SYSBOX WinUpdater documentation

Overview

SYSBOX WinUpdater keeps your Windows servers up to date from one web console, without WSUS. It is a single portable program with its own web server and a SQLite database. It needs no installation, no SQL Server and no IIS. WinUpdater connects to your servers with standard PowerShell remoting (WinRM) and uses the PSWindowsUpdate module to find and install updates. No agent is installed on the servers.

What you can do:

  • See every server's update status on a dashboard
  • Check servers for updates: one, several or all
  • Install all pending updates, or only the ones you select, with an optional automatic restart
  • Hide updates you don't want installed
  • Import servers from Active Directory
  • See who did what in the audit log
WinUpdater dashboard

Requirements

Machine running WinUpdater

  • Windows 10/11 or Windows Server 2016 or newer, 64-bit
  • Windows PowerShell 5.1 (included in Windows)
  • A free TCP port for the web console (default 8080)
  • Network access to the managed servers on the WinRM ports (below)

Managed servers

  • Windows Server 2012 or newer (Windows clients work too). On 2012 / 2012 R2, install Windows Management Framework 5.1 (PowerShell 5.1); otherwise PSWindowsUpdate can't be deployed and WinUpdater falls back to the Windows Update API
  • PowerShell remoting enabled. This is the default on Windows Server 2012 and newer. If it is off, run this once as administrator: Enable-PSRemoting -Force
  • Firewall open for WinRM: TCP 5985 (HTTP) or TCP 5986 (HTTPS)
  • An account that is a local administrator on the server
  • Access to Windows Update or Microsoft Update (the servers download updates themselves)

PSWindowsUpdate doesn't need to be installed beforehand. WinUpdater copies it to each server on the first check (see Checking and installing updates).

Installation

  1. Download SYSBOX-WinUpdater.zip and extract it to a folder, e.g. C:\Tools\SysboxWinUpdater.
  2. Optional: adjust config.json (port, HTTPS; see config.json).
  3. Double-click start.cmd. WinUpdater starts in a console window and opens the browser at http://localhost:8080/.
  4. On the first start, create the administrator account (user name, optional display name, password with at least 6 characters).

That's it. All data (database, keys, logs) is stored inside the program folder.

Run as a Windows service

To keep WinUpdater running without a logged-on user:

  1. Right-click install-service.cmd → Run as administrator.
    • Without parameters, the service runs as LocalSystem.
    • install-service.cmd CONTOSO\svc-wu P@ssw0rd runs the service with this domain account. Servers without saved credentials are then contacted with this account.
  2. The script creates the service "SYSBOX WinUpdater" (service name SysboxWinUpdater, start type automatic/delayed, restart on failure), opens the web port in the Windows Firewall (rule "SYSBOX WinUpdater") and starts the service.
  3. To remove it: run uninstall-service.cmd as administrator. Your data is kept.

Stop the console version before installing the service; both use the same port.

First steps

  1. Add servers: click + Add in the tree (top left). See Adding servers.
  2. WinUpdater checks each new server for updates automatically. The first check takes 1-3 minutes, because PSWindowsUpdate is deployed and Windows Update searches.
  3. Open the Dashboard to see which servers need updates.
  4. Check the Automatic updates setting of your servers (see Windows Update policy), so they don't install and restart on their own.
  5. Install updates: on a server with Install all or Install selected, or for all servers with Update all servers on the dashboard.

Dashboard

The dashboard is the first node in the tree.

  • Tiles: servers, up to date, need updates, errors/offline, reboot pending, missing updates (with the number of critical/important updates).
  • Warning bar: appears when servers install updates automatically or have no Windows Update policy configured. See Windows Update policy.
  • Charts: compliance, missing updates by classification, servers with the most missing updates, operating systems, installed updates over the last 30 days.
  • Servers table: sortable. Click a row to open the server. The buttons check a server or install its updates.
  • Recent activity: the latest jobs. Click one to see its log.
  • Buttons: Add servers, Check all servers, Update all servers.

Status colours

Icon/colourMeaning
Green checkUp to date
Red download icon / red numberUpdates pending, at least one is Critical or Important
Yellow download icon / yellow numberUpdates pending (moderate, low or unrated)
Red triangleLast check failed (error)
Plug with red crossServer not reachable (offline)
Grey question markNot checked yet
Spinning circleA job is running for this server
Red power iconReboot pending

Group folders in the tree show the total number of pending updates of their servers. The folder is red if any server in it has important updates.

