Hi Fred Boulton,
Where do you update the client, Microsoft update or WSUS server?
How do you configure the Windows update policy, configure locally or via GPO (the client is domain-joined)?
1. If you use GPO to apply the update police, then use command
gpupdate/ force & gpresult /h C:\report.html
to check if the client has apply the policy;
2. If you configure AU options locally, then check the following article to verify if all the configurations are all correct:
https://technet.microsoft.com/en-us/library/cc720464(v=ws.10).aspx
3. After configuring the clients, wait the client to report to the WSUS server, then approve related updates for the client on WSUS server, then check updates on clients.
Best Regards,
Anne
Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact tnmff@microsoft.com.