This script allows you to automate several WSUS-related tasks:
- Perform a manual sync
- Decline several types of WSUS updates.
- Approve all updates that are not declined.
- Delete all declined updates.
The script will decline all updates from the following categories/types:
- preview or beta
- superseded
- language packs
- drivers
- updates for ARM
- updates for x86
- updates for all Windows 10
- updates for all Windows 11 versions before 24H2
You will need to run the script from an account with admin rights on the WSUS server.
Decline WSUS updates that are preview, beta, superseded, language packs, drivers. Decline all updates for ARM and x86 architectures. Any update meant for a Windows 11 version before 24H2 will also be declined.
Approve all updates that have not been approved or declined, for the target group "All Computers".
Delete from WSUS all updates that are marked as declined.
Start the sync process on the WSUS server. This parameter takes precedence over the others, except cleanup. If both WsusCleanup and WsusSync are selected, the script will first perform a cleanup and then sync. The script will wait until the sync is completed, then process the other operations, if any.
Start the cleanup process on the WSUS server. This parameter takes precedence over all others. If both WsusCleanup and WsusSync are selected, the script will first perform a cleanup and then sync. The script will wait until the cleanup is completed, then process the other operations, if any.
The WSUS server to connect to. Deafult is localhost.
If SSL is needed to connect to the WSUS server. Default is False.
The port number used by WSUS. Default is 8530.
Auto-WSUSUpdates.ps1 -WsusSync -WsusCleanupStart the WSUS cleanup and wait for it to complete. Afterwards, start the sync.
Auto-WSUSUpdates.ps1 -WsusSync -AutoDecline -AutoApproveTrigger a sync and wait for it to complete. Afterwards, decline all updates that are not needed, and approve the remaining ones.
Auto-WSUSUpdates.ps1 -AutoDecline -DeleteDeclinedDecline all updates that match the categories listed above, and delete them from the server.
Auto-WSUSUpdates.ps1 -DeclineAll -DeleteDeclinedMark all updates as declined, then delete them. This will remove all updates from the server.