Skip to content

Maintenance Scripts

WSUS (Windows Server Update Services) maintenance is critical for ensuring efficient update management and preventing database bloat. Automating routine tasks like synchronization and cleanup with PowerShell scripts reduces manual effort and minimizes errors. Below are examples of scripts for common WSUS maintenance operations.


Synchronizing WSUS with Microsoft Update

Regular synchronization ensures WSUS has the latest updates from Microsoft. Use the Invoke-WsusServerSync cmdlet to trigger synchronization.

# Connect to WSUS server
$wsus = Get-WsusServer -Name "WSUS-Server" -Port 8530 -UseSSL

# Synchronize updates (offline mode)
$syncResult = $wsus.Sync(-SyncMode 'Offline')

# Output synchronization details
$syncResult | Format-Table -AutoSize

Notes:
- Replace "WSUS-Server" with your WSUS server's FQDN or IP.
- The -Port and -UseSSL parameters depend on your WSUS configuration.
- Use Sync() in offline mode for production environments to avoid disrupting clients.


Cleaning Up the WSUS Database

Over time, the WSUS database accumulates obsolete data. Use the following scripts to remove superseded updates and old computers.

1. Remove Superseded Updates

# Connect to WSUS server
$wsus = Get-WsusServer -Name "WSUS-Server" -Port 8530 -UseSSL

# Get all superseded updates
$supersededUpdates = $wsus.GetUpdates() | Where-Object { $_.IsSuperseded -eq $true }

# Remove superseded updates
foreach ($update in $supersededUpdates) {
    Remove-WsusUpdate -Update $update -Force
}

2. Remove Old Computers

# Connect to WSUS server
$wsus = Get-WsusServer -Name "WSUS-Server" -Port 8530 -UseSSL

# Get computers older than 90 days
$oldComputers = $wsus.GetComputers() | Where-Object { $_.LastSyncDate -lt (Get-Date).AddDays(-90) }

# Remove old computers
foreach ($computer in $oldComputers) {
    Remove-WsusComputer -Computer $computer -Force
}

Notes:
- Adjust the age threshold (-90 days) based on your environment.
- Use -Force to bypass confirmation prompts in scripts.


Generating Reports

Automate reporting to track synchronization status or cleanup actions.

# Connect to WSUS server
$wsus = Get-WsusServer -Name "WSUS-Server" -Port 8530 -UseSSL

# Get sync status from Sync() result
$syncStatus = $syncResult

# Output report
"WSUS Sync Status:" | Out-File -FilePath "C:\WSUS_Report.txt"
$syncStatus | Format-List | Out-File -FilePath "C:\WSUS_Report.txt" -Append

This script saves a report to C:\WSUS_Report.txt, including details like last sync time and update counts.


Key takeaways

  • Automate synchronization with Invoke-WsusServerSync to ensure WSUS stays up-to-date.
  • Clean up obsolete data using PowerShell to remove superseded updates and old computers.
  • Schedule scripts with Task Scheduler or IIS to run maintenance tasks during off-peak hours.
  • Test scripts in non-production environments first to avoid unintended data loss.
  • Balance cleanup with retention policies to ensure critical updates and client data are preserved.