Skip to main content

Configure Winget Auto Update

Summary​

The script deploys and configures a self-contained, portable Winget auto-update solution on the endpoint. It is completely independent of any external Winget-AutoUpdate software, using the Configure-WingetAutoUpdate PowerShell script. The solution deploys a portable copy of Winget and its dependencies, writes approval lists (whitelist/blacklist), stores the auto-update policy for auditing, and registers scheduled tasks for system and optionally user context.

Two remote monitors are created to ensure ongoing health:

  • Winget Auto Update Errors – detects runtime failures in the update process. This monitor is only created when the client‑level EDF WAU - MonitorFailures is flagged.
  • Winget Auto Update Configuration Check – verifies that the scheduled tasks and stored configuration are intact and automatically triggers a repair if they are missing. This monitor is created whenever the Winget Auto Update solution is enabled (i.e., the Winget Auto Update EDF is not Disabled and the computer/location is not excluded).

Configuration is driven entirely by client, location, and computer EDFs, which are explained later in this document.

Update Notice: 30‑June‑2026​

If you are updating the solution after 30‑June‑2026, you must run the script once with Set_Environment = 1 to implement the new EDF structure (removal of WAU - NotificationLevel and addition of the Audit Only dropdown option).

Sample Run​

First Run / Environment Setup:
When setting up the solution for the first time, or when upgrading from a version prior to 30‑June‑2026, run the script with the Set_Environment parameter set to 1. This creates the necessary pvl_wau_config table, inserts all required EDFs, adds the new Audit Only option to the Winget Auto Update dropdown, and removes any obsolete EDFs (e.g., WAU - NotificationLevel).

First Run

Regular Execution:
Regular Execution

Uninstall:
Setting Uninstall to 1 removes all scheduled tasks, runtime files, stored configuration, and deletes the remote monitors, including Winget Auto Update Errors.
Uninstall

Force:
The script normally compares the existing configuration with the EDF settings before making changes. Setting Force to 1 skips this comparison and re‑deploys all components, including re‑installing the portable Winget files.
Force

Dependencies​

Global Variables​

NameValueAccepted ValuesDescription
DebugFalseFalse, TrueWhen True, enables informational logging; when False (default), informational logs are suppressed to avoid adding entries to the h_scripts table. Set to True to assist with troubleshooting.
ScriptEngineEnableLoggerFalseFalse, TrueWhen True, enables final (success/failure) logging; when False (default), these logs are suppressed to avoid adding entries to the h_scripts table. Set to True to assist with troubleshooting.

User Parameters​

NameExampleRequiredDescription
Set_Environment1True (for first execution)Run the script with the Set_Environment parameter set to 1 for the first run to create the pvl_wau_config table and EDFs used by the solution. Also required when upgrading from a version prior to 30‑June‑2026 to migrate the EDF structure.
Force1FalseThe script's default nature is to compare the existing configuration before running the installation. Setting the Force to 1 will skip the comparison and re‑deploy all components, including portable Winget files.
Uninstall1FalseRemoves the scheduled tasks, runtime files, stored configuration, and both remote monitors.

Client-Level EDF​

NameExampleTypeDropdown Options / NotesDescription
Winget Auto UpdateEnabled for Servers and WorkstationsDropdown
  • Disabled
  • Enabled for Workstations Only
  • Enabled for Servers and Workstations
  • Audit Only
Set this EDF to enable the Winget Auto Update solution. The Audit Only mode performs application inventory auditing without installing any update schedules.
WAU - WhitelistDitto.Ditto, Greenshot.Greenshot, HeidiSQL.HeidiSQL...TextA comma-separated list of applications to update. By default, all applications are updated unless a whitelist is defined. This list overrides the blacklist. Windows App Runtime packages are unconditionally excluded regardless of this list.
WAU - BlacklistDitto.Ditto, Greenshot.Greenshot, HeidiSQL.HeidiSQL...TextA comma-separated list of applications to exclude. Only one of Whitelist or Blacklist may be used; Whitelist takes precedence if both are supplied. Windows App Runtime packages do not need to be listed here as they are excluded by default.
WAU - InstallUserContextCheck-BoxFlag this EDF to enable auto-update for user-level applications in addition to system-wide ones. Note: End users may see a PowerShell window during the scheduled update.
WAU - UpdateIntervalDailyDropdownDaily · BiDaily · Weekly · BiWeekly · Monthly · NeverSpecifies the frequency of update checks. Default: Daily.
WAU - UpdatesAtTime06AMDropdown12‑hour format with 30‑minute increments (see previous dropdown list)Specifies the time for updates in 12‑hour format. Default: 06AM.
WAU - updatesAtLogonCheck-BoxWhen flagged, the update task also runs at user logon. Can be combined with UpdatesAtTime.
WAU - doNotRunAfterInstallationCheck-BoxFlag to prevent the update runtime from executing immediately after configuration. By default, it runs once after setup.
WAU - MonitorFailuresCheck-BoxFlag to create the Winget Auto Update Errors remote monitor, which alerts on runtime failures.

