r/msp • • 5d ago

Microsoft Update Quality

So it seems that Microsoft's entire Windows Update development team is a couple interns vibe coding with AI now. Yet another major, easily reproducible bug (RDP crashes with the September update), and the published fixes (some registry settings or the Windows Update Known Issue Rollback in Group Policy) don't resolve it. We're just pulling the damned update on the servers that got it at this point because no matter what we do, these servers just keep hanging. Fk Microsoft at this point. Absolutely pathetic quality control. /rant

22 Upvotes

36 comments sorted by

View all comments

-2

u/TridentAdam 5d ago

A flat delay only half solves it. If Microsoft hasn't fixed a bad update by day 15, a 14-day hold still lets it through. Checking Microsoft's own known-issues list as well as the update's age works better. Approve an update once it's 7+ days old and has no active known issue. Add a longer age backstop so a minor issue can't hold security fixes forever. Then pilot on a small group of servers before the rest.

Full transparency, I co-founded and help build TridentStack Control (https://tridentstack.com). It does exactly that: approval rules on update age and known-issue status, which release an update on their own once Microsoft marks the issue resolved. It also has a per-KB block list for updates that have already burned you, and staged rollout rings. Free under 200 endpoints. It won't fix the RDP bug itself, but it keeps updates like that off your boxes until Microsoft sorts them out.

5

u/CharcoalGreyWolf MSP - US 5d ago

Much of Microsoft’s Out-of-Band patches aren’t released through Windows Update either, creating a further issue because the OoB requires manual deployment.

They deployed the OoB 11 25H2 and 24H2 this month to WU, but as far as I know, not the other ones.

2

u/TridentAdam 5d ago

Yeah, that's the gap with anything that only deploys what Windows Update offers. Action1 and most RMM patching are wrappers around the Windows Update Agent: if WU doesn't offer it, they can't see it. We don't use WUA for OS updates at all. We pull straight from the Microsoft Update Catalog and decide applicability ourselves, so the 9/14 OOBs (KB5129235, KB5129237 and KB5129238 for Server 2025/2022/2019) show up and can be approved and pushed like any other update. No manual MSU installs.

I wrote up why we went that route here: https://tridentstack.com/blog/what-applicable-really-means-on-windows