| MC1465017 | Reminder: Configure firewall and proxies for smooth Windows updates |
|---|
| Classification | stayInformed |
|---|---|
| Last Updated | 08/31/2026 17:10:04 |
| Start Time | 08/31/2026 17:10:02 |
| End Time | 08/31/2027 17:10:02 |
| Message Content |
What and why
By design, Windows Update doesn’t trust servers that don’t have TLS certificates issued by an actual Windows Update trust anchor. We published guidance in May 2026 to help you diagnose and fix connection issues that result from this design.
Rollout schedule
Impact on your organization
Your firewalls and proxies might block access to the trustworthy and necessary Windows Update service if your configuration is either intercepting TLS connections or isn’t passing TLS requests through for the necessary DNS subdomains. The published guide helps you diagnose and fix related issues.
Action required/recommendations
Diagnose connection issues by checking the Windows Update audit log. Our detailed guidance lists the recommended PowerShell command and four error codes that can confirm the issue.
To remedy the situation, trust all the DNS hosts and subdomains related to wildcard FQDN for the connection to work properly. For example, a recommended DNS host name *.update.microsoft.com represents all the following hosts and subdomains:
Update your proxy and firewall configurations if any of these subdomains are missing. If your devices connect to an IT-managed Windows Server Update Services (WSUS) server, these exceptions aren’t necessary.
Compliance considerations
Devices that cannot reach the Windows Update service will stop receiving security updates.
Additional information
|
| Machine Translation |
何となぜ
設計上、Windows Updateは実際のWindows Update信頼アンカーによって発行されたTLS証明書を持たないサーバーを信頼しません。この設計に起因する接続問題の診断と修正を支援するためのガイダンスを2026年5月に公開しました。
展開スケジュール
組織への影響
構成がTLS接続を傍受したり、必要なDNSサブドメインのTLSリクエストを通過していない場合、ファイアウォールやプロキシが信頼できる必要なWindows Updateサービスへのアクセスをブロックする可能性があります。公開されているガイドは、関連する問題の診断と修正に役立ちます。
必要な行動/提言
接続問題の診断は 、Windows Update監査ログを確認しましょう。 詳細なガイダンスでは 推奨されるPowerShellコマンドと、問題を確認できる4つのエラーコードが記載されています。
この状況を改善するために、ワイルドカードFQDNに関連するすべてのDNSホストおよびサブドメインを信頼して接続を正常に機能させます。例えば、推奨されるDNSホスト名*.update.microsoft.com は以下のすべてのホストおよびサブドメインを表します。
これらのサブドメインが欠けている場合は、プロキシやファイアウォールの設定を更新してください。もしデバイスがIT管理のWindows Server Update Services(WSUS)サーバーに接続しているなら、これらの例外は必要ありません。
コンプライアンスの考慮事項
Windows Updateサービスにアクセスできないデバイスはセキュリティアップデートの受信を停止します。
追加情報
|