Joe_Lurie why will future versions not require this I actually like this idea more so you have better control. Its annoying to see updates for 1703, 1607, 1803 if they are builds I have never deployed in my environment then have to time consolingly deny them every single month. That fact that WSUS has not received a UI facelift in so long to better manage this stuff is disappointing especially if you don't tie it to SCCM. Same thing with freaking Itanium updates where is there no way to disable them or auto deny them if I dont have any of that hardware so every month I have to go deny them so they dont show in the unapproved interface. We still need to control so WUFB in the clound is not a good choice but WSUS needs improvement after a lot of stagnation Make this simpler on us please.