How to Create WSUS Computer Groups and Approval Rings
Applies to: Windows Server 2019, 2022 and 2025.
Approval rings move updates from test to pilot and production populations after defined observation periods.
Patch controls must align with maintenance windows, application support and recovery. Visit networkmanager.info.
Prerequisites
- Define ring membership and owners.
- Choose client-side or server-side targeting.
- Set observation time and rollback criteria.
- Exclude unsupported applications until tested.
Procedure
Step 1: Create groups
In WSUS create Test, Pilot and Production groups.
Step 2: Assign clients
Use client-side targeting GPO or server-side assignment consistently.
Step 3: Approve for Test
Approve selected updates only to the first ring.
Step 4: Review telemetry
Check installation failures, application incidents and reboot outcomes.
Step 5: Promote to Pilot and Production
Approve in stages after acceptance.
Step 6: Document exceptions
Use expiry dates for paused systems.
Verification
Use WSUS console reports or API to compare needed, installed and failed states by group.
Get-WinEvent -LogName 'Microsoft-Windows-WindowsUpdateClient/Operational' -MaxEvents 100Rollback
Decline or remove approval for later rings before installation. Installed update rollback depends on the specific package and vendor guidance.
Operational notes
Auto-approval can be appropriate for definitions but is risky for broad classifications without pilot controls.
Official references
Explore Netcloud24 Canada.