Azure Update Manager is Microsoft’s unified service for managing operating system updates for Windows and Linux machines across Azure, on-premises, and other clouds.
What is Azure Update Manager?
Azure Update Manager is a native service for monitoring and governing update compliance across Windows and Linux machines — whether running as an Azure VM, an on-premises or multi-cloud machine connected via Azure Arc, a VMware machine, a System Center Virtual Machine Manager machine, or an Azure Local cluster. The service is built as native functionality on Azure VMs and Azure Arc-enabled servers and, unlike the older Update Management approach in Azure Automation, requires no Log Analytics workspace and no Azure Automation account.
Update Manager provides periodic update assessments (every 24 hours by default, also available on demand), immediate or scheduled patch installation within defined maintenance windows, automatic guest patching for Azure VMs, and hotpatching for supported Windows Server configurations to apply critical updates without a restart. Role-based access control (RBAC) enables granular permission management at the resource level.
Core Features
- Unified update management for Windows and Linux servers from a single dashboard
- Flexible patching options: immediate installation, scheduled maintenance windows, automatic guest patching, hotpatching for supported Windows Server scenarios
- Periodic assessments to automatically check for missing updates
- Dynamic scoping to group machines by criteria and roll out updates at scale
- Support for diverse targets: Azure VMs, Azure Arc-enabled servers, VMware machines, System Center Virtual Machine Manager, Azure Local
- Custom reports and alerts via Azure Workbooks to monitor update compliance
Typical Use Cases
Automatic Patch Management for Azure VMs
Configure automatic patch installation for Windows and Linux VMs within defined maintenance windows outside business hours. Automatic guest patching handles ongoing update installation without manual intervention.
Compliance Reporting for Security Updates
Get a central overview of all machines with missing security updates, including filtering by update classification. Azure Policy can be used to enforce and report non-compliance.
Hybrid Cloud Patch Management with Azure Arc
Manage updates for on-premises servers and machines in other clouds via Azure Arc together with your Azure VMs, instead of maintaining separate tools for different environments.
Maintenance Windows for Production Workloads
Define maintenance configurations with start time, duration, and recurrence pattern to apply updates specifically outside critical operating hours.
Benefits
- Native integration with Azure VMs and Azure Arc without additional Log Analytics or Automation account dependency
- Role-based access control at the resource level instead of broad Automation account permissions
- Unified patch management across Azure, on-premises, VMware, and other clouds
- Hotpatching option reduces restarts and downtime for critical Windows updates
Frequently Asked Questions about Azure Update Manager
What does Azure Update Manager cost?
There is no separate charge for using Update Manager itself; you only pay the standard charges for the underlying Azure VMs or Azure Arc resources. Details on any additional charges for specific Arc scenarios are available on the official pricing page.
What is the difference from the older Update Management in Azure Automation?
Azure Update Manager is the successor to the legacy Update Management service in Azure Automation. Advantages include no dependency on a Log Analytics workspace or Automation account, native Azure Resource Manager integration, more granular RBAC control, and additional features such as hotpatching and dynamic scoping.
Does Update Manager support Linux?
Yes. Update Manager manages updates for common Linux distributions via their native package managers, and for Windows via Microsoft Update and WSUS-published updates.
Can I patch on-premises servers?
Yes, via Azure Arc-enabled servers. After installing the Azure Arc agent, on-premises or multi-cloud machines appear in Update Manager and can be managed centrally alongside Azure VMs.
How do maintenance windows work in Update Manager?
You define maintenance configurations with a start time, duration, and recurrence pattern, and assign the relevant machines to them. Updates are then installed only within these windows, or alternatively installed immediately on demand.
Integration with innFactory
As a Microsoft Solutions Partner, innFactory supports you in implementing Azure Update Manager for centralized patch management across Azure, on-premises, and multi-cloud environments.
Contact us for a non-binding consultation on Azure Update Manager and Microsoft Azure.
Typical Use Cases
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.
