Reminder: Configure firewall and proxies for smooth Windows updates
🚨 The Signal: Microsoft reminds organisations to configure firewalls and proxies to allow Windows Update traffic, specifically TLS connections to *.update.microsoft.com. Failure to do so blocks critical security updates, leaving systems vulnerable.
The Impact
All Windows device users are at risk if their devices cannot receive security updates, increasing exposure to known vulnerabilities.
- Security Teams: Increased attack surface due to unpatched systems.
- IT Administrators: Manual effort to diagnose and remediate network connectivity issues.
- End Users: Potential for system instability or compromise if updates are blocked.
The Action
- Review Windows Update audit logs for connection errors (e.g., 0x8024402C, 0x8024401C, 0x80244007, 0x80072EE2).
- Identify if TLS interception or blocking is occurring for Windows Update traffic.
- Update firewall rules to allow outbound TLS connections to *.update.microsoft.com.
- Update proxy configurations to trust and pass through traffic for *.update.microsoft.com.
- Verify that all necessary DNS subdomains (e.g., update.microsoft.com, sls.update.microsoft.com) are explicitly allowed if wildcard FQDNs are not supported.
Domain: Other · Impact: high · Workload: Other · Essential Eight: Patch Operating Systems, Patch Applications · ISM: ISM-0304, ISM-1407, ISM-1501, ISM-1621, ISM-1622, ISM-1623, ISM-1654, ISM-1655, ISM-1690, ISM-1691, ISM-1692, ISM-1693, ISM-1694, ISM-1695, ISM-1696, ISM-1698, ISM-1699, ISM-1700, ISM-1701, ISM-1702, ISM-1704, ISM-1807, ISM-1808, ISM-1876, ISM-1877, ISM-1889, ISM-1901, ISM-1902, ISM-1905