

I’ll explain slow. MS offers a native way to manage updates, both for servers and workstations. It’s called Windows Server Update Services (WSUS).
Assuming you have your shit together as a Windows admin, you’re running the infrastructure on Active Directory (AD). WSUS is how you control and roll out Window’s updates in an AD environment.
No surprises, no bullshit. Roll updates however it works for your org.
Questions?
What if the pass is only temporarily stored in a db table, then instantly hashed and dropped? Obviously, I’m no db admin. :(