2025-05-29
Windows Update Orchestration Platform
Microsoft is previewing the Windows Update Orchestration Platform, which will allow third-party apps to update through Windows Update. According to the Windows IT Pro blog, "Built on the Windows Update stack, the orchestration platform aims to provide developers and product teams building apps and management tools with an API for onboarding their update(s) that supports the needs of their installers. The orchestrator will coordinate across all onboarded products that are updated on Windows 11, in addition to Windows Update, to provide IT admins and users with a consistent management plane and experience, respectively."
Editor's Note
A system like this is overdue. I am always impressed by how much easier it is to patch Linux systems, with most updates being available from a single source. Windows has some catching up to do.

Johannes Ullrich
While this is a welcome move and one that should make patching and updating third-party applications much more effective, I do sincerely hope that Microsoft will provide appropriate controls and measures to ensure third-party vendors are not compromised to enable malicious code to be delivered via this solution.

Brian Honan
Having fewer tools to coordinate, install, and update products is a win for both IT and security, and many shops have solutions in play for this reason. The update orchestration platform handles both Microsoft and third-party updates, including apps and drivers, and provides services for scheduling updates/reboots during less impactful times, as you get with Windows update services today. Compare this to your current update orchestration service, particularly if you're a Windows-only shop.

Lee Neely
This could be huge news for the cybersecurity industry. Whether you like it or not, Windows is the dominant operating system used by both the consumer and enterprise market. Consumers are notoriously bad at handling software updates, especially if dealing with multiple update services. Centralizing this service perhaps removes some of the burden for those users. More to follow I suspect, on both risk and reward.

Curtis Dukes
Who in the audience is a Red Teamer who just realized that we have a new way of delivering implants, like a Microsoft-sanctioned version of Evilgrade? Am I the only one?

Moses Frost
Probably worth waiting for release and testing of Microsoft's fix to the Open Drive issue before committing to putting all your eggs in the Windows Update basket.

John Pescatore
Read more in
Microsoft: Introducing a unified future for app updates on Windows
The Register: Microsoft is opening Windows Update to third-party apps
BleepingComputer: Microsoft wants Windows to update all software on your PC
Help Net Security: Microsoft unveils ‘centralized’ software update tool for Windows
ZDNet: Microsoft's Windows Update to include third-party apps - now that's a game changer