Software Updates Required vs Installed

Bill Fry 1 Reputation point
2020-10-21T16:05:42.063+00:00

Not sure if I am in the right place but this question is about Configuration Manager.

When software updates become available, in CM, it shows that only 1 device is required but non being installed. We have 90+ computers that this update should be installed on.
'
Seems like Windows Update is installing it vs CM. I see this with Office 365 updates and others.

Is there a way to fix this so that CM does the updates and not Windows?

Microsoft Configuration Manager Updates
Microsoft Configuration Manager Updates
Microsoft Configuration Manager: An integrated solution for for managing large groups of personal computers and servers.Updates: Broadly released fixes addressing specific issue(s) or related bug(s). Updates may also include new or modified features (i.e. changing default behavior).
1,005 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. AllenLiu-MSFT 42,356 Reputation points Microsoft Vendor
    2020-10-22T02:43:22.267+00:00

    @Bill Fry
    Thank you for posting in Microsoft Q&A forum and you are in the right place.
    You may check if you have configured any group policy of WUfB? The WUfB setting will enable our clients to also reach out to Microsoft Update online to fetch update bypassing our WSUS/SCCM end-point. And check if your "Do not allow update deferral policies to cause scans against Windows Update" policy have enabled.
    34086-54.jpg
    34126-55.jpg
    For more details, you may refer to below link:
    https://techcommunity.microsoft.com/t5/configuration-manager-archive/using-configmgr-with-windows-10-wufb-deferral-policies/ba-p/274278


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. Jason Sandys 31,186 Reputation points Microsoft Employee
    2020-10-22T22:20:58.26+00:00

    The ConfigMgr site isn't instantly aware of the update compliance of managed systems. This is reported in every 7 days (by default) for updates that are not deployed. This in no way prevents you from deploying the required updates though. In general, if an update is applicable to an in-scope product in your environment, you should deploy it per our update policy and not wait for update compliance scanning results as that would make your process reactive instead of proactive and security should be a proactive activity.

    0 comments No comments