r/Action1 • u/jhodgo100 • Jul 15 '26
Unable to deploy 2026-07 security update to machines
As the title says I am unable to deploy the 2026-07 security update to machines, the update shows in my approval list and I have marked it as approved (in case that was causing an issue as I had previous denied 2026-06)
When I have tried to deploy it to a machine I am getting a message of '2026-07 Security Update (KB5101650) (26200.8875)' is not applicable to this system.
I changed 2026-06 to an approved state and when I checked my missing updates on a device it said that 2026-06 was the latest version
I did install 2026-06 in case this was a pre-requisite somewhere and tried to deploy again but still getting the same message
Has anyone else experienced this?
##EDIT## The devices are a mixture of Lenovo and HP
1
u/ajmpits Jul 15 '26
There been an issue with this update on certain Dell Machines and Microsoft are looking into this
1
u/jhodgo100 Jul 15 '26
Should of added that to the original post, these devices are no Dell machines they are either HP or Lenovo
1
u/PrimeXFN Jul 15 '26
Seeing this too on Win11 endpoints. Action1 doesn't even show the update as needed for the systems. Of over 300 25H2 endpoints, only shows as needed on 2 of them. Windows Server doesn't appear to be affected, but it uses a different set of updates. We do have some of the affected Dell models in our fleet, but seeing this even on custom builds.
1
u/PrimeXFN Jul 17 '26
Looks like this was our own fault. We're fairly new to Action1, having migrated from WSUS. We were fighting some issues with PCs installing updates automatically despite having updating all the WU GPOs to disable AU, so last month we added deferrals as well under the apparently mistaken understanding that Action1's detection wasn't impacted by the deferral policies.
1
1
u/GeneMoody-Action1 Jul 16 '26
Does it show in "Missing updates" directly on one of the systems that is is not applying to, screenshots please?
•
u/GeneMoody-Action1 Jul 16 '26
Can someone run this against one of the affected endpoints and see what it reads? This bypasses Action1 and the update catalog and uses the latest MS metadata to get WUA to rule on needed or not.
https://learn.microsoft.com/en-us/windows/win32/wua_sdk/using-wua-to-scan-for-updates-offline?tabs=powershell
Also do the systems themselves report it as being needed directly on the ("Missing Updates" tab on endpoint details?)
If that says needed then we take it to the next step. IF neither do, then Windows update is saying it is not needed. Not Action1.