Adding servers

Click + Add in the tree or Add servers on the dashboard.

Single server

FieldDescription
Host name or IP addressHow WinUpdater connects, e.g. srv01 or srv01.contoso.local or 10.0.0.25
Display nameOptional. Defaults to the host name in capitals
GroupOptional folder in the tree
CredentialsService account (no explicit credentials), a saved credential, or a new credential
NotesFree text, shown on the server page

Click Test connection to check the connection before saving. The button counts the seconds while testing; a test usually takes 3-10 seconds. If it succeeds, you see the server name, OS and the PSWindowsUpdate version.

Credentials: the account must be a local administrator on the server. Use DOMAIN\user, or SERVER\user for local accounts. If you choose "Service account", WinUpdater connects with the account it runs as (your user in console mode, or the service account).

TrustedHosts - servers by IP or outside the domain

If the machine running WinUpdater and the server are not in the same domain, or you add a server by IP address, Windows only connects when the server is in the TrustedHosts list of the WinUpdater machine. Otherwise the test fails with "…the destination machine must be added to the TrustedHosts configuration setting…".

The Trust command section below Test connection shows the exact command with your host name filled in, plus a Copy button. Run it once in an elevated PowerShell (Run as administrator) on the machine where WinUpdater runs:

Set-Item WSMan:\localhost\Client\TrustedHosts -Value "srv01" -Concatenate -Force

Important:

  • The entry must match exactly what you entered as host. A wildcard like 192.168.200.* only matches when you connect by IP. It does not match the name srv01, even if the name resolves to that IP.
  • -Concatenate adds to the list. Without it, the list is replaced.
  • Show the current list: Get-Item WSMan:\localhost\Client\TrustedHosts
  • Avoid * (trust everything). It disables the server identity check for every connection.
  • Domain servers added by name need no entry, because Kerberos is used.

WinUpdater itself never changes TrustedHosts. It only shows the command.

Import from Active Directory

Tab From Active Directory:

  1. Domain: leave it empty to use the domain of the WinUpdater machine, or enter it, e.g. contoso.local.
  2. Credentials: used for the directory query and for the imported servers.
  3. Servers only (operating system contains "Server") and Enabled only filter the list.
  4. Click Search, select computers (servers that already exist are marked "added"), optionally enter a group, and click Add n server(s).
  5. With Check for updates after adding, all new servers are checked right away.

No RSAT tools are needed.

Importing servers from Active Directory

Checking and installing updates

Check for updates

Check for updates on a server (or Check all servers on the dashboard) asks Windows Update on the server which updates are available. The result is live, not cached. It also reads the system information and the Windows Update setting.

On the first check, WinUpdater deploys PSWindowsUpdate to the server, in this order:

  1. from the Modules folder next to WinUpdater (bundled with the download),
  2. from the PSWindowsUpdate module installed on the WinUpdater machine,
  3. from the PowerShell Gallery on the server (needs internet).

If none of this works, WinUpdater uses the Windows Update API directly and shows a warning in the job log.

By default only Windows updates are searched. To include other Microsoft products (SQL Server, Office, …), enable Settings → Use Microsoft Update. If a server is configured for a WSUS server, the search goes to WSUS, and the server page shows a warning.

Install updates

  • Install all (n): installs all pending updates of the server.
  • Install selected: tick updates in the Pending tab, then click Install selected.
  • Update all servers (dashboard): starts an installation on every server with pending updates.

The confirmation dialog lists the updates and offers "Restart the server automatically when the installation requires it". Without this option, the server is never restarted; the server page then shows Reboot pending.

What happens during an installation:

  1. WinUpdater creates a one-time scheduled task on the server that runs as SYSTEM. Windows doesn't allow installing updates directly from a remote session.
  2. The task downloads and installs the updates with PSWindowsUpdate and writes progress to C:\ProgramData\SysboxWinUpdater\ on the server.
  3. WinUpdater reads the progress every 15 seconds and shows it live in the job log.
  4. If a restart is required and allowed, the server restarts 30 seconds after the installation. WinUpdater waits until it is back (up to 30 minutes).
  5. The server is checked again automatically, and the job ends with a summary, e.g. "5 of 6 update(s) installed, 1 failed, server rebooted".

Installations can take a long time (cumulative updates often 20-60 minutes). The maximum is 240 minutes (configurable). You can close the browser meanwhile; the job continues.

WinUpdater server details
WinUpdater install confirmation

Hiding updates

Hidden updates are not offered for installation and are not installed by "Install all".

