Welcome to Microsoft Q&A!
Thank you for providing the detailed information, including the operating system version, the scan results, and the PowerShell code used to reproduce the behavior.
Based on what you've described, the behavior you're seeing with KB5007651 (Windows Security platform update) can occur and does not necessarily indicate that the update is missing from the device.
Unlike a traditional cumulative Windows update, KB5007651 is a Windows Security / Microsoft Defender platform update. These updates use their own applicability and detection logic, which can occasionally result in differences between the installation status reported by Windows Update History and the status returned by the Windows Update Agent (WUA) COM API.
When you run: $searcher.Search("IsInstalled=0")
The query returns updates that the Windows Update Agent currently considers applicable. For Defender platform updates, the detection state maintained by WUA does not always align perfectly with:
- Windows Update History
- Windows Security UI
- Defender platform version reporting
As a result, it is possible for the same UpdateID, RevisionNumber, and KB article to continue appearing in COM API scan results even after the update has been successfully installed. In such cases, the behavior is generally considered a detection-state or metadata evaluation discrepancy rather than evidence that the update is missing.
To verify the true installation state, I would recommend checking the currently installed Defender platform version:
Get-MpComputerStatus |
Select-Object AMProductVersion, AMServiceVersion
If AMProductVersion reports 10.0.29628.1000 (or a newer version), that would indicate the Windows Security platform update has already been applied successfully, even if KB5007651 continues to appear in the results of Search("IsInstalled=0").
If you'd like to investigate further, reviewing the following logs may provide additional insight into why the update is being reoffered:
-
Microsoft-Windows-WindowsUpdateClient logs -
WindowsUpdate.log -
Microsoft-Windows-Windows Defender/Operational log
These logs can help determine whether the behavior is related to applicability evaluation, cached detection metadata, or another update detection condition.
In summary, if the Defender platform version is already 10.0.29628.1000 and Update History shows KB5007651 as successfully installed, then seeing the same update returned by the COM API query can be an expected reporting anomaly and does not, by itself, indicate an installation failure.
I hope this helps clarify the behavior.
Reference: Microsoft Update Catalog
If you find this information helpful, please click Accept Answer.
Thank you for using Microsoft Q&A.