The deprecated WAU - NotificationLevel EDF has been removed. Notification settings are no longer configurable; the solution operates silently.

Client-Level EDF

Location-Level EDF​

NameTypeSectionDescription
Exclude From Winget Auto UpdateCheck-BoxExclusionsFlag this EDF to exclude the location from the Winget Auto Update solution.

Computer-Level EDF​

NameTypeSectionDescription
Exclude From Winget Auto UpdateCheck-BoxExclusionsFlag this EDF to exclude the computer from the Winget Auto Update solution.

Notes​

Windows App Runtime Exclusion​

The underlying Configure-WingetAutoUpdate script unconditionally excludes Windows App Runtime packages (Microsoft.WindowsAppRuntime*) from updates. This exclusion is hardcoded into the update runtime and applies before any approval lists (whitelist or blacklist) are evaluated.

  • You do not need to add these packages to the WAU - Blacklist EDF.
  • They will not be updated even if explicitly listed in the WAU - Whitelist EDF.
  • This prevents the accumulation of side-by-side framework builds, as these are shared runtime components rather than standalone applications.
  • The companion Get-WingetReport audit script mirrors this behaviour and will always report these packages with auto-update disabled.

Output​

Scheduled Tasks​

Two tasks are created under the \WAU\ path:

Task NameContextDescription
Winget-AutoUpdateSYSTEMRuns the update runtime on the defined schedule (and optionally at logon).
Winget-AutoUpdate-UserContextUserCreated only if WAU - InstallUserContext is flagged. Runs after the system task finishes.

Note: The legacy Winget-AutoUpdate-Notify and Winget-AutoUpdate-Policies tasks are no longer used. They are automatically removed when the new solution is deployed.

Files​

PathDescription
C:\ProgramData\_Automation\App\Winget\Portable Winget and its dependencies.
C:\ProgramData\_Automation\Script\Winget-AutoUpdate\Runtime script (Winget-UpdateApproved.ps1), silent launcher (SilentLauncher.exe), approval lists (included_apps.txt / excluded_apps.txt), and runtime logs.
C:\ProgramData\_Automation\Script\Winget-AutoUpdate\Winget-UpdateApproved-error.txtError log generated by the update runtime. Cleared at the start of each run.
C:\ProgramData\_Automation\Script\Winget-AutoUpdate\Winget-UpdateApproved-log.txtInformational log from the update runtime.

Remote Monitors​

Monitor NameTriggerBehavior
Winget Auto Update ErrorsChecks for existence of the runtime error log. If present and recently written, it raises an alert with the failure details.Created when WAU - MonitorFailures is flagged.
Winget Auto Update Configuration CheckValidates that the scheduled tasks exist (1–2 tasks) and the stored configuration table is present. If either fails, it returns "Force", which triggers a re‑run of the solution with the -Force parameter to repair the configuration.Always created when the solution is enabled, regardless of other EDFs. This monitor runs every hour.

Changelog​

2026-09-10​

  • Enhanced the Implementation PowerShell script.
  • Added documentation notes regarding the unconditional exclusion of Windows App Runtime packages (Microsoft.WindowsAppRuntime*) by the underlying PowerShell script.

2026-09-03​

  • Fixed error validation remote monitor creation logic.

2026-07-01​

  • Replaced the legacy Romanitho Winget-AutoUpdate software with an independent, portable Winget solution using the Configure-WingetAutoUpdate PowerShell script.
  • Removed the WAU - NotificationLevel EDF and all related notification settings.
  • Added the Audit Only option to the Winget Auto Update EDF dropdown.
  • Introduced a new remote monitor Winget Auto Update Configuration Check to automatically detect and repair missing configurations.
  • Updated all file paths, scheduled tasks, and monitor logic to reflect the new architecture.
  • Cleaned up obsolete EDFs and database columns (e.g., notification column in pvl_wau_config).

2025-04-10​

  • Fixed the script where it was exiting with Success status when it failed because it wasn't able to download the ps1 file

2025-04-08​

  • Initial version of the document