Windows MDM更新管理中客户端上报更新GUID与官方ID不一致问题咨询
问题描述
我正在研究通过MDM实现Windows更新管理,需要展示客户端已安装及可安装的更新明细。
按照官方指南操作,我通过Update-CSP从客户端获取已安装、可安装等状态的更新GUID,再到公开更新服务查询对应GUID的元数据。但出现的问题是:客户端上报的部分更新GUID在公开更新服务中无法查询到,例如某设备返回的已安装更新ID为1f36097b-e8c9-41a3-bcc3-baae597f692d。
我调用GetUpdateData接口查询该ID,提示不存在。在客户端本地查询已安装更新,得到如下详情:
PS C:\Windows\system32> $session.CreateUpdateSearcher().Search("UpdateID='1f36097b-e8c9-41a3-bcc3-baae597f692d'").Updates Title : 2021-09 Cumulative Update for Windows 10 Version 20H2 for x64-based Systems (KB5005565) AutoSelectOnWebSites : True BundledUpdates : System.__ComObject CanRequireSource : False Categories : System.__ComObject Deadline : DeltaCompressedContentAvailable : True DeltaCompressedContentPreferred : True Description : Install this update to resolve issues in Windows. For a complete listing of the issues that are included in this update, see the associated Microsoft Knowledge Base article for more information. After you install this item, you may have to restart your computer. EulaAccepted : True EulaText : HandlerID : http://schemas.microsoft.com/msus/2016/01/UpdateHandlers/OSInstaller Identity : System.__ComObject Image : InstallationBehavior : System.__ComObject IsBeta : False IsDownloaded : True IsHidden : False IsInstalled : True IsMandatory : False IsUninstallable : False Languages : System.__ComObject LastDeploymentChangeTime : 9/14/2021 12:00:00 AM MaxDownloadSize : 110963910278 MinDownloadSize : 0 MoreInfoUrls : System.__ComObject MsrcSeverity : RecommendedCpuSpeed : 0 RecommendedHardDiskSpace : 0 RecommendedMemory : 0 ReleaseNotes : SecurityBulletinIDs : System.__ComObject SupersededUpdateIDs : System.__ComObject SupportUrl : https://support.microsoft.com/help/5005565 Type : 1 UninstallationNotes : UninstallationBehavior : UninstallationSteps : System.__ComObject KBArticleIDs : System.__ComObject DeploymentAction : 1 DownloadPriority : 2 DownloadContents : System.__ComObject RebootRequired : False IsPresent : True CveIDs : System.__ComObject BrowseOnly : False PerUser : False AutoSelection : 1 AutoDownload : 2
但我通过更新名称或KB编号查询该补丁,在微软更新目录中查到的对应公开更新ID为9a11c8f1-525f-4088-8fb7-33d7b56dd6dc。
目前不清楚客户端为何会上报和公开ID不一致的更新ID,请问是否有方法可以让客户端上报公开的更新ID?
解决方案
问题根因
客户端上报的GUID不是无效ID,是该更新对应修订版本的唯一ID。Windows累积更新每次迭代调整(包括补丁内容修复、部署逻辑优化)都会生成新的修订ID,客户端本地存储的是实际安装的对应修订版ID,而公开更新查询接口、微软更新目录默认只对外展示最新修订版的主ID,因此旧修订ID无法通过公开接口直接查询到。
可行解决方法
- 优先使用KB编号+系统版本+CPU架构的组合字段匹配更新元数据,该组合具备全局唯一性,不需要依赖更新ID即可100%匹配到对应的补丁信息。你可以在客户端拉取更新状态时直接获取上述三个字段,无需额外调用其他接口。
- 如果必须通过更新ID查询元数据,可在客户端读取更新对象的
Identity.RevisionNumber属性,调用GetUpdateData接口时同时传入更新ID和修订号参数,即可查询到对应修订版本的完整元数据。 - 若要直接获取公共主更新ID,可通过MDM配置客户端更新源指向自建WSUS服务器,WSUS会自动将客户端上报的修订ID映射为公开主ID,管理端直接从WSUS拉取的更新ID即可直接匹配公开元数据。
内容的提问来源于stack exchange,提问作者Ehsan Farhadi
相关产品推荐
相关产品推荐