  • Hide: tick updates in Pending → Hide selected.
  • Unhide: tab Hidden → tick → Unhide selected.

Hiding is stored on the server itself (Windows Update), not only in WinUpdater. Tip: if a server seems up to date but has an old build, check the Hidden tab. A hidden cumulative update blocks all later ones.

Server details

Click a server in the tree.

  • Header: status, reboot pending, host, credential, group. Buttons: Check for updates, Install all, Restart (power icon), Edit (pencil), Remove (bin). Removing only deletes the server from WinUpdater; nothing is changed on the server.
  • System: operating system, version/build, domain, hardware, CPU, and the PSWindowsUpdate version ("WU module").
  • Status: last boot and uptime, last check, last install, Automatic updates setting (see Windows Update policy), update counts and memory usage.
  • Disks: free space per disk. Red below 10% or 5 GB free, yellow below 20%.
  • Tabs:
    • Pending: available updates with KB, title, classification, severity, size and release date. Icons show "already downloaded" and "may require a restart". Click a title for the description and a link to the Microsoft support article.
    • Hidden: hidden updates.
    • Installed: the Windows Update history (installations only). Only the latest 500 entries are loaded. If there are more, the tab shows "500+" and a note.
    • Jobs: all jobs of this server.

Restarting servers

The power icon on the server page restarts the server (after confirmation). WinUpdater waits until the server is back and checks it again.

Jobs

Every action (check, install, hide, unhide, restart) runs as a background job.

  • Up to 8 jobs run in parallel (configurable), but only one job per server at a time. Further jobs wait in the queue.
  • Administration → Jobs lists all jobs. Click a job for its live log.
  • Queued jobs can be cancelled. Cancelling a running installation only stops the monitoring. The installation already running on the server continues there.
  • When a job finishes, a notification appears at the bottom right.
  • Old jobs are deleted after 90 days (configurable).

Audit log

Administration → Audit log records who did what and when: logins (including failed ones), adding/editing/removing servers, checks, installations (with the KB numbers), hide/unhide, restarts, user and credential changes, settings changes and WinUpdater updates. It includes the IP address and is searchable. Entries are kept for 365 days (configurable).

Users and credentials

Users (Administration → Users): all users have the same rights. There are no roles; the audit log shows who did what. You can add, edit, disable and delete users, and reset passwords. You can't disable or delete your own account. Change your own password via the user menu (top right) → Change password.

Credentials (Administration → Credentials): saved accounts for connecting to servers. Passwords are stored encrypted (ASP.NET Data Protection, keys protected with Windows DPAPI). Deleting a credential switches its servers to "Service account".

Windows Update policy Since 1.1

For WinUpdater to be in control, servers should not install updates and restart on their own. Every check reads the server's Automatic Updates setting and shows it on the server page. The dashboard warns about servers that install automatically or have no policy. WinUpdater only reads this setting; it never changes it.

BadgeMeaningOK?
Download onlyDownloads automatically, installs only via WinUpdater (recommended)Yes
Notify onlyNothing downloaded or installed automaticallyYes
Download, notify installLike download onlyYes
OffAutomatic updates disabled; WinUpdater still worksYes
Installs automaticallyWindows installs and may restart on its ownNo
Local admin decides / Not configuredNot controlled by a policyCaution

Click how to change on the server page, or see Settings, for copy-ready instructions.

Standalone servers

Run on the server itself, in an elevated Command Prompt or PowerShell. Example for Download only (recommended):

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v NoAutoUpdate /t REG_DWORD /d 0 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v AUOptions /t REG_DWORD /d 3 /f
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v NoAutoRebootWithLoggedOnUsers /t REG_DWORD /d 1 /f
  • Notify only: use AUOptions /d 2.
  • Off: only NoAutoUpdate /d 1 (plus the NoAutoRebootWithLoggedOnUsers line).
  • Show the current setting: reg query "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU"
  • Back to Windows default: reg delete "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /f

Then click Check for updates in WinUpdater; the new mode is shown. If a domain Group Policy configures Windows Update, it overwrites these values at the next policy refresh.

Domain (Group Policy)

  1. Open Group Policy Management, create a GPO (e.g. "Windows Update - managed by WinUpdater") and link it to the OU with your servers.
  2. Edit it: Computer Configuration → Policies → Administrative Templates → Windows Components → Windows Update (on newer templates: … → Windows Update → Manage end user experience).
  3. Configure Automatic Updates → Enabled, option 3 - Auto download and notify for install (or 2 - Notify for download and auto install for "notify only"; Disabled for "off").
  4. No auto-restart with logged on users for scheduled automatic updates installations → Enabled (on newer templates under Legacy Policies).
  5. Apply with gpupdate /force on a server, or wait up to 90 minutes. Then click Check for updates in WinUpdater.

