Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →To patch Windows Server 2025 with Microsoft Configuration Manager (often still called SCCM), use its software-update workflow: confirm your Configuration Manager release supports the server, configure a software update point (SUP) backed by WSUS, make update content available to distribution points, and deploy updates to a scoped collection. Start with a pilot and expand according to your change-control policy; Microsoft does not prescribe one universal deployment schedule.
Check support before configuring updates
First establish whether you are managing Windows Server 2025 as a client or installing Configuration Manager infrastructure roles on it. These are separate support questions.
Managing Windows Server 2025 clients
Microsoft lists Windows Server 2025 client support beginning with Configuration Manager version 2409. The listed editions are IoT, Standard, Datacenter, and Datacenter: Azure Edition; Server Core is also supported from version 2409. Check the current client support matrix for the exact edition and installation option in your fleet before deployment. The matrix is at Microsoft’s supported operating systems for clients and devices documentation.
As of October 8, 2026, Microsoft’s rolling Configuration Manager servicing information lists version 2609 (5.00.9152.1000), available September 28, 2026, with support ending March 28, 2028. Confirm the live release table and your organization’s supported servicing position before planning an upgrade; these release details change over time. See Updates and servicing for Configuration Manager.
#1 Best Overall
Hosting Configuration Manager roles
If the Server 2025 machine will host a site server or another site-system role, verify that specific role in Microsoft’s site-system support matrix. Client support does not establish that every infrastructure role is supported on the same OS. The referenced matrix was last updated December 19, 2024, so check the current page before relying on it: Supported operating systems for Configuration Manager site system servers.
Record the update baseline
Windows Server 2025 is Microsoft’s current LTSC release. As of October 8, 2026, the release information page lists build 26100.33451, revision date September 14, 2026, for the September out-of-band update KB5129235; it also lists the September B update as build 26100.33438, dated September 8, 2026, KB5122871. These are dated reference points, not recommendations to deploy a particular KB. Check the live release history and the applicable KB before approving or executing a deployment. The page lists availability as November 1, 2024, mainstream support through November 13, 2029, and extended support through November 14, 2034. See Windows Server release information.
Understand the software-update dependencies
Configuration Manager’s software-update workflow relies on connected components. A healthy deployment requires more than selecting a KB in the console:
Rank #2
- WSUS: Windows Server Update Services provides update synchronization and supports client applicability scans.
- Software update point: The SUP is a Configuration Manager site-system role associated with a WSUS server.
- Management points: Clients use management points to communicate with the Configuration Manager site.
- Distribution points: Update content must be distributed to locations from which clients can download it.
- Windows Update Agent: The client-side agent participates in scanning and update installation.
Microsoft’s prerequisites explain the software-update architecture and installation requirements: Prerequisites for software updates in Configuration Manager.
Use Configuration Manager to manage its WSUS instance
When Configuration Manager manages a WSUS server for a SUP, do not use the WSUS Administration Console to configure WSUS settings. Microsoft explicitly instructs administrators not to configure those settings in the WSUS console; configure the software update point through Configuration Manager instead.
Check remote-role prerequisites and consistency
Confirm WSUS is installed before creating the SUP. If the update point is remote and WSUS is not installed on the site server, the WSUS Administration Console is required on the site server as described in Microsoft’s prerequisites. If a site has multiple software update points, Microsoft’s guidance says their WSUS versions should match.
Rank #3
Configure the software update point
Use the following sequence as a deployment checklist. The exact console options and available settings can vary with Configuration Manager release and topology; follow the documentation for the version you operate.
- Inventory the environment. Record the Configuration Manager release, each server’s edition and installation option, client health, site and management point, WSUS server and version, SUP placement, distribution points, network paths, and available content.
- Install and verify WSUS. Install WSUS on the server intended to support the update point and meet the documented prerequisites. If using multiple update points at a site, verify their WSUS versions match.
- Add or configure the SUP in Configuration Manager. In the Configuration Manager console, use Administration > Site Configuration > Servers and Site System Roles, select the site-system server, and add or configure the Software update point role. Use Configuration Manager’s SUP settings rather than configuring WSUS directly in its administration console.
