deploy update ADR FOR SERVER AND CLINT

Nasser Albusaidi [Economy] 0 Reputation points
2026-10-06T09:23:30.9266667+00:00

We will be implementing Automatic Deployment Rules (ADR) for Microsoft updates to ensure timely and consistent patch management across both servers and client devices.

Microsoft Security | Intune | Configuration Manager | Other
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-10-06T09:23:44.13+00:00

    For Configuration Manager, use an Automatic Deployment Rule (ADR) to automate Microsoft update deployment for both server and client collections.

    A practical rollout is:

    1. In the Configuration Manager console, go to Software Library > Software Updates > Automatic Deployment Rules.
    2. Select Create Automatic Deployment Rule.
    3. On General:
      • Give the ADR a unique Name and optional Description.
      • Select a template if applicable, such as Patch Tuesday for monthly updates.
    4. Define the update criteria for the ADR so only the required updates are added to the software update group.
    5. On Evaluation Schedule:
      • Enable the ADR schedule.
      • Set the recurring schedule with Customize.
      • Keep the ADR evaluation frequency at or below the software update synchronization schedule.
      • ADR evaluation can run up to three times per day.
    6. Run the ADR manually with Run Now when needed.

    Recommended deployment strategy:

    • Create the ADR first for a test or pilot collection.
    • After validation, add a new deployment to the existing ADR for a broader production collection.
    • Each added deployment can target a different collection and have its own:
      • activation time
      • deadline
      • user experience
      • alerts
    • All added deployments use the same update group and package created by the ADR when it first runs.

    To add another deployment to the same ADR:

    1. Go to Software Library > Software Updates > Automatic Deployment Rules.
    2. Select the existing ADR.
    3. Click Add Deployment.
    4. Configure:
      • Collection
      • Deployment Settings
      • Deployment Schedule
      • User Experience
      • Alerts
      • Download Settings

    Important behavior to plan for:

    • An ADR can add updates to a new software update group each time it runs, or to an existing group.
    • If configured to use an existing group, when the rule runs it removes all updates from that group and then adds only the updates that match the ADR criteria.
    • Before creating the first ADR, verify that software updates synchronization has completed.

    If scripting is preferred, Configuration Manager also provides the New-CMSoftwareUpdateAutoDeploymentRule PowerShell cmdlet to create an ADR. Run Configuration Manager cmdlets from the Configuration Manager site drive, for example PS XYZ:\>.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.