Update scan reports not installed when scanned via COM api despite update is installed `Update for Windows Security platform - KB5007651 (Version 10.0.29628.1000) `

Yuvraj Garhwal 0 Reputation points
2026-09-10T05:54:32.1466667+00:00

On device update with title Update for Windows Security platform - KB5007651 (Version 10.0.29628.1000) is installed but when scanned for updates using script below same update appears again with same update id, revision and kb id. Update is not visible in Windows Update UI and update history also shows update as installed but COM Api returns same updates when queried for not installed updates.

Can someone help to understand why is there such discrepancy ? is this expected ?

Device is using Windows 11 Pro, version: 10.0.26200

$session  = New-Object -ComObject Microsoft.Update.Session
$searcher = $session.CreateUpdateSearcher()
$result   = $searcher.Search("IsInstalled=0")

$result.Updates | ForEach-Object {
    [PSCustomObject]@{
        Title          = $_.Title
        KB             = ($_.KBArticleIDs -join ",")
        UpdateID       = $_.Identity.UpdateID
        RevisionNumber = $_.Identity.RevisionNumber
        IsDownloaded   = $_.IsDownloaded
        IsHidden       = $_.IsHidden
        MsrcSeverity   = $_.MsrcSeverity
    }
} | Format-Table -AutoSize

Windows for business | Windows Client for IT Pros | Devices and deployment | Install Windows updates, features, or roles

1 answer

Sort by: Most helpful
  1. Daphne Huynh (WICLOUD CORPORATION) 1,570 Reputation points Microsoft External Staff Moderator
    2026-09-11T05:18:36.23+00:00

    Welcome to Microsoft Q&A!

    Thank you for providing the detailed information, including the operating system version, the scan results, and the PowerShell code used to reproduce the behavior.

    Based on what you've described, the behavior you're seeing with KB5007651 (Windows Security platform update) can occur and does not necessarily indicate that the update is missing from the device.

    Unlike a traditional cumulative Windows update, KB5007651 is a Windows Security / Microsoft Defender platform update. These updates use their own applicability and detection logic, which can occasionally result in differences between the installation status reported by Windows Update History and the status returned by the Windows Update Agent (WUA) COM API.

    When you run: $searcher.Search("IsInstalled=0")

    The query returns updates that the Windows Update Agent currently considers applicable. For Defender platform updates, the detection state maintained by WUA does not always align perfectly with:

    • Windows Update History
    • Windows Security UI
    • Defender platform version reporting

    As a result, it is possible for the same UpdateID, RevisionNumber, and KB article to continue appearing in COM API scan results even after the update has been successfully installed. In such cases, the behavior is generally considered a detection-state or metadata evaluation discrepancy rather than evidence that the update is missing.

    To verify the true installation state, I would recommend checking the currently installed Defender platform version:

    Get-MpComputerStatus |

    Select-Object AMProductVersion, AMServiceVersion

    If AMProductVersion reports 10.0.29628.1000 (or a newer version), that would indicate the Windows Security platform update has already been applied successfully, even if KB5007651 continues to appear in the results of Search("IsInstalled=0").

    If you'd like to investigate further, reviewing the following logs may provide additional insight into why the update is being reoffered:

    • Microsoft-Windows-WindowsUpdateClient logs
    • WindowsUpdate.log
    • Microsoft-Windows-Windows Defender/Operational log

    These logs can help determine whether the behavior is related to applicability evaluation, cached detection metadata, or another update detection condition.

    In summary, if the Defender platform version is already 10.0.29628.1000 and Update History shows KB5007651 as successfully installed, then seeing the same update returned by the COM API query can be an expected reporting anomaly and does not, by itself, indicate an installation failure.

    I hope this helps clarify the behavior.

    Reference: Microsoft Update Catalog

    If you find this information helpful, please click Accept Answer. 

    Thank you for using Microsoft Q&A.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.