Overview

In April 2025, Microsoft released security update KB5055528 for Windows 11 versions 22H2 and 23H2. This update inadvertently introduced a significant issue for enterprise environments utilizing Windows Server Update Services (WSUS) to manage system updates. Specifically, attempts to upgrade to Windows 11 version 24H2 via WSUS failed, displaying error code 0x80240069 and logging messages indicating that the Windows Update service (wuauserv) had unexpectedly stopped.

Background on WSUS

Windows Server Update Services (WSUS) is a tool that enables IT administrators to manage the distribution of updates released through Microsoft Update to computers in a corporate environment. By using WSUS, administrators can fully manage the distribution of updates that are released through Microsoft Update to computers in their network.

Issue Details

After installing the April 2025 security update KB5055528, systems running Windows 11 versions 22H2 and 23H2 encountered failures when attempting to upgrade to version 24H2 via WSUS. The upgrade process would not initiate or complete, and the Windows Update logs displayed error code 0x80240069. Further logs indicated that the Windows Update service had unexpectedly stopped. This issue primarily affected enterprise environments where WSUS is employed to distribute updates across numerous devices. Home users and systems receiving updates directly through Windows Update were not impacted.

Microsoft's Response and Resolution

Upon identifying the issue, Microsoft acknowledged the problem and initiated an investigation to develop a resolution. On May 5, 2025, Microsoft released a Known Issue Rollback (KIR) to address the problem. The KIR allows administrators to revert the specific change introduced by the April update that caused the upgrade failures. To implement the KIR, administrators are advised to install and configure a special Group Policy, which can be found under Computer Configuration > Administrative Templates. Detailed instructions on deploying and configuring this Group Policy are available in Microsoft's support article.

Implications and Impact

This incident underscores the complexities associated with managing large-scale software deployments and the potential for unintended consequences following security updates. It highlights the importance of thorough testing and validation of updates, especially in enterprise environments where update management tools like WSUS are integral to operations. Furthermore, the issue brings attention to the status of WSUS, which Microsoft deprecated in 2024. While existing features of WSUS continue to function, Microsoft has adopted a reactive approach to addressing issues as they arise. This situation may prompt organizations to consider transitioning to alternative update management solutions, such as Windows Autopatch and Microsoft Intune for client updates, and Azure Update Manager for server updates.

Technical Details

The error code 0x80240069 typically indicates issues related to the Windows Update service, such as broken system files or problems with the update installer. In this case, the error was triggered by a change introduced in the April 2025 security update that affected the interaction between WSUS and client devices during the upgrade process to Windows 11 version 24H2. The Known Issue Rollback (KIR) provided by Microsoft effectively disables the specific change that caused the issue, allowing the upgrade process to proceed as intended.

Conclusion

The April 2025 security update for Windows 11 inadvertently caused upgrade issues for systems managed via WSUS, presenting challenges for IT administrators in enterprise settings. Microsoft has addressed the issue through a Known Issue Rollback, and affected organizations are advised to implement the provided Group Policy to resolve the problem. This incident serves as a reminder of the critical need for comprehensive testing and the potential benefits of adopting modern, cloud-based update management solutions to enhance system reliability and security.