Download Windows Updates
Use the Download Updates feature to gather and maintain Windows updates with ease.
The Download Updates feature helps you gather and maintain Windows updates with ease and reliability. Access it via the toolbar under Start → Tools, or the Updates page → Add → Latest online updates.
This guide covers downloading and maintaining the update files themselves. For slipstreaming them into an image - queue analysis, extraction caching and parallelism, and update store cleanup - see the Integrate Windows Updates guide.
Key Features
- Downloads the latest updates directly from Microsoft servers
- Verifies downloaded update file hashes
- Resumes interrupted downloads
- Organizes downloaded updates per Windows version
- Labels updates to help with pre-selection of recommended ones
- Multi-threaded download and hashing
Update lists are manually curated and usually updated within a few hours of release. While lists come from the NTLite server, actual updates are downloaded only from Microsoft's servers.
Supported Windows Versions
Client editions with amd64 and x86 architectures (ARM64 on Win11 24H2+):
Windows 11
- 26H2 (11.0.26300)
- 26H1 (11.0.28000)
- 25H2 (11.0.26200)
- 24H2 (11.0.26100) - Server 2025 has a list of its own
- 23H2 (10.0.22631)
- 22H2 (10.0.22621)
- 21H2 (10.0.22000)
Windows 10
- 22H2 (10.0.19045)
- 21H2 (10.0.19044) - October 2021 Update
- 21H1 (10.0.19043) - May 2021 Update
- 2009/20H2 (10.0.19042) - includes Server 20H2
- 2004/20H1 (10.0.19041) - includes Server 2004
- 1809 (10.0.17763) - includes LTSC 2019 and Server 2019
- 1607 (10.0.14393) - includes LTSB 2016 and Server 2016
Older Versions
- Windows 8.1 - includes Server 2012 R2
- Windows 7 SP1 - includes Server 2008 R2 (extended support optional)
Update Cache
Before using the Downloader, set your preferred download location under Menu → Settings → Update cache (Downloads).
Releases on the same servicing base share one cache folder, so a cumulative update is stored once however many releases it serves - Windows 11 24H2, 25H2 and 26H2 all use 11.26100.x64 (or .arm64). Files left in an older per-release folder are still read, and show up for cleanup as duplicates.
You can use subfolders to organize updates. Update files can be renamed and are still properly detected.
Choosing Updates
Pick the Windows version and the platform (x64, x86 or ARM64) at the top. The loaded image's entry is tagged (Loaded) and this PC's (Host); with an image loaded, only its own release is offered. The list is split into groups, each with a tick box for the whole group:
- Feature Update - enablement packages, first because they decide which release the rest of the list is for.
- Cumulative Update - one group for Windows, one for .NET Framework.
- API & Runtime, Command-Line Utilities, Services & Platform.
- Security - Defender definitions and the Windows Security app update.
- Setup & Boot - Safe OS and setup dynamic updates, and the Out of Box Experience update.
- Other, then Superseded and Unlisted - cached files no longer on the list, or never on it.
Feature Upgrades
Ticking an enablement package moves the target to its release: the Cumulative Update group renames itself, and rows the new release does not use grey out while keeping their ticks, so unticking it again restores the list. Enablement packages at or below the image's own release are not shown. On LTSC a warning explains that an enablement package breaks future servicing there.
Security or Optional
When a group holds more than one cumulative update - a month's security release and its optional preview, say - the rows become a choice of one. Whether you took the security or the optional release is remembered for the next month. Hold Ctrl to tick a second cumulative update alongside the first. On 24H2 and later images that still need the checkpoint cumulative update, it is ticked along with the latest one automatically.
Show Filter
The Show drop-down beside the search box narrows the list to All, Not installed (offered with an image loaded) or Downloaded. The Installed and Downloaded columns carry an icon each; hover it for the word.
Operations
Verify
Verify hash-checks the Update Cache folder to detect incomplete downloads and corrupted files. It re-scans in the background each time the downloader opens, so pre-existing updates are covered without starting it by hand. Only updates from the online list support verification.
Enqueue
Adds updates to the Updates → Integration Queue for integration to the loaded image. First load a target on the Image page to enable this. Non-existing updates will be automatically downloaded before integration when Apply → Process starts. Enqueueing an update whose cached file failed verification asks first, since it will be downloaded again during integration.
Download
Pre-downloads selected non-existing updates without integrating them.
Delete
The Delete group on the toolbar clears the update cache, each button showing how many files it would remove:
- Unlisted - files no update list knows.
- Superseded Premium - updates a newer one has replaced.
- Duplicates Premium - extra copies, keeping one of each update.
The counts cover the caches of every Windows version, not only the one on screen. To remove single files instead, right-click a row in the Superseded or Unlisted group and choose Delete. A listed update with extra copies carries a folded Duplicates part listing each copy's path, and Delete there removes only the copies.
Offline Mode
When no update list can be fetched, the dialog reads Offline and assembles the list from the updates already in the cache, sorted into the same groups, so you can still enqueue what you have. A refresh button retries the online list.
Row States
The Downloaded column's icon says what is known about the file behind a row:
- Available - listed, not in the cache yet.
- Downloading - in progress, with the bar in the Update cache column.
- Downloaded - in the cache, and checked against its expected hash where one exists.
- Not verified - in the cache, not yet read against its expected hash.
- Incomplete - a partial or corrupted file. The row stays selectable so it can be downloaded again.
With an image loaded, the Installed column marks the updates the image already has, and those already queued. Installed rows are greyed out and locked, so a queue cannot be filled with updates that would do nothing. This covers both hotfixes matched by identity and MSIX packages whose provisioned version on the image is already the same or newer. Cumulative updates are the exception - an already-integrated cumulative stays unlocked, since re-applying one is a legitimate manual call.
Interrupted Downloads
A download that breaks part-way is resumed rather than restarted, including across sessions - closing NTLite mid-download and coming back later continues where it stopped, with no repeat of what already arrived. Short network drops heal silently, and only a link that stays down raises a prompt.
That prompt appears once per download batch, not once per file: several updates downloading in parallel usually break together, so the answer given to the first one applies to its siblings - Retry resumes them all, Cancel stops them all.
Integrating the latest cumulative update is also the prerequisite for the Secure Boot 2023 certificate deployment - once the image carries it, the Updates page Secure Boot tab can stage the certificate offline. See the Secure Boot 2023 Migration guide.