To deploy software updates in SCCM (Microsoft Configuration Manager), prepare and synchronize the software update point (SUP), select and download update content, distribute it to distribution points, target a collection, configure availability and deadlines, then verify client installation and compliance. The exact console labels and options vary by current-branch release and site topology, so confirm them in your environment.
How do I deploy software updates in SCCM?
Use this sequence for a controlled deployment. Metadata synchronization makes updates available for selection; it does not download their binary content. A deployment package carries update content to distribution points, while the deployment itself assigns updates and timing to a collection.
- Confirm the site and deployment scope. Record the installed Configuration Manager current-branch version, site hierarchy, target collection, update products and classifications, client policy state, and required maintenance windows.
- Prepare the software update point. A SUP is required at the central administration site or standalone primary site, and at primary sites for update compliance and deployment. It is optional at secondary sites. The highest site with a SUP synchronizes first; synchronization then proceeds to child sites where applicable. See Microsoft’s preparation guidance and SUP synchronization guidance.
- Synchronize metadata and set scope. Configure synchronization settings and schedule, then run an initial synchronization. Review the available product and classification lists, select the updates you manage, and synchronize again to retrieve metadata for those choices. Updates do not appear in the console until synchronization has occurred. Metadata synchronization is separate from downloading update files.
- Check client-side prerequisites. Verify client settings for software updates, relevant Group Policy configuration, and the software update settings used by your clients. Microsoft’s preparation guide describes the initial synchronization as a way to obtain the updated products and classifications list before choosing those settings.
- Select and download updates. For a controlled rollout, select the reviewed updates and download them to a deployment package. You can also download content as part of a manual deployment or automatic deployment rule (ADR) run. Confirm the package source location and content before deploying broadly.
- Distribute content. The usual content path is the package source to the site-server content library, then to distribution-point content libraries. Check distribution-point status before targeting a broad collection.
- Create the deployment. Use the Deploy Software Updates Wizard for a manual group deployment, or configure an ADR for recurring selection and deployment. Choose the target collection, required or available behavior, availability time, deadline, alerts if useful, and boundary-group download options.
- Validate client results. Track deployment status and client state messages. On the client, confirm the update is no longer required or is reported installed after any required restart.
Microsoft’s software updates introduction describes the overall workflow, including synchronization, deployment, and client evaluation.
How do I create an SCCM software update deployment package?
A deployment package is a way to stage and distribute update content; it is not the assignment that tells a collection which updates to install. Keep the package source location accessible to the site server, download the selected updates into the package, and distribute the package to the required distribution points. Before broad deployment, confirm that distribution has completed and that the intended clients can obtain content from an allowed source.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
For on-premises update management using Unified Update Platform (UUP), Microsoft’s download guidance states that an additional 10 GB of space per Windows version and processor architecture is required. This is a UUP-specific capacity note; it should not be applied to every update workflow.
Should I deploy updates manually or use an ADR?
Both approaches need deliberate collection targeting, timing, content distribution, and validation. Choose manual deployment when an administrator wants to review a particular update batch before assigning it; consider an ADR when recurring criteria should select updates on a schedule. These are operational guidelines, not guarantees about suitability for every site.
Rank #2
| Decision point | Manual deployment | Automatic deployment rule (ADR) |
|---|---|---|
| Update selection | The administrator selects the updates or group for the deployment. | Rule criteria select matching updates during evaluation. |
| Operational cadence | Useful for a specifically reviewed batch or one-off release. | Supports recurring selection and deployment; review the criteria and schedule. |
| Timing | Set availability and deadline in the deployment wizard. | Availability and deadline are tied to ADR evaluation timing. Microsoft documents a calculation change starting with Configuration Manager version 2203. |
| What to verify | Package distribution, target collection, deadline, client compliance, and restart state. | Rule criteria and evaluation results, resulting deployment, package distribution, client compliance, and restart state. |
For procedure details, consult Microsoft’s manual deployment guide and ADR guide. Check the documentation for your installed release before relying on a particular label or time calculation.
When will clients install updates?
With a required deployment, clients are expected to install the updates at the configured deadline, subject to policy, applicability, content access, and maintenance-window behavior. An available deployment without a deadline is optional: the client does not download the update until a user starts installation. Configure the availability time and deadline to match the intended rollout, rather than treating them as interchangeable.
Rank #3
For ADRs, Microsoft’s documentation for version 2203 and later bases available-time and deadline calculation on the scheduled or start time of rule evaluation. Because this is release-sensitive, confirm the behavior against the installed current-branch version and your ADR schedule. See Microsoft’s ADR timing documentation.
How should I plan maintenance windows and restarts?
Coordinate update windows with restart policy before deploying. If a device has both a general maintenance window and a software-updates maintenance window, updates install only during the software-updates window unless the relevant setting changes that behavior. Review Microsoft’s software update planning guidance alongside the maintenance-window settings in your site.
Rank #4
Required updates may need a computer restart to complete installation. Suppressing a required restart is an operational decision: it can leave a device in an insecure state or leave installation incomplete. Account for restart timing and user impact in the deployment plan rather than treating restart suppression as a harmless convenience. Microsoft describes deployment restart controls in its manual deployment documentation.
How do I check whether an SCCM patch installed?
- In the Configuration Manager console, review the deployment status and client state messages for the targeted deployment.
- On a client, confirm that the update is reported as installed or no longer required after the device has completed any required restart and subsequent evaluation.
- If status is missing or unexpected, distinguish a scan or applicability problem from content transfer, installation, supersedence, detection, restart, or reporting issues. Use Microsoft’s deployment troubleshooting guide and software update management troubleshooting guide for the relevant failure stage.
Why is my SCCM update deployment stuck downloading?
Start by scoping the problem, then trace the client’s content-location and transfer path. Avoid broad changes until you know whether the issue affects one client, one boundary group, or a wider portion of the site.
Best Value
- Define the scope. Record the symptom, start time, frequency, percentage of affected clients, client and server versions, recent environment changes, and shared site or network characteristics.
- Read the client transfer logs. For download failures, inspect
CAS.log,ContentTransferManager.log, andDataTransferService.log. Microsoft’s deployment troubleshooting guidance identifies these as useful logs for tracing content acquisition and transfer. - Check boundary and content availability. Confirm that the client is in the intended boundary and boundary group, and that an associated distribution point has the package content.
- Review allowed content sources. Check deployment and package status, and whether the client’s boundary-group configuration permits content fallback or another source when the preferred distribution point cannot serve the content.
- Separate download from later failures. If content arrived, investigate scan, applicability, installation, supersedence, detection, restart, or reporting instead of treating the symptom as a download problem.
Microsoft’s software update management troubleshooting guidance provides additional context for diagnosis; match its steps to the client and server releases in use.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

