status and update type

The expiry status indicates what type of updates are displayed to you, regardless of the classification selected. This only refers to the relationship between the updates themselves or whether they have been withdrawn from distribution by Microsoft.

For a better overview, only Current and May expire are selected by default when ACMP is installed.

Expiry statusDescription
Up-to-date

Lists all current updates that have been released by Microsoft for the product and classification. There is currently no update that replaces this.

Can expire

Updates that may expire are listed in this status. There is at least one update that is newer. However, this update is not further along in the Release process than the one currently selected. In the Replacement tab, there should be at least one update on the right-hand side under Replaced by the following updates.

Is expired

Expired updates are updates for which a newer version is available. A newer version has already been released for the update AND the newer update is in the same or higher Release Ring as the selected one.

Example: Microsoft releases new feature updates twice a year. These differ in the version number (Version 23H2, 24H2, etc.), which indicates how current the version is. If an update has expired, it is listed in the Replacement tab. The current Windows versions can be viewed on the official Microsoft website (Windows 10 and Windows 11).

RevokedUpdates may be withdrawn if they cause increased problems. In this case, Microsoft will withdraw the updates until a solution has been found and a replacement update is available. Withdrawn updates will then no longer be distributed or installed in this way. It is also not recommended that withdrawn updates be downloaded manually from the MS catalog and added to the network.

In addition to the status, you can also filter by update type. To do this, tick the checkboxes if you want to display updates for software and/or drivers. Drivers are only automatically selected if you have ticked them in the First Steps Wizard or subsequently in the settings under the classifications

If you want to add or deselect another status or type, tick the checkbox and then refresh the view. Your changes will be taken into account in the system and displayed accordingly.

2. Properties of the updates

The grid contains a wealth of relevant information that you need to know about an update. The table shows whether an update is critical, its Knowledge ID, which product it belongs to, and when it was released.

Tip: Read more here about how you can optimise the grid for your work in Windows Update Management.

PropertyDescription

Expiration State

 

The process status indicates which type of updates are displayed in the grid. If, for example, you have only selected the current updates in the process status, this filter will also be applied here. If you would like to see additional "withdrawn" updates, you must select the status above and click Update in the ribbon bar to refresh the grid.

TitleThe designation reflects the official name of the update.
Clients Required

If a client reports an update as required, this is displayed in this column: Any value greater than zero (0) means that at least one client has reported the update to the ACMP Console as required.

Tip: How does a client report an update to ACMP as required?

When a client reports an update as required in ACMP, this is done in the background either via the Windows Update Scanner, an Update Collection, or Windows sends a status report on its own initiative stating that the update is required. In one of these situations, the client updates the status of the update. The condition for this is that the agent is managed by WUM.

The client scans the status of its updates. Two lists of updates are then created: updates that are already installed and updates that still need to be installed. Both lists are stored in the database, which then determines the number of updates reported as required by the client. If, for example, several clients have the security update ‘2025-01 Cumulative Update for Windows 11 version 22H2 for arm64-based systems (KB5050021)’ in their table, the grid column Clients required would show exactly the number of clients that have reported it as required.

Hinweis  Note:  

The setting On Demand - Only download if at least one client required the update you can specify that only those updates that have been reported as required by clients should be downloaded. This saves storage space, as not every update is downloaded in full.

Tip: Once the Windows Update Scanner has successfully completed its scan, you can set the filter in the Clients Needed column to (> 0) so that only the updates that are needed are displayed. This allows you to significantly reduce the quantity of results.

Clients FailedIf the installation or uninstallation of an update fails on a client, this is displayed in the column of the same name. The value zero (0) means that it did not fail on any client, while the value 1 indicates that it could not be installed/uninstalled correctly on at least one client. The column shows whether the last action failed.
Clients InstalledThe column shows the total number of updates that have installed this update.
EULA status

The EULA status indicates whether the licence agreements for the update have already been accepted or not. Possible values that may appear in the row:

  • Accepted: The EULA has already been accepted for the update.
  • Not yet accepted: The EULA has not yet been accepted for the selected update.
  • Not required: No EULA needs to be accepted for this update, which is why the status is Not required.
KB-IDThe KB ID consists of the knowledge base and the article number.
ClassificationThe classification indicates the update type (e.g. critical updates, update rollups or upgrades).
Last Change of Distribution Ring

Displays the date and time of the last change to the distribution ring. This also includes transitions between individual distribution rings, provided that an update was made, e.g. from Test Ring 2 to Released.

ProductsProducts are the selected operating systems, software, or drivers for which you wish to obtain and distribute updates.
Severity

The severity level indicates how Microsoft categorises its updates. A distinction is made between Niedrig Icon CAWUM.png Low, 1747373720350-481.pngImportant, 1747373720350-147.png Critical, 1747373720351-361.png Moderate and 1747373720351-444.png No security level defined.Example: Microsoft's security updates are often classified as Important or Critical. Example: Microsoft's security updates are often classified as Important or Critical.

