Loading...

Hardening changes for Windows Server Update Services in Windows Server 2025

Hardening changes for Windows Server Update Services in Windows Server 2025

Important hardening changes are here. Starting with the September 2025 security update, WSUS running on Windows Server 2025 is removing dependencies on old code that’s no longer supported. This means that Windows operating systems (OS) that reached the end of their lifecycle will no longer qualify to receive extended security updates (ESU), unless you take additional action. Short-term and long-term next steps are available for Windows Server 2012 and Windows Server 2012 R2 that still need to receive ESUs.    When will this happen:  September 9, 2025    How this will affect your organization:  Removing certain binaries from WSUS helps ensure the integrity and security of our software supply chain. This specifically applies to dependencies on components that no longer meet our compliance and security standards.    The security benefit of removing these binaries from Windows Server 2025 comes with a potential change for you if you’re using ESU updates for Windows Server 2012. You’ll need to take additional action to resume servicing to these devices.    Important: If WSUS is part of a hierarchical deployment (such as connected downstream and upstream servers), there is no impact to your environment. Synchronization and update distribution will continue to function as expected.    What you need to do to prepare:  Consider the following temporary steps to restore service for ESU updates on Windows Server 2012:  After completing these steps, service will resume. To be secure in the longer term, we recommend upgrading the legacy OS versions and upgrading to Windows Server 2025.    Additional information:  Choose an older supported version of WSUS. For example, Windows Server 2025 on the August 2025 security update or earlier, or Windows Server 2022.  Locate the “SelfUpdate” folder on this version of WSUS at %systemdrive%\Program Files\Update Services.  Copy the “SelfUpdate” folder and its contents from the chosen older version of WSUS.  Place it under the WSUS install path on Windows Server 2025 updated with the security update released in or after September 2025.  Add this folder as virtual directory under WSUS website in Internet Information Services (IIS).  Read the official information in Hardening changes for Windows Server Update Services in Windows Server 2025.  […]

The post Hardening changes for Windows Server Update Services in Windows Server 2025 appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Hardening changes for Windows Server Update Services in Windows Server 2025

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Microsoft 365: Entra ID Backup & Recovery

Enable extended 30-day backup and recovery for a tenant’s Entra objects via the Microsoft 365 Backup native app or M365 Backup Storage p...

15 hours ago

Microsoft Viva: Viva Insights and Copilot Analytics in GCC-High

Microsoft Viva Insights and Copilot Analytics are coming to Microsoft 365 Government Community Cloud High (GCC High), providing eligible organ...

15 hours ago

Microsoft Copilot Studio: Streamlining experiences from Copilot Studio Agents in Microsoft 365 Copilot

This update is meant to bridge the experience of using Copilot Studio agents in M365 Copilot with the Copilot Chat experience. With these upda...

15 hours ago

Microsoft Copilot Studio: Enabling makers to require human approval for tool calls

Copilot Studio now let’s makers require human approval before an agent runs specific tools. With a per-tool, per-agent toggle, any gated tool ...

15 hours ago

Updates available for Microsoft 365 Apps for Current Channel

We’ve released updates to the following update channel for Microsoft 365 Apps: Current Channel When this will happen: We’ll be gra...

15 hours ago

General Availability of Power BI developer mode

Power BI developer mode and the PBIP file format are generally available, making PBIR the default report format in Power BI Desktop and servic...

15 hours ago

Microsoft Teams: Users can temporarily pause all notifications

Microsoft Teams will let users temporarily pause notifications for a chosen time to reduce interruptions and improve focus. This feature, avai...

15 hours ago

Teams web client users will be redirected to teams.cloud.microsoft

Teams web users will be redirected from teams.microsoft.com to teams.cloud.microsoft by September 2026. This domain change won’t affect ...

15 hours ago

Outlook for iOS and Android: Automatically apply email sensitivity labels from labeled attachments

Outlook for iOS and Android will automatically apply or recommend email sensitivity labels based on attached files with Microsoft Purview labe...

15 hours ago

Outlook for Mac: Sensitivity label recommendations and auto-labeling from attachments

Outlook for Mac will auto-apply or recommend Microsoft Purview sensitivity labels on emails based on attached files’ labels, enhancing c...

15 hours ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.