如何使用PowerShell筛选并批量安装7位编号的Windows KB更新?
Hey there! I've been digging into PowerShell recently and found the PSWindowsUpdate module incredibly useful—perfect for backend or remote workers. Let me break down how to fulfill your IT manager's request: installing only Windows updates with 7-digit KB numbers (excluding drivers, BIOS updates, etc.), plus walk through the module setup and basic operations.
First: Install the Module & Basic Operations
Before diving into targeted installs, you'll need to set up the required modules and get familiar with core commands. Here's the code to get started:
# -------------------------- Install Windows Update via PowerShell # Allow script execution (disabled by default) Set-ExecutionPolicy Unrestricted -Force # Install the main Windows Update module Install-Module PSWindowsUpdate -Force -AllowClobber # Install module to check for pending reboots Install-Module -Name PendingReboot -Force -AllowClobber # List all available pending updates Get-WindowsUpdate # **************** REVIEW UPDATES BEFORE CONTINUING! **************** # Install all available updates (add -AutoReboot if you want automatic restart) Get-WindowsUpdate -AcceptAll -Install # Install a single update by KB ID (example) Get-WindowsUpdate -KBArticleID KB5022282 -Install # Install multiple updates at once (example) Get-WindowsUpdate -KBArticleID KB4484527, KB890830, KB5022546 -Install # Check if a reboot is pending after updates Test-PendingReboot # Re-enable restricted script execution (recommended after use) Set-ExecutionPolicy Restricted -Force
Step-by-Step Solution for Targeting 7-Digit KB Updates
Follow these four steps to isolate and install only the 7-digit KB updates your team needs:
1. Export All Pending Updates to a File
First, save every pending update entry to a text file for parsing:
Get-WindowsUpdate | Out-File -Path ".\AllPendingUpdates.txt" -Encoding UTF8
2. Extract 7-Digit KB Entries
Use a regular expression to filter out only KB numbers with exactly 7 digits, then save them to a dedicated file:
# Match "KB" followed by 7 digits, extract unique entries, and save Select-String -Path ".\AllPendingUpdates.txt" -Pattern 'KB\d{7}' | ForEach-Object { $_.Matches.Value } | Sort-Object -Unique | Out-File -Path ".\TargetKBs.txt" -Encoding UTF8
Note: The regex KB\d{7} ensures we only capture KB numbers with exactly 7 digits, excluding drivers, BIOS updates, or other non-standard entries.
3. Verify the Target KB List
Take a quick look at the generated file to confirm you're only targeting the right updates:
Get-Content -Path ".\TargetKBs.txt"
4. Loop Through & Install Each Targeted KB Update
Finally, read the filtered KB list and install each update one by one (with optional reboot checks):
$KBList = Get-Content -Path ".\TargetKBs.txt" foreach ($KB in $KBList) { Write-Host "Starting installation for $KB..." -ForegroundColor Cyan Get-WindowsUpdate -KBArticleID $KB -Install # Check if a reboot is needed after this install if (Test-PendingReboot) { Write-Host "⚠️ Pending reboot required after installing $KB. Please restart to proceed." -ForegroundColor Yellow # Uncomment the line below to auto-reboot if your workflow allows it # Restart-Computer -Force } }
内容的提问来源于stack exchange,提问作者Kunta Kinke