Don't configure "Specify intranet Microsoft update service location" (WSUS) in this GPO, otherwise the servers search the WSUS server.

Windows Update policy help

config.json

config.json in the program folder contains the settings needed before the database is opened. Restart WinUpdater (or the service) after changes. Relative paths are relative to the program folder. Every key can also be set with an environment variable SYSBOX_<Key> or on the command line (--Port 9090).

KeyDefaultDescription
Port8080Web port
BindAddress** = all network interfaces, or one IP (e.g. 127.0.0.1 for local only)
UseHttpsfalseHTTPS on the web port, see HTTPS
CertificatePath"".pfx file for HTTPS
CertificatePassword""Password of the .pfx
DatabasePathdata\winupdater.dbSQLite database
LogDirectorylogsLog files (one per day)
LogRetentionDays30Days to keep log files
SessionTimeoutMinutes480Login session lifetime (extended while you work)
PowerShellPathpowershell.exeWindows PowerShell 5.1
WinRmUseSslfalseConnect to all servers via WinRM over HTTPS (port 5986)
WinRmPort00 = default port (5985/5986)
WinRmAuthenticationDefaultDefault, Negotiate, Kerberos, CredSSP, Basic
MaxParallelJobs8Jobs in parallel (on different servers)
OperationTimeoutMinutes30Timeout for checks, hide/unhide, restart
InstallTimeoutMinutes240Maximum duration of an installation
RebootWaitMinutes30How long to wait for a server after a restart
UpdateUrlsysbox.io download folderSource of WinUpdater updates; "" disables updates completely
AutoUpdateCheck Since 1.1truefalse = no automatic check for new WinUpdater versions (manual check still works)

config.json may contain comments (// …).

HTTPS for the web console

  1. Get a certificate for the name you use in the browser (CN or SAN), e.g. from your internal CA, and export it as .pfx with the private key.
  2. Copy it into the program folder, e.g. cert\winupdater.pfx.
  3. In config.json:
    "Port": 8443,
    "UseHttps": true,
    "CertificatePath": "cert\\winupdater.pfx",
    "CertificatePassword": "…",
  4. Restart WinUpdater and open https://<server>:8443/.

Notes:

  • If you run it as a service and change the port, run uninstall-service.cmd and install-service.cmd again, so the firewall rule uses the new port.
  • The .pfx password is stored in plain text in config.json. Restrict access to the program folder.
  • With UseHttps: true, CertificatePath must be set.

Settings

Administration → Settings:

SettingDescription
Check all servers for updates automatically, every n hoursBackground check of all servers (off by default)
Check for new WinUpdater versions automatically Since 1.1Twice a day. Greyed out when AutoUpdateCheck is false in config.json
Use Microsoft UpdateAlso search updates for other Microsoft products
Keep job history (days)Default 90
Keep audit log (days)Default 365

The right side shows the startup configuration (read-only), and at the bottom there are the Windows Update policy help and the requirements.

Updating WinUpdater Since 1.1

When a new version is available, a white Update x.y button appears in the top bar. It opens the update dialog with the installed and latest version and the release notes.

Install x.y:

  1. Running or queued jobs must be finished first.
  2. WinUpdater downloads the new version and verifies its SHA-256 checksum. If it doesn't match, nothing is installed.
  3. WinUpdater stops, backs up the current program files to data\update\backup-<old version>, copies the new files and starts again (the service, or the program). data\, logs\ and config.json are never changed. If copying fails, the backup is restored.
  4. The browser reloads automatically when the new version is running. Log: data\update\update.log.
  • Check now in the dialog checks immediately. The link "check for updates" is also in Settings next to the version.
  • Turn off the automatic check: "AutoUpdateCheck": false in config.json. Turn off updates completely: "UpdateUrl": "".
  • Manual update: stop WinUpdater, extract the new zip over the program folder without overwriting config.json, and start again.

Not supported (as of 1.1)

  • Caching or distributing update files (every server downloads from Microsoft itself)
  • Approval workflows like WSUS
  • Roles/permissions for users
  • Connections other than WinRM (no agent, no SMB/PsExec)
  • A per-server HTTPS switch for WinRM (only globally via WinRmUseSsl)

Privacy

WinUpdater does not submit any data or usage statistics.

