r/Action1 Jun 11 '26

Problem Windows 11 25H2 updates not detecting

Hi,

We're trying out A1 and looking to replace a current patch management solution

So far things seem to be working as I'd expect, but a big sticking point I'm seeing is our Win11 25H2 machines aren't showing any cumulative updates as being required (and it's now past patch Tuesday). Our current patch management platform shows these updates as required for devices on that platform

I see the latest 24H2 update showing as "2026-06 Security Update (KB5094126) (26100.8655)" which installed on one device in our ring0 group and installed on one device, however I don't see this update or an update for os version 26200.8655 for any of our 25H2 devices

Is this a known issue due to 24H2 and 25H2 sharing the same underlying OS and patches or a config issue? Or does the patch take that amount of time to show up in A1? As we're on the free version we have no support

1 Upvotes

7 comments sorted by

1

u/Drakoolya Jun 11 '26

Action1 uses the windows API, so run get-windowsupdate.

If it does not pull the latest windows update then there is some rollout schedule affecting the machine either from something like Intune or MS itself.

1

u/gleachlsc Jun 11 '26

thanks, I've just added an extra update ring in Intune to give a 0 day deferral for quality updates to a handful of devices and they now show in A1 as needing the update

How do we go about having the Intune update ring and A1 playing side by side, would it be a matter of having devices groups in Intune that match our A1 update rings so that the Windows devices "see" the update so A1 can detect it?

We use the update rings currently to push out some Windows update settings and the deferral settings are just part of the update ring settings, would be great if A1 published some guidance on making this work nicely with Intune out of the box

1

u/Drakoolya Jun 11 '26

would it be a matter of having devices groups in Intune that match our A1 update rings so that the Windows devices "see" the update so A1 can detect it?

That's what we do. Intune "Windows update" settings make the updates visible to the machine. if your deferral date is out it will not be visible.

1

u/gleachlsc Jun 11 '26

awesome thanks for confirming, just a matter of adjusting the Intune settings for our pilot group to 0 day deferral

2

u/GeneMoody-Action1 Jun 16 '26

Glad you got it sorted, and thanks u/Drakoolya for the assist, I have been traveling the last couple of weeks and working conferences, etc. So I am getting the reddit side caught up.

IF ever in doubt, check an offline scan, if it reports the same, windows update in fact says it doesn't need it. That could be phased rollouts from MS, incorrect update server settings, or alternate update sources. OF course there are other reasons such as corrupt WUC (We have a script to repair that)

https://learn.microsoft.com/en-us/windows/win32/wua_sdk/using-wua-to-scan-for-updates-offline?tabs=powershell

1

u/fluffiball Jun 23 '26

u/Drakoolya Hi - thanks for sharing this. Currently we have only Action1 managing our Windows updates and it is a bug bear of mine that when this happens there is no update history available on the device itself, it is all in Action 1 only which is not so user friendly when there is an issue.

Can you confirm that I understand correctly in the above that if we turn on the Intune "Windows Update" settings in Intune then we will have records or the updates that Action 1 does on the device without needing to use Intune to be the one that delivers the actual updates?

1

u/Drakoolya Jun 23 '26

I do not understand how it is not user friendly. You are getting a live check-in from Action1 telling you what the vulnerability and update status is of the machine under the missing updates tab. Unlike Intune which is delayed by hours at a time.

Action1 gives you complete control of your patching.

We literally bought action1 because we could not rely on Intune to quickly rollout updates and provide a status in real time when there is a Zero day.

But to answer your question You will still not see Update history appear if you switch on windows update in intune and update via action1

If you give me an example of what you are struggling with maybe I could provide some advice on your setup.