WSUS Deprecation: What It Means for Third-Party Patching

October 2, 2026 6 min. read

Direct Answer 

Microsoft deprecated Windows Server Update Services (WSUS) in September 2024. WSUS still works, still ships with Windows Server 2025 and still receives content through the WSUS channel, but it gets no new features. For third-party patching, nothing breaks immediately: updates published to WSUS directly or through Configuration Manager continue to work. The real impact is strategic, because new Microsoft investment is going into Intune and Windows Autopatch, so organizations should choose a third-party patching approach that works with WSUS or ConfigMgr today and Intune later. 

Key Takeaways

  • Deprecation means no new WSUS features or feature requests, not immediate removal.
  • WSUS remains available in Windows Server 2025, and Microsoft continues to publish updates through the WSUS channel.
  • Configuration Manager’s software update point still relies on WSUS.
  • WSUS never sourced third-party content; that still requires local publishing or a publishing tool.
  • The safest plan is a third-party patching method that works across WSUS, Configuration Manager and Intune.

What did Microsoft announce?  

In September 2024, Microsoft announced the deprecation of WSUS on the Windows IT Pro Blog as part of its move toward cloud-based Windows management. Microsoft clarified that it is no longer investing in new WSUS capabilities or accepting new feature requests, while preserving current functionality, continuing to publish updates through the WSUS channel and supporting content already published through that channel.

What deprecation does and does not mean?

Still true What changed
The WSUS server role is available in Windows Server 2025. No new WSUS features are being developed.
Synchronization, approvals and deployments keep working. Microsoft does not accept new WSUS feature requests.
Configuration Manager continues to use WSUS for its software update point. Microsoft’s new update investment is focused on cloud services.
Locally published third-party updates continue to work. Long-term plans should assume a gradual move toward Intune-based management.

Impact on Configuration Manager

Configuration Manager uses WSUS as the foundation of its software update point. Because existing WSUS functionality is preserved, organizations can continue to deploy Microsoft and third-party updates through Configuration Manager, including through automatic deployment rules. The practical question is not whether ConfigMgr patching stops working, but how long your organization wants to maintain on-premises update infrastructure.

Impact on third-party patching

WSUS has never downloaded or packaged third-party updates on its own. Organizations add them through local publishing, where signed update packages are published to the WSUS server and client devices trust the signing certificate. Configuration Manager simplifies this with its Third-Party Software Update Catalogs node, available since version 1806.

Deprecation does not change these mechanisms. It does mean that any new third-party patching investment should also cover Intune, where Microsoft is focusing its development.

Where Microsoft is heading

Microsoft points organizations toward cloud-based update management: Windows update policies managed in Intune, Windows Autopatch for managed update rings, and Azure Update Manager for servers, including Azure Arc–enabled machines. None of these services updates third-party Windows desktop applications by itself. Intune’s Enterprise App Management can keep catalog applications updated for licensed tenants, and third-party publishing tools cover the rest.

Three practical paths

Path Best for Third-party patching approach
Stay and stabilize Organizations with stable WSUS or ConfigMgr estates and no near-term cloud plans Keep local publishing or ConfigMgr third-party catalogs; maintain WSUS health; document the long-term plan.
Hybrid (co-management) Organizations moving workloads from ConfigMgr to Intune in phases Use one catalog and one process that can publish to both ConfigMgr and Intune to avoid coverage gaps.
Cloud-first Organizations already managing most devices with Intune Use Intune Win32 apps with supersedence, Enterprise App Management or a publisher that works directly with Intune.


WSUS transition checklist

  1. List everything WSUS delivers today, including third-party and driver updates.
  2. Identify which device groups are managed by WSUS, Configuration Manager or Intune.
  3. Decide which workloads stay on-premises and which move to Intune, with dates.
  4. Confirm how third-party updates will reach each group during and after the transition.
  5. Keep WSUS maintenance running (cleanup, database health) while it is in use.
  6. Align reporting so compliance can be measured across both environments.

How Easy2Patch supports WSUS, Configuration Manager and Intune

Easy2Patch publishes third-party application updates to WSUS, Microsoft Configuration Manager and Microsoft Intune from the same catalog, without installing an additional agent on endpoints. E2P Patch Manager also automates WSUS maintenance tasks. For Intune-only environments, PatchInCloud provides a cloud-based way to publish and update third-party applications directly in Intune.

Frequently Asked Questions

Microsoft announced the deprecation of WSUS in September 2024. Deprecation means Microsoft is no longer developing new WSUS features or accepting feature requests, but existing functionality is preserved and updates continue to be published through the WSUS channel. WSUS remains available in Windows Server 2025, and Microsoft has not announced a removal date.

Not immediately. The Configuration Manager software update point relies on WSUS, and existing WSUS functionality is being preserved, so ConfigMgr users can keep deploying Microsoft and third-party updates as they do today. The practical impact is strategic: Microsoft’s new update investment is focused on cloud services such as Intune and Windows Autopatch, so long-term plans should account for that direction.

Yes, with additional tooling. WSUS supports locally published updates, which lets an administrator or a publishing tool add signed third-party update packages to the WSUS server, and client devices must trust the signing certificate. WSUS itself does not find, download, package or monitor third-party releases, so organizations usually rely on a catalog-based publishing tool to automate that work.

Microsoft points organizations toward cloud services: Windows update policies managed through Intune, Windows Autopatch for managed update rings, and Azure Update Manager for servers, including Azure Arc-enabled machines. None of these services updates third-party Windows desktop applications such as Chrome or Zoom by itself, so third-party patching remains a separate decision when moving away from WSUS.

Plan it, but an abrupt migration is rarely necessary because WSUS keeps working. Start by listing what WSUS delivers today, including any third-party updates. Then decide which workloads move to Intune and which remain in Configuration Manager, and choose a third-party patching method that works in both environments so coverage does not drop during the transition.

Conclusion

WSUS deprecation is a planning signal, not an outage. Keep WSUS healthy while you use it, decide how workloads will move to Intune, and make sure third-party updates keep flowing on every path.

Sources

Get started with our patch management software for free Advanced Patch Management Get 30 Days Premium Trial