The only network call it makes to sysbox.io is a periodic check for new versions (see Updating WinUpdater). No data is sent with this request - our server only responds with the version number of the current release.

This check can be turned off in config.json (see config.json).

Troubleshooting

Message / symptomCauseSolution
"…the destination machine must be added to the TrustedHosts configuration setting…"Server by IP or outside the domain, no matching TrustedHosts entryAdd the exact host with the trust command (TrustedHosts)
"Access is denied" when connectingAccount is not a local admin, wrong password, or a local non-built-in admin account over the networkUse a domain admin account or the built-in Administrator; check the saved credential. To test outside WinUpdater: Invoke-Command -ComputerName srv01 -Credential (Get-Credential) -ScriptBlock { hostname }
"WinRM cannot complete the operation" / server shown OfflineServer off, name not resolvable, firewall blocks 5985/5986, or WinRM disabledCheck Test-NetConnection srv01 -Port 5985; run Enable-PSRemoting -Force on the server
Access denied on Set-Item WSMan:…PowerShell not elevated, or TrustedHosts is set by a GPORun as administrator; if a GPO sets it, change it in the GPO
Server shows 0 pending but its build is oldA cumulative update is hiddenCheck the Hidden tab and unhide it
Spinners don't turnWindows "Animation effects" is off (reduced motion)Only cosmetic; the test button shows a seconds counter
Warning "PSWindowsUpdate … could not be deployed"No module in Modules, none on the host, no internet on the serverPut PSWindowsUpdate in the Modules folder, or install it on the WinUpdater machine (Install-Module PSWindowsUpdate)
Job ends with "The install task ended unexpectedly"The installation on the server was interruptedLook at the job log and at C:\ProgramData\SysboxWinUpdater\Install-<job>.log on the server
"Server did not come back online within 30 minutes"Long restart (many updates) or the server hangs at bootCheck the server console; raise RebootWaitMinutes
WinUpdater update failedFiles locked, disk full, no rightsSee data\update\update.log; the backup is in data\update\backup-<version>
Web console not reachable from other PCsFirewall or BindAddressAllow the port (install-service.cmd does this) and check BindAddress: "*"

Logs:

  • WinUpdater: logs\winupdater-YYYYMMDD.log in the program folder
  • Job logs: in the console (Jobs)
  • On the servers: C:\ProgramData\SysboxWinUpdater\ (install progress and logs)
  • Self-update: data\update\update.log

Files and folders

Path (program folder)Content
SysboxWinUpdater.exeThe program (includes the .NET runtime)
config.jsonStartup settings
start.cmdStart in a console window and open the browser
install-service.cmd / uninstall-service.cmdInstall/remove the Windows service
Scripts\PowerShell scripts used for the servers (can be adjusted)
Modules\PSWindowsUpdate\Bundled PSWindowsUpdate (deployed to servers)
wwwroot\Web console files
data\winupdater.dbDatabase (servers, updates, jobs, users, audit log, settings)
data\keys\Encryption keys for saved credentials. Back them up together with the database.
data\update\Self-update downloads, backups and log
logs\Daily log files

Backup: stop WinUpdater and copy data\ and config.json.

Moving to another machine: copy the whole program folder. Saved credentials can only be decrypted on the original machine (DPAPI), so re-enter the passwords under Credentials after moving.

FAQ

For keeping servers patched, yes: check, install, report. It doesn't store or distribute update files and has no approval workflow.

No agent. PowerShell remoting must be enabled; PSWindowsUpdate is deployed automatically.

Yes. Add servers by name or IP, save credentials, and add TrustedHosts entries (see TrustedHosts).

Only if you tick the restart option when installing, or click Restart. Also configure the Windows Update policy (see Windows Update policy), so Windows doesn't restart them on its own.

Yes. Create users under Administration → Users. Everyone has the same rights, and the audit log shows who did what.

In the program folder (data\). Nothing is sent anywhere, except the update check against sysbox.io (can be disabled).

Version history

1.1

  • Self-update from the web console (SHA-256 verified, automatic restart, backup)
  • Windows Update policy check with copy-ready reg commands and GPO directions
  • Trust command helper for TrustedHosts in the Add Servers dialog
  • Help button, config option AutoUpdateCheck
  • SYSBOX design (colours, logos, program icon), single program file
  • Fixes: updates shown merged under "Hidden"; consistent status colours; note for truncated history

1.0

  • First release