TECHRUNBOOK · PRACTICAL GUIDE

Azure VM Windows Update Network and Proxy Troubleshooting

Troubleshoot Windows Update failures on Azure VMs caused by outbound connectivity, DNS, firewalls and proxy configuration.

Practical RunbookTechnical Troubleshooting
Practical Runbook10 StepsIssues → Solutions → Recommendations
Have a question about this runbook?Post your issue to the TechRunbook Community and get help from other IT professionals.
Ask the Community →
!Issue

Troubleshoot Windows Update failures on Azure VMs caused by outbound connectivity, DNS, firewalls and proxy configuration.

Solution

Start with Test Windows Update connectivity and work through the six diagnostic checks in order.

Recommendations

Record results before changing configuration and validate the original symptom after each controlled change.

TechRunbook approach: Test one dependency at a time, record the result and only then change the configuration.

Quick checks

Start with the basic checks in this runbook before moving to deeper troubleshooting.

  • Confirm the affected service or component is available.
  • Check recent configuration or connectivity changes.
  • Run the relevant commands and compare the result with the expected state.
01

Test Windows Update connectivity

Confirm the VM can establish HTTPS connectivity to the Windows Update endpoints required by the operating system.

02

Check outbound NSGs

Review outbound NSG rules on the NIC and subnet for required HTTPS traffic.

03

Check Azure Firewall or NVA

If traffic uses Azure Firewall or an NVA, verify the required Microsoft update destinations are permitted.

04

Check proxy configuration

Check WinHTTP proxy settings and confirm the configured proxy is intentional and reachable.

05

Check DNS

Verify Windows Update endpoint names resolve correctly from the affected VM.

06

Collect Windows Update logs

Generate Windows Update logs after reproducing the issue and correlate errors with the network tests.

07

Useful commands

Run these checks from an appropriate administrative session and replace example values with your environment.

Update endpoint

Test-NetConnection windowsupdate.microsoft.com -Port 443

Proxy

netsh winhttp show proxy
08

Quick troubleshooting path

Use this sequence to isolate the failing dependency before changing production configuration.

  1. Test Windows Update connectivity → Confirm the VM can establish HTTPS connectivity to the Windows Update endpoints required by the operating system.
  2. Check outbound NSGs → Review outbound NSG rules on the NIC and subnet for required HTTPS traffic.
  3. Check Azure Firewall or NVA → If traffic uses Azure Firewall or an NVA, verify the required Microsoft update destinations are permitted.
  4. Check proxy configuration → Check WinHTTP proxy settings and confirm the configured proxy is intentional and reachable.
  5. Check DNS → Verify Windows Update endpoint names resolve correctly from the affected VM.
  6. Collect Windows Update logs → Generate Windows Update logs after reproducing the issue and correlate errors with the network tests.
09

What good troubleshooting looks like

Good infrastructure troubleshooting is evidence-driven. Capture the original state, test the dependency that can prove or disprove your hypothesis, make the smallest safe change and repeat the original test.

Example workflow
Symptom → hypothesis → direct test → result → controlled change → validation → documentation
10

Frequently asked questions

What should I check first?

Start with the exact symptom and validate the dependency closest to the failure in this Azure runbook.

Should I change production configuration immediately?

No. Capture the current state first, test the suspected dependency and make one controlled change at a time.

How should I document the fix?

Record the symptom, commands used, result, configuration change and validation result so the procedure can be repeated.

+

Related TechRunbook guides

Was this runbook helpful?

↑ Top