Transition mode

The transition mode indicates whether an update switches automatically or manually from one distribution ring to another.
You can disable automatic transitions (1747373735179-436.png) via the ribbon bar. To reactivate them, use the function Enable automatic transition mode (1747373739790-869.png).

Warning  Warning:  

If you disable automatic transition mode for the selected update, the automatic move setting specified in the settings for it will be overridden.

Origin

The origin indicates the source from which the update originates. Updates originating from the metadata download are indicated with Windows Update. Updates obtained from the MS catalogue are marked with Manual import.

Release DateThe publish date indicates the date on which it was published by Microsoft.
Distribution Process

The distribution process reflects the testing and approval process for Windows updates. Any Windows update that has not been explicitly assigned to a user-defined test and release process is always assigned to the default process. Otherwise, the processes you have created are listed here.

Distribution Ring

The distribution ring indicates the transition phase the update is currently in and how far the automatic distribution has progressed. There are four rings that an update can typically pass through: No distribution ring, Test Ring 1, Test Ring 2 and Released.

Tip: In the chapter Testing and Release  you can learn more about how to define the individual processes and customize them for your specific needs.

Distribution State

This refers to the status of the downloaded files in the file repositories. A distinction is made between Synchronised, Synchronisation and Not downloaded.

  • Synchronised: If the files have already been deployed to the relevant file repositories, the distribution status is Synchronised, as the files or updates are available. The updates have been successfully downloaded.
  • Synchronisation: The current synchronisation with the file repository is still in progress.
  • Not downloaded: The updates have not yet been downloaded and currently only exist as metadata.

Properties that you will exclude from finding under the declined updates tab:

PropertyDescription
Declination DateReturns the date on which an update was denied.
Declination CommentDisplays the reason or comment given when an update was refused.

Hinweis  Note:  

Please note that you may not see all columns in the grid if you have hidden them. To display all columns, click on the asterisk star in the top left-hand corner of the grid and tick the desired entries or deselect them as required.

3. Detailed view of a selected Update

The detailed view of a selected update provides you with a wealth of info, some of which supplements the existing info from the grid. Depending on the number of items, it is always worth opening the detailed view to avoid the risk of slipping in the row or column and reading out incorrect info, for example. The view opens below the grid as soon as you select an update.

Hinweis  Note:  

The detailed view is not available for multiple selections.

67_CAWUM_Detailansicht eines ausgewählten Updates_1674.png

Example of a detailed view of a selected update

The information is divided into six tabs:

TabDescription
GeneralThis tab provides general details and information about the selected update. In addition to the official name and description from Microsoft and the publish date, you will also find the severity, KB ID and further information about the update.
Installation/Uninstallation

If you want to install or uninstall the update, you will find more detailed information on the respective behaviour here:

  • Restart behavior: How does the update behave during installation or uninstallation? Does the computer need to be restarted?
  • May require user input: Is it necessary for the user to enter information during installation/uninstallation in order for the update to be finished successfully?
  • Installation impact: How must the update be installed? For example, should the update be installed on its own, even if several updates should execute?
  • Requires network connection: Is a network connection required for the update installation/uninstallation to be successfully executed?
Affected Clients

This tab lists all agents that are affected by the update in any way:

  • Installed
  • Failed
  • Required

From this tab, you can perform a pushed installation. To do this, select a client and then click on ​ Install Updates and provide your confirmation in the window that opens. In addition, you can uninstall updates or 

Test runsEs werden alle Ausführungen von Update Collections, Installationen und Deinstallationen gelistet, die im Testring1 oder Testring2 durchgeführt wurden.
EULA

Hinweis  Note:  

Dieser Tab ist nur sichtbar, sofern für das Update einer EULA (End User License Agreement) zugestimmt werden muss.

Hier finden Sie die Informationen zum EULA-Status, sowie wann und wer die EULA akzeptiert hat. Über den Button EULA anzeigen wird ein neues Fenster geöffnet, in dem Sie die Lizenzbedingungen für das jeweilige Update nachlesen können.

ReplacementDer Tab gibt an, ob das ausgewählte Update ein anderes Update ersetzt oder durch ein anderes Update bereits ersetzt wurde. Die zu ersetzenden oder ersetzten Updates werden untereinander, namentlich gelistet.

EULA akzeptieren

Eine EULA (End User License Agreement) ist eine rechtliche Vereinbarung, die einem Benutzer eine Lizenz zur Verwendung einer Software gewährt. Erst – sollte es sich um eine Software handeln, die so etwas voraussetzt – wenn der Lizenzvertrag akzeptiert wurde, kann der Benutzer die Anwendung nutzen (z.B. herunterladen oder installieren).

