locked
How to remove patch from WSUS RRS feed

  • Question

  • I'm wondering what is the best way to remove a patch, KB4487017, from WSUS but not my clients just yet?  We've ran into some problems with Chrome and BSODs on our Windows 10 1803 clients which look very similar to what's reported here

    In that article he says uninstalling and reinstalling KB4487017 on his clients seems to have fixed the issue, so what I'd like to do is remove the patch from WSUS so that it gets redownloaded, as I know MS sometimes re-releases updates with "fixes" but does not documented this.  I'll then locally uninstall the update from a couple clients where the issue has been reported, scan for updates and have them pull the new, hopefully "fixed" update.

    Thanks.

    Thursday, March 7, 2019 7:03 PM

Answers

  • The info I was looking for is here under the 'Reinstating declined updates' heading
    • Marked as answer by J. Wall Monday, March 25, 2019 3:49 PM
    Monday, March 25, 2019 3:48 PM

All replies

  • Hi,
      

    Thank you for posting here.
      

    Analyze what you have provided. If you currently need to uninstall the updates already installed by the client via WSUS, please read the following thread: uninstall update from client
      

    If you need to reject the update in WSUS, this can be done directly in the WSUS console's updated list.
      

    In addition, I noticed that KB4487029, as the latest cumulative update for Windows 10 Version 1803, has improved and fixed known issues and replaced KB4487017. Read the following to learn more about the latest cumulative updates: Windows 10 update history
      

    Hope the above can help you.
      

    Regards,
    Yic Lv

    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Friday, March 8, 2019 5:46 AM
  • Hi,
     

    Any update is welcome here.
    If the issue is resolved, share your solution or find the helpful response "Mark as Answer" to help other community members find the answer.
     

    Thank you for your cooperation, as always.
     

    Regards,
    Yic

    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Friday, March 15, 2019 6:10 AM
  • Hi Yic.  Ok, I understand how to remove updates from clients by setting the update to "Approve for removal" in WSUS.

    What I want to do at the moment is remove and re-download KB4487017 to my WSUS as per the instructions in the article I linked to above, the one here. I understand I can decline KB4487017, but this only prevents it from being installed on clients, it does not force WSUS to re-download it, correct?

    Thursday, March 21, 2019 4:30 PM
  • Hi,
     

    WSUS server contacts the Microsoft Update servers and will only download the metadata (Not complete Full Update Package). The Binaries or the actual downloads are only downloaded when you approve them manually or if there is an Auto approval rule configured.
     

    If you have concerns about how to get updates in WSUS, you can also consider getting updates through the Microsoft Update Catalog import.
     

    Hope the above can help you.
     

    Regards,
    Yic

    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Monday, March 25, 2019 2:40 AM
  • The info I was looking for is here under the 'Reinstating declined updates' heading
    • Marked as answer by J. Wall Monday, March 25, 2019 3:49 PM
    Monday, March 25, 2019 3:48 PM