- Synchronize the update catalog. Configure synchronization for the products and classifications your organization needs, then run or verify synchronization. Product and classification selections determine which updates enter the site’s catalog; avoid selecting broadly without a deployment need.
- Make update content available. Download or otherwise acquire the content for approved updates, place it in an update deployment package as appropriate, and distribute the package to the distribution points that serve the target servers. Verify distribution completes before deployment deadlines.
- Confirm client communication and scan readiness. Check that target servers have healthy Configuration Manager clients, can reach their management point and an appropriate distribution point, and can complete software-update scans.
- Deploy to a limited collection first. Target a pilot collection that represents the relevant Server 2025 editions, roles, and network locations. Set deployment availability, deadline, user experience, restart handling, and maintenance-window behavior to match local policy.
- Review results before widening scope. Evaluate scan and compliance state, installation outcomes, content availability, and restart completion. Resolve failures and obtain the required change approval before deploying to broader collections.
Stage deployment and define restart behavior
A pilot-to-broader rollout is a change-control recommendation, not a Microsoft-mandated ring count or deferral period. Build the scope around service criticality and operational ownership rather than applying the same schedule to every server.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →| Stage | Purpose | What to verify before proceeding |
|---|---|---|
| Pilot | Expose applicability, content, and installation issues on a limited set of representative systems. | Scan results, install status, application and service health, and restart completion. |
| Broader deployment | Expand to approved server collections after pilot results meet local acceptance criteria. | Collection membership, content distribution for each location, maintenance windows, and change approval. |
| Exception handling | Manage servers that cannot follow the normal rollout because of dependencies or availability constraints. | Named owner, documented reason, approved alternative deadline, and follow-up plan. |
Set restart and maintenance-window expectations explicitly for each deployment. The cited Microsoft guidance does not establish a universal restart setting or claim that every update requires the same reboot schedule. Coordinate the deadline and user experience with service owners, and confirm the target collection’s maintenance windows will not conflict with the approved plan.
Rank #4
Validate compliance and diagnose failures
Use Configuration Manager deployment status and client-side evidence to distinguish scan or applicability problems from content, installation, deadline, or restart problems. Do not treat a single console status as proof that a server is fully patched and operational; confirm the outcome against the deployment goal and your organization’s validation process.
- No scan or unexpected applicability: Check client health, management point communication, the SUP and WSUS configuration, synchronization state, and whether the update applies to the server’s edition and state.
- Update is required but installation does not start: Review deployment targeting, availability and deadline settings, maintenance windows, and client policy receipt.
- Download or content error: Verify the update’s content is available and distributed to a reachable distribution point, and check connectivity from the client to that point.
- Installation failure: Review Configuration Manager status and relevant client logs for the affected deployment and update. Match log guidance to the Configuration Manager version in use rather than relying on a generic log-name list.
- Restart is pending or service health is uncertain: Check the deployment’s restart behavior and maintenance window, then validate the server and its hosted services with the responsible service owner.
Keep the evidence with the change record: target collection, update identity and KB, deployment settings, scan and compliance results, installation status, restart outcome, and exceptions. This makes it easier to separate an update issue from a distribution, client-health, or scheduling issue.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Server Core and Software Center
Windows Server Core is included in the supported client platform information from Configuration Manager version 2409, but the Software Center application is not supported on Windows Server Core. Do not direct Core administrators to Software Center to initiate or inspect the deployment; manage the software-update deployment through Configuration Manager and validate using its status and client evidence.
Best Value
WSUS deprecation and Configuration Manager servicing
Is WSUS deprecated or still supported?
Microsoft describes WSUS as deprecated and says it is no longer adding new features. Microsoft also says it continues to support production deployments and deliver security and quality updates according to the product lifecycle. Its deployment guidance lists Windows Server 2025 as a supported OS for the WSUS role. Deprecation therefore does not mean WSUS support or update delivery ended. See Microsoft’s WSUS deployment guidance.
OS updates are not Configuration Manager updates
Windows Server 2025 operating-system updates are deployed through the software-update workflow described above. Configuration Manager itself is serviced separately through the console’s Administration > Updates and Servicing workflow. Microsoft’s servicing documentation describes a prerequisite check for an infrastructure update and the option to schedule updates across primary sites using service windows: Updates and servicing for Configuration Manager.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

