<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Windows Update - automatic policy without manual address definition in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/windows-update-automatic-policy-without-manual-address/m-p/1247424#M6654</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;is there a way on Palo Alto firewalls to allow &lt;STRONG&gt;Windows Update&lt;/STRONG&gt; traffic without manually defining a list of addresses?&lt;/P&gt;&lt;P&gt;For example, is it possible to create a policy that &lt;STRONG&gt;automatically determines or updates the list of these addresses&lt;/STRONG&gt;, without requiring manual administrator intervention?&lt;/P&gt;&lt;P&gt;I would appreciate any information on whether such solutions exist at all.&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
    <pubDate>Wed, 04 Feb 2026 11:54:50 GMT</pubDate>
    <dc:creator>jakub.kuchniak</dc:creator>
    <dc:date>2026-02-04T11:54:50Z</dc:date>
    <item>
      <title>Windows Update - automatic policy without manual address definition</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/windows-update-automatic-policy-without-manual-address/m-p/1247424#M6654</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;is there a way on Palo Alto firewalls to allow &lt;STRONG&gt;Windows Update&lt;/STRONG&gt; traffic without manually defining a list of addresses?&lt;/P&gt;&lt;P&gt;For example, is it possible to create a policy that &lt;STRONG&gt;automatically determines or updates the list of these addresses&lt;/STRONG&gt;, without requiring manual administrator intervention?&lt;/P&gt;&lt;P&gt;I would appreciate any information on whether such solutions exist at all.&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Wed, 04 Feb 2026 11:54:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/windows-update-automatic-policy-without-manual-address/m-p/1247424#M6654</guid>
      <dc:creator>jakub.kuchniak</dc:creator>
      <dc:date>2026-02-04T11:54:50Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Update - automatic policy without manual address definition</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/windows-update-automatic-policy-without-manual-address/m-p/1247464#M6659</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/976453629"&gt;@jakub.kuchniak&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for post!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could try to create a security policy with app-id: "&lt;STRONG&gt;ms-update&lt;/STRONG&gt;" to allow windows updates.&lt;/P&gt;
&lt;P&gt;For reference, here are KB articles with instructions to allow allow Microsoft updates:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHXCA0" target="_self"&gt;How to Block Web Browsing while Allowing Microsoft Updates&lt;/A&gt;&amp;nbsp;and to block them:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClbvCAC" target="_self"&gt;How to block a Windows update&lt;/A&gt;&amp;nbsp;(You can get required URLs from article to use them to allow traffic).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Wed, 04 Feb 2026 23:32:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/windows-update-automatic-policy-without-manual-address/m-p/1247464#M6659</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2026-02-04T23:32:14Z</dc:date>
    </item>
  </channel>
</rss>

