Loading...

Hardening changes for Windows Server Update Services in Windows Server 2025

Hardening changes for Windows Server Update Services in Windows Server 2025

Important hardening changes are here. Starting with the September 2025 security update, WSUS running on Windows Server 2025 is removing dependencies on old code that’s no longer supported. This means that Windows operating systems (OS) that reached the end of their lifecycle will no longer qualify to receive extended security updates (ESU), unless you take additional action. Short-term and long-term next steps are available for Windows Server 2012 and Windows Server 2012 R2 that still need to receive ESUs.    When will this happen:  September 9, 2025    How this will affect your organization:  Removing certain binaries from WSUS helps ensure the integrity and security of our software supply chain. This specifically applies to dependencies on components that no longer meet our compliance and security standards.    The security benefit of removing these binaries from Windows Server 2025 comes with a potential change for you if you’re using ESU updates for Windows Server 2012. You’ll need to take additional action to resume servicing to these devices.    Important: If WSUS is part of a hierarchical deployment (such as connected downstream and upstream servers), there is no impact to your environment. Synchronization and update distribution will continue to function as expected.    What you need to do to prepare:  Consider the following temporary steps to restore service for ESU updates on Windows Server 2012:  After completing these steps, service will resume. To be secure in the longer term, we recommend upgrading the legacy OS versions and upgrading to Windows Server 2025.    Additional information:  Choose an older supported version of WSUS. For example, Windows Server 2025 on the August 2025 security update or earlier, or Windows Server 2022.  Locate the “SelfUpdate” folder on this version of WSUS at %systemdrive%\Program Files\Update Services.  Copy the “SelfUpdate” folder and its contents from the chosen older version of WSUS.  Place it under the WSUS install path on Windows Server 2025 updated with the security update released in or after September 2025.  Add this folder as virtual directory under WSUS website in Internet Information Services (IIS).  Read the official information in Hardening changes for Windows Server Update Services in Windows Server 2025.  […]

The post Hardening changes for Windows Server Update Services in Windows Server 2025 appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Hardening changes for Windows Server Update Services in Windows Server 2025

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Microsoft Teams: Updated header and dashboard for chats and channels on mobile

Microsoft Teams mobile will feature a redesigned header and lightweight dashboard for chats and channels, improving navigation and access to k...

1 day ago

Deprecation for Manifest V2 (MV2) browser extensions support in Microsoft Edge

Microsoft Edge will retire Manifest V2 (MV2) extensions by early 2027, fully switching to Manifest V3 (MV3) for improved security and performa...

1 day ago

Power BI subscriptions: Changes to notification delivery and sender experience

Power BI is updating subscription notification delivery to improve reliability and sender reputation, changing sender identity, email formatti...

1 day ago

Cross-post SharePoint News to Engage

SharePoint News can now be cross-posted to Viva Engage communities with full fidelity and synchronized conversations across platforms. Rolling...

3 days ago

Call Quality Dashboard Custom Detailed Reports

Call Quality Dashboard will get a refreshed interface with enhanced accessibility and features like dark mode. Public preview starts mid-Augus...

3 days ago

Microsoft Copilot Pages: Access existing Pages from the “/” menu in chat

Starting late August 2026, users can access existing Pages via the “/” menu in Copilot chat, while the “Edit in Pages”...

3 days ago

Microsoft Teams: Collect information with List Form in Workflows

Microsoft Teams Workflows will add a new trigger, “A form is submitted,” for automating actions based on SharePoint list–backed fo...

3 days ago

Microsoft Viva Engage: Reducing reply notification volume in email

Microsoft Viva Engage will reduce email reply notifications by only sending alerts for direct replies, @mentions, and new posts, cutting down ...

3 days ago

Microsoft Teams: Lobby visibility will align with the “Who can admit from lobby” meeting option

Microsoft Teams will align lobby visibility with the “Who can admit from lobby” setting, so only users allowed to admit participan...

3 days ago

Microsoft Word: Similarity Checker retirement

Microsoft Word’s Similarity Checker will be retired on October 3, 2026, and removed from Microsoft Editor. Other writing and editing fea...

3 days ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.