Bei manchen Updates (häufig bei der Klassifizierung Upgrades) ist es notwendig, dass Sie für die Verteilung und die weitere Installation einer EULA (End User License Agreement) zustimmen müssen. Für diese Updates haben Sie die Möglichkeit in der Ribbonleiste über den Button 1747373817030-691.png EULA akzeptieren, die Lizenzbedingungen anzunehmen. Hierfür öffnet sich ein zweigeteiltes Fenster: Im oberen Teil sehen Sie die Knowledgebase-ID und den Titel des Updates und unten die Lizenzvereinbarungen für das Update. Lesen Sie sich den Text sorgfältig durch und haken Sie die Checkbox an und klicken Sie anschließend auf Akzeptieren, um den Bedingungen zuzustimmen.

67_CAWUM_EULA akzeptieren_785.png

Beispiel einer akzeptierten EULA für ein Upgrade

Mit der Zustimmung der EULA ändert sich auch der EULA-Status im Grid auf Akzeptiert für das ausgewählte Upgrade.

Hinweis  Note:  

Sollten Sie die EULA für ein Update explizit nicht akzeptiert haben, wird dieses Update auch nicht heruntergeladen. Eine anschließende Verteilung und Installation ist nicht möglich. 

Warning  Warning:  

Innerhalb der Einstellungen (System > Einstellungen > Windows Update Management > Optionen) finden Sie eine Konfigurationsmöglichkeit, mit der Sie automatisch die EULAs ungelesen akzeptieren können.
Beachten Sie dabei, dass dieser Automatismus dem in Ihrem Land geltenden Recht widersprechen kann.

Updates verweigern

Wenn ein angezeigtes Update nicht mehr in Ihrem Netzwerk verteilt werden soll (weil es zum Beispiel veraltet ist o.ä.), können Sie dieses Update verweigern. Ein verweigertes Update wird nicht mehr auf den Clients verteilt oder installiert und aus allen bestehenden Updatesammlungen (Windows Update Collections) entfernt.

Um ein Update zu verweigern, markieren Sie zunächst das entsprechende Update im Grid und klicken Sie anschließend in der Ribbonleiste auf 1747373870721-499.png Verweigern oder wählen Sie die Aktion über das Kontextmenü (Rechtsklick) aus. Es öffnet sich ein neues Fenster, in dem Sie einen optionalen Verweigerungsgrund nennen können.

67_CAWUM_Updates verweigern_475.png

Kommentarfenster zur Verweigerung eines Updates

Hinweis  Note:  

Beachten Sie, dass abhängig von Ihrem Ablaufdatumsfilter auch ältere ersetzte Updates erscheinen können, nachdem die ausgewählten Updates abgelehnt wurden.

Erst mit der nächsten Bereinigung (siehe Bereinigungsjob) wird der durch das Update belegte Festplattenspeicher freigegeben. Aktualisieren Sie dafür die Ansicht im Dashboard.

Verweigerte Updates werden Ihnen anschließend im gleichnamigen Reiter Verweigerte Updates angezeigt.

Warning  Warning:  

Sollten Sie ein Update verweigern, das ein anderes Update ersetzt, wird dieses wieder in der Übersicht angezeigt.

Hinweis  Note:  

Updates können ebenfalls nach einer bestimmten Zeit automatisch verweigert werden, wenn diese für eine vordefinierte Anzahl an Tagen nicht benötigt wurden. Dieser Zeitraum beträgt standardmäßig 180 Tage. Die Einstellung lässt sich entweder im First Steps Wizard (Automatisches Bereinigen von Updates) oder auch nachträglich über die Einstellungen (System > Einstellungen > Windows Update Management > Optionen > Windows Update Bereinigung) aktivieren.

Verweigerte Updates genehmigen

Sämtliche Updates, die Sie zuvor verweigert haben, werden unter dem gleichnamigen Reiter im Windows Update Management gelistet. Ähnlich wie bei den Updates werden Ihnen die Ergebnisse auch hier in einem Grid gezeigt, einzig die Spalten und befüllten Felder unterscheiden sich minimal (zum Beispiel finden Sie hier das Verweigerungsdatum sowie den eingefügten Kommentar).

Wenn Sie eines der angezeigten Updates dennoch in Ihrem Netzwerk verteilen und installieren wollen, markieren Sie dieses und klicken Sie in der Ribbonleiste auf 1747373905472-717.png Genehmigen.

67_CAWUM_Verweigerte Updates genehmigen_1384.png

Verweigertes Update nachträglich genehmigen

Bestätigen Sie den Dialog mit Ja. Hierdurch wird Ihnen das ausgewählte Update wieder im Reiter Updates angezeigt und steht Ihnen zur Verfügung, um es im Netzwerk zu installieren.

