This article is contributed. See the original author and article here.

We are excited to announce that the Update Baseline is now a part of the Security Compliance Toolkit! If you’re not yet familiar with this great tool, the Update Baseline offers Microsoft’s set of recommended policy configurations for Windows Updates to help you:



  • Ensure that the devices on your network receive the latest monthly security updates in a timely manner.

  • Provide a great end user experience throughout the update process.


The Update Baseline includes Windows Update policies as well as power and Delivery Optimization policies—all designed to streamline the update process, improve patch compliance, and help ensure your devices stay secure. In fact, devices that are configured using  the Update Baseline reach, on average, a compliance rate between 80-90% within 28 days.


What is included in the Update Baseline?


For Windows Update policies, the Update Baseline offers recommendations around:



  • Deadlines, the most powerful tool in the IT administrator’s arsenal for ensuring devices get updated on time.

  • Downloading and installing updates in the background without disturbing end users. This also removes bottlenecks from the update process.

  • A great end user experience. Users don’t have to approve updates, but they get notified when an update requires a restart.

  • Accommodating low activity devices (which tend to be some of the hardest to update) to ensure the best-possible user experience while respecting compliance goals.


How do I apply the Update Baseline?


If you manage your devices via Group Policy, you can apply the Update Baseline using the familiar Security Compliance Toolkit framework. With a single PowerShell command, the Update Baseline Group Policy Object (GPO) can be loaded into Group Policy Management Center (GPMC) as shown below:


You can add the MSFT Windows Update GPO that adds the Update Baseline to GPMC with a single command.You can add the MSFT Windows Update GPO that adds the Update Baseline to GPMC with a single command.


You can then view the Update Baseline GPO (MSFT Windows Update) in the GPMC.You can then view the Update Baseline GPO (MSFT Windows Update) in the GPMC.


That’s it! Simple and easy.


Download the updated Security Compliance Toolkit today to start applying security configuration baselines for Windows and other Microsoft products.


I also encourage you to learn more about common policy configuration mistakes for managing Windows updates and what you can do to avoid them to improve update adoption and provide a great user experience.


Other cool tidbits? The Update Baseline will continue to be updated and improved as needed, and an Intune solution to apply the Update Baseline is coming soon! Let us know your thoughts and leave a comment below.

Brought to you by Dr. Ware, Microsoft Office 365 Silver Partner, Charleston SC.