Forum Discussion
Define Patch Approvals in WSUS but pull patches from Windows Update (Internet)
So is there a way for us to continue to define the approved patches/metadata via WSUS but have the system pull the patches files from the internet (Windows Update) source? Perhaps this is possible with MECM?
Yes, if you are managing updates with MECM, it is possible to have your endpoints download the content from Microsoft Update. See the "If software updates are not available on distribution point in current, neighbor or site boundary groups, download content from Microsoft Updates" setting documented at Manually deploy software updates - Configuration Manager | Microsoft Learn.
That being said, I would recommend taking a closer look at Windows Update for Business. You can use it alongside Software Updates in MECM. I think you can even use it alongside WSUS by configuring a Scan Source policy: Use Windows Update for Business and Windows Server Update Services (WSUS) together | Microsoft Learn