Windows MDM update management

Viewed 83

I'm trying to figure out Windows update management via MDM (https://docs.microsoft.com/en-us/windows/client-management/mdm/device-update-management) and I would like to show installed and installable updates details for clients.

So following this guide, I'm getting installed/installable/... update GUIDs from the client using Update-CSP, then try to query GUID from sws.update.microsoft.com to get the metadata. The problem is, the client is reporting update GUIDs that cannot be found in sws.update.microsoft.com. For example the device returns an update id: "1f36097b-e8c9-41a3-bcc3-baae597f692d" as an installed update.

When I query this Using GetUpdateData, it doesn't exists. I queried installed updated on the client and found the detail:

PS C:\Windows\system32> $session.CreateUpdateSearcher().Search("UpdateID='1f36097b-e8c9-41a3-bcc3-baae597f692d'").Updates


Title                           : 2021-09 Cumulative Update for Windows 10 Version 20H2 for x64-based Systems (KB5005565)
AutoSelectOnWebSites            : True
BundledUpdates                  : System.__ComObject
CanRequireSource                : False
Categories                      : System.__ComObject
Deadline                        :
DeltaCompressedContentAvailable : True
DeltaCompressedContentPreferred : True
Description                     : Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer.
EulaAccepted                    : True
EulaText                        :
HandlerID                       : http://schemas.microsoft.com/msus/2016/01/UpdateHandlers/OSInstaller
Identity                        : System.__ComObject
Image                           :
InstallationBehavior            : System.__ComObject
IsBeta                          : False
IsDownloaded                    : True
IsHidden                        : False
IsInstalled                     : True
IsMandatory                     : False
IsUninstallable                 : False
Languages                       : System.__ComObject
LastDeploymentChangeTime        : 9/14/2021 12:00:00 AM
MaxDownloadSize                 : 110963910278
MinDownloadSize                 : 0
MoreInfoUrls                    : System.__ComObject
MsrcSeverity                    :
RecommendedCpuSpeed             : 0
RecommendedHardDiskSpace        : 0
RecommendedMemory               : 0
ReleaseNotes                    :
SecurityBulletinIDs             : System.__ComObject
SupersededUpdateIDs             : System.__ComObject
SupportUrl                      : https://support.microsoft.com/help/5005565
Type                            : 1
UninstallationNotes             :
UninstallationBehavior          :
UninstallationSteps             : System.__ComObject
KBArticleIDs                    : System.__ComObject
DeploymentAction                : 1
DownloadPriority                : 2
DownloadContents                : System.__ComObject
RebootRequired                  : False
IsPresent                       : True
CveIDs                          : System.__ComObject
BrowseOnly                      : False
PerUser                         : False
AutoSelection                   : 1
AutoDownload                    : 2

But when I look up this update by its name or KB article, I find the correct update id is: 9a11c8f1-525f-4088-8fb7-33d7b56dd6dc catalog page

I'm not sure why client reports an incorrect (or deprecated?) update id. Is there a way to make client to correct it?

0 Answers
Related