Freigabeprozess der Updates ändern

Updates, die sich bereits in einem Freigabeprozess befinden und auch schon einen Verteilungsring (Testring 1 oder Testring 2) zugewiesen bekommen haben, können über die Ribbonleiste oder das Kontextmenü manuell den Verteilungsring wechseln. Dies kann zum Beispiel dann erforderlich sein, wenn ein wichtiges Update in einen anderen Ring verschoben werden soll, damit dieses schneller verteilt werden kann.

Wählen Sie hierzu zunächst das entsprechende Update aus dem Grid aus und klicken Sie auf Verteilungsring wechseln (1747373939888-917.png). Es öffnet sich der Verteilungsring-Editor, in dem Sie nun den neuen Verteilungsring für das Update auswählen können. Kontrollieren Sie außerdem, ob die Checkbox Elemente automatisch in den nächsten Verteilungsring schieben aktiviert ist, damit dieser Automatismus greift und das Update zu einem späteren Zeitpunkt in den darauffolgenden Ring verschoben wird. Beenden Sie Ihre Arbeiten, indem Sie auf Ändern klicken. Die Ansicht des Grids wird automatisch aktualisiert, sodass das Update in den entsprechenden Verteilungsring eingeordnet wird.

67_CAWUM_Verteilungsring wechseln_453.png

Verteilungsring-Editor im Windows Update Management

Hinweis  Note:  

Ob es einen automatischen Übergangsmodus für das jeweilige Update gibt, sehen Sie in der Grid Eigenschaft Übergangsmodus. Ist der Automatismus aktiviert, steht in der Zeile „Automatisch“. Ist der Modus deaktiviert, steht dort dann „Manuell“.
Sie können den Übergangsmodus auch noch nachträglich ändern, indem Sie in der Ribbonleiste auf Automatischen Übergangsmodus aktivieren (1747373997490-853.png) / deaktivieren (1747373997490-436.png)  klicken, je nachdem ob Sie einen Übergangsmodus wünschen oder nicht.

Warning  Warning:  

Beachten Sie, dass Sie durch die Einstellung zur Deaktivierung des automatischen Übergangsmodus den dahinter festgelegten Automatismus zum Verschieben von Updates außer Kraft setzen.

Grundsätzlich ist es auch möglich, dass Sie die Updates in einen vorherigen Verteilungsring verschieben können und der Wechsel nicht zwangsläufig näher der Freigabe sein muss. Möchten Sie beispielsweise ein Update länger in einem Testring behalten und beobachten, ob es noch Änderungen seitens von Microsoft gibt, könnten Sie es so länger in der Testumgebung behalten und es einen Testring zurückschicken, wenn Sie nicht direkt die Anzahl der konfigurierten Tage des Prozesses komplett ändern wollen.

Updates aus dem MS Katalog beziehen

Der Microsoft Update-Katalog ist ein Dienst von Microsoft, der eine Vielzahl an Updates bereitstellt, die Sie über Ihr Unternehmensnetzwerk verteilen können. Über den Katalog können Sie nach Microsoft-spezifischen Softwareupdates jeglicher Art suchen und diese bei Bedarf manuell herunterladen und in Ihr Netzwerk einpflegen.

Klicken Sie in der Ribbonleiste auf 1747374014242-333.pngMS Katalog und es öffnet sich ein neues Fenster, welches aus zwei Tabs besteht: Update-Katalog und Ausgewählte Updates.

67_CAWUM_MS Katalog_1282.png

Microsoft Update-Katalog

Geben Sie in das Suchfeld oben rechts Ihren Suchbegriff ein. Um die Ergebnismenge einzuschränken, empfiehlt Microsoft die passende Knowledgebase-ID (KB-ID) einzugeben.

67_CAWUM_MS Katalog KB Nummer_1282.png

Suche nach Updates im MS Katalog

Wenn Sie das passende Update aus den Einträgen gefunden haben, klicken Sie im rechten Bereich auf Add. Im Hintergrund wird nun das Update importiert und für Sie im Tab Ausgewählte Updates zur Verfügung gestellt. Klicken Sie auf Entfernen, sollte das Update nicht benötigt werden und Sie es aus der Liste löschen wollen.

Beim nächsten Metadaten-Download werden die ausgewählten Updates zusätzlich heruntergeladen und Ihnen in der ACMP Console zur Verfügung gestellt.

Tipp: Updates, die Sie direkt über den MS Katalog beziehen, werden Ihnen innerhalb des Grids in der Spalte Ursprung mit „Manueller Import“ angezeigt.

 

© Aagon GmbH 2026
Besuchen Sie unsere aagon-Community