Skip to content

How MSPs manage Windows updates in PDQ

Meredith
Meredith Kreisa|Updated August 31, 2026
Green PDQ Connect logo on vintage computer
Green PDQ Connect logo on vintage computer

TL;DR: MSPs can use PDQ to manage Windows patching across separate client tenants, with tenant-level visibility into applicable KBs, deployment status, and installed updates. Most patching can be handled directly from the Windows updates view or PSWindowsUpdate packages. For internet-connected environments, PDQ can also replace many common WSUS workflows while adding inventory, deployment tracking, reporting, and third-party patching.

Managing Windows updates across multiple client environments requires keeping devices, deployments, and results organized by customer. In PDQ, you can switch into each client tenant and manage its Windows devices separately. For MSPs looking to reduce their reliance on WSUS, PDQ can also cover many of the same day-to-day Windows update workflows for internet-connected endpoints, including finding applicable updates, deploying them, and tracking results.

Here’s how those Windows update workflows work in PDQ.

How Windows updates work in PDQ

PDQ includes a dedicated Windows updates tab on the left navigation bar that gives MSPs a tenant-wide view of applicable Microsoft KBs across their managed Windows devices. Updates are broken down by status — Not Installed, In Progress, Pending Reboot, Failed, or Installed — so you can quickly see where each update stands.

From the Windows updates tab, you can drill into a KB to see which devices are affected, then trigger installs for one or multiple devices across one or multiple KBs. Each KB gets its own deployment, making it easier to track individual updates.

Windows update installs also appear on the Deployments page with a Windows Update deployment type so you can filter them separately from package deployments. You can also open the Windows updates tab on an individual device to see all update states for that machine.

How to install Windows updates in PDQ

To install Windows updates, first switch into the tenant you want to manage. Then use the Windows updates page to find applicable KBs and deploy them to the devices that need them. Here's how the process breaks down:

  1. In the left navigation, select Windows updates.

  2. Find the update you want to install. PDQ shows applicable KBs across the current tenant, along with device counts for each status, including Not Installed, In Progress, Pending Reboot, Failed, and Installed.

  3. Select one or more KBs, then click Install to deploy them to all eligible devices. To install a specific KB on only certain devices, click its Not installed device count, select the devices you want to target, and then click Install.

  4. Start the deployment. If you select multiple KBs, PDQ creates a separate deployment for each update so you can track their results individually.

  5. Monitor progress from the Deployments page. Windows update installs appear with the Windows Update deployment type, making them easier to distinguish from package deployments.

You can also manage updates for a single endpoint by opening the device from the Devices page, selecting its Windows updates tab, and installing applicable updates from there.

What are Windows update packages in PDQ? 

For most MSPs, using the Windows updates tab is the easiest way to maintain visibility and distribute Windows updates. But it's not the only way. PDQ also offers prebuilt packages that target specific tasks related to Windows updates. For the sake of simplicity, the names are self-explanatory.

  • PSWindowsUpdate – Get All Applicable Updates from Microsoft (Audit Only) 

  • PSWindowsUpdate – Install All Applicable Updates from Microsoft (No Drivers, No Feature Updates) 

  • PSWindowsUpdate – Install Applicable Critical and Security Updates from Microsoft 

  • PSWindowsUpdate – Install Applicable Drivers from Microsoft 

  • PSWindowsUpdate – Install Applicable Feature Updates from Microsoft 

  • PSWindowsUpdate - Install Specific Microsoft KB

Each of these packages relies on PSWindowsUpdate, a popular PowerShell module for managing Windows updates. These packages use PSWindowsUpdate to query Microsoft Update and, for installation packages, install applicable updates.

The same package may install different updates on different endpoints because PSWindowsUpdate installs only the updates applicable to each device.

How to deploy a Windows update package in PDQ

If a PSWindowsUpdate package better fits your use case, first switch into the tenant you want to manage. Then you can deploy the package to individual devices or groups within that tenant.

  1. In the left navigation bar, select Packages. In the Search packages field, type pswindowsupdate, then select your package of choice. For this example, I’ll select PSWindowsUpdate – Install Applicable Critical and Security Updates from Microsoft. Then, click Deploy.

    Screenshot of PDQ Connect interface showing the Packages button, pswindowsupdate in the search field, a checkmark next to PSWindowsUpdate – Install Applicable Critical and Security Updates from Microsoft, and the Deploy button.

  2. Select your target device group. In this example, I’m targeting the My favorite customer group I created (because I play favorites).

    Screenshot of the PDQ Connect Create deployment window showing the My favorite customer group in the Search devices and groups field.

  3. Click Deploy.

    Screenshot of the Create deployment window in PDQ Connect showing the My favorite customer group added and the Deploy button.

And that’s it! But there are a couple of slight caveats: 

  • If you run PSWindowsUpdate – Get All Applicable Updates from Microsoft (Audit Only), the results you’re looking for will be in the output log after deployment.

    Screenshot of the PDQ Connect output log after running PSWindowsUpdate – Get All Applicable Updates from Microsoft (Audit Only).

How does PDQ compare to WSUS?

PDQ and WSUS can both help admins manage Windows updates, but they use different approaches. With Microsoft no longer actively developing WSUS, IT teams and MSPs evaluating alternatives can use PDQ to manage Windows patching on internet-connected endpoints while also handling device inventory, deployment tracking, reporting, and third-party patching.

Capability

WSUS

PDQ

Update source

Uses a WSUS server that synchronizes Microsoft updates

Uses the Windows Update Agent on each managed endpoint to identify applicable updates and trigger installs

Air-gapped environments

Can support disconnected environments using an export and import workflow

Requires internet connectivity and is not designed for air-gapped endpoints

Update control

Admins approve updates for defined computer groups

Admins select applicable KBs and deploy them to specific devices

Tracking and reporting

Provides centralized update status and reporting

Shows KB status, tracks installs, and supports reports for installed Windows updates

Third-party patching

Does not provide a built-in curated third-party package library

Includes prebuilt packages for popular third-party applications

Migrating Windows update workflows from WSUS to PDQ

Moving Windows update workflows from WSUS to PDQ works best as a phased process. Start by documenting your existing WSUS setup, then test deployments with a small group before expanding to additional devices and tenants.

  1. Document your existing WSUS configuration and device groups.

  2. Map those devices to the appropriate PDQ tenants and groups.

  3. Test Windows update deployments on a small group of representative endpoints.

  4. Roll out updates in phases and verify results in Windows updates, Deployments, or Reports.

MSP Windows updates FAQs

Can PDQ handle third-party updates?

Yes. PDQ can manage Microsoft Windows updates alongside software deployments for popular third-party applications using prebuilt packages from the Package Library.

How do I audit which Windows updates were applied?

Use the Windows updates page and Deployments page to track update status and deployment results. You can also build reports showing installed Windows updates, including update titles and installation dates.

Can PDQ patch Windows Server without WSUS?

Yes. PDQ can identify applicable Microsoft updates and deploy them to supported internet-connected Windows Server devices. The PDQ agent supports 64-bit Windows Server 2016 or later, so an on-premises WSUS server is not required for these devices.


Ready to see your clients gasp in disbelieving delight? Get Windows updates on their endpoints with less hassle. Schedule a demo or start a trial to see PDQ in action. 

Meredith
Meredith Kreisa

Meredith is a content marketing manager at PDQ focused on endpoint management, patching, deployment, and automation. She turns dense IT workflows into clear, step-by-step guidance by collaborating with sysadmins and product experts to keep tutorials accurate and repeatable. She brings 15+ years of experience simplifying complex SaaS and security topics and holds an M.A. in communication.

Related articles