can Azure update manager for linux install Bug fixes?

prasanthi sunkara 0 Reputation points
2026-10-07T08:24:10.07+00:00

We are using Azure Update Manager with a Maintenance Configuration for RHEL 8/9 Linux VMs.

The patch orchestration mode is Customer Managed Schedules and the update classification is configured as:

Linux: Security and critical updates

A recent patch run completed successfully:

Installed updates: 142

Failed: 0

Not selected: 42

On the VM, dnf updateinfo summary shows:

3 Security notice(s)

39 Bugfix notice(s)

and dnf updateinfo list shows the remaining updates are primarily RHBA (Bugfix) advisories rather than RHSA (Security) advisories.

My questions are:

  1. Does Azure Update Manager for Linux only install Security/Critical updates and intentionally exclude RHBA Bugfix advisories?
  2. Is there a supported way to configure a Maintenance Configuration to install Bugfix updates as well as Security updates?
  3. If so, where is this configured in Azure Update Manager?
  4. If not, is the recommended approach to use a custom script, Ansible, or another patching solution to install all available dnf updates?

Thanks in advance for any guidance.

Azure Update Manager
Azure Update Manager

An Azure service to centrally manages updates and compliance at scale.

0 comments No comments

1 answer

Sort by: Most helpful
  1. Salamat Shah 830 Reputation points MVP
    2026-10-07T08:45:15.0666667+00:00

    Yes. Azure Update Manager can install Bugfix updates (RHBA) on Linux, but only if the update classification includes them.

    1. Your maintenance configuration is currently set to "Security and Critical updates", so Azure Update Manager installs mainly RHSA (Security) updates and excludes most RHBA (Bugfix) updates.
    2. Edit the Maintenance Configuration and include Other updates (or the classification that maps to bugfix packages for your distro).
    3. If your goal is to install all available dnf updates, Azure Update Manager's classification-based patching may not be sufficient. In that case, use a custom script, Ansible, or another configuration management tool to run: dnf update -y

    The 39 remaining RHBA advisories are expected because your current configuration targets Security/Critical updates only. Add the appropriate classification or use a custom patching approach for full package updates.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.