Azure Update Manager Implementation for On-Premises Environment with Limited Internet Bandwidth

Luis Gabriel Mieles Benavides 70 Reputation points
2025-10-24T23:14:03.1766667+00:00

We are planning to implement Azure Update Manager in an on-premises environment consisting of approximately 200 virtual machines, all joined to the abc.local domain. These VMs are currently managed within our local infrastructure and are not configured to communicate directly with the internet due to bandwidth constraints and high traffic sensitivity.

To ensure efficient patching and update management without saturating our outbound connection, we require a solution where a single on-premises server acts as a control point or proxy for update orchestration. The goal is to centralize communication with Azure Update Manager through this server, minimizing direct internet traffic from individual VMs.

We are seeking guidance on:

Recommended architecture for Azure Update Manager in this scenario.

Whether a proxy or gateway server can be configured to relay update metadata and instructions.

Network and firewall requirements to support this setup.

Integration considerations with our existing domain (abc.local) and group policies.

Best practices for update deployment scheduling and bandwidth optimization.

Thank you for your support.

Azure Update Manager
Azure Update Manager
An Azure service to centrally manages updates and compliance at scale.
0 comments No comments
{count} votes

Answer accepted by question author
  1. Adam J. Marshall 10,456 Reputation points MVP
    2025-10-25T02:52:31.2666667+00:00
    1 person found this answer helpful.

Answer accepted by question author
  1. Jeff Pigott 475 Reputation points Microsoft Employee
    2025-10-25T01:53:44.2333333+00:00

    Utilize WSUS as Azure update manager will use your local repo without pulling updates from the Internet. WSUS will be around for 8+ years until Windows Server 2025 is EOL.

    https://learn.microsoft.com/en-us/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus

    Try this out and see if it solves your issue here.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.