Windows Updates on Managed Computers: Why “Last Checked” Looks Out of Date
If you've opened Settings → Windows Update on your work computer and noticed the "Last checked" time reads days, weeks, or even months ago, you're not alone — a few of you have written in recently asking exactly that. It's a completely fair question: at first glance, that screen makes it look like your computer isn't receiving updates at all. Rest assured, it is.
Why "Last checked" looks out of date
On a typical home PC, Windows checks for updates by itself and stamps the "Last checked" time whenever it does. Your work computer is different: updates are handled centrally through our remote monitoring and management (RMM) platform, NinjaOne — the "NinjaRMMAgent" you may recognize from our managed software list.
Here's the technical reason for the old date. The "Last checked" field only updates when Windows Update itself runs a check — either because someone clicked the Check for updates button or because Windows' own automatic check ran. Our management agent doesn't go through that screen: it scans for and installs updates using the Windows Update Agent API, Microsoft's official programming interface for update management. Checks made through that channel never touch the timestamp — NinjaOne's own documentation confirms it cannot update that date, because the field reflects only checks run by Windows Update directly.
There's a second, deliberate part to this: on managed computers we turn down Windows' own automatic update checking. If Windows fetched and installed updates on its own, it would work against our patching schedule — updates could land before we've tested them, and surprise restarts could interrupt your workday. So Windows' built-in checker stays quiet, our agent does the real work through the API channel, and nothing is left running that refreshes the "Last checked" stamp. The result is a date that drifts further and further into the past while updates quietly continue on schedule.
So is my computer actually getting updates? Yes.
Every managed computer continuously reports back to our management platform: which updates it needs, which were installed and when, and whether anything failed. We review this patch data across the entire fleet — if a computer falls behind, it's flagged on our dashboard and we investigate, usually before anyone at your office would notice a thing. There is nothing you need to click or check for this to work.
How and when updates are applied
Critical security updates — applied as needed
When Microsoft releases a fix for a serious, actively exploited, or high-risk vulnerability, we don't wait. Critical security updates are validated and pushed to managed computers as needed, outside the normal monthly cycle.
Everything else — the 25th of each month
Non-critical security updates, feature enhancements, and all remaining updates — the ones that typically require a system restart — are applied during our dedicated patching window on the 25th of each month, regardless of which day of the week that falls on. Before the window opens, each month's updates are tested and validated against our standard hardware deployments and core applications, so a problematic patch gets caught in testing instead of on your computer.
Can I check for updates myself?
Yes — the Check for updates button still works normally, and clicking it will refresh that "Last checked" time. We recommend against it, though. A manual check asks Microsoft directly for everything currently on offer — including updates we haven't yet finished testing and validating against our hardware deployments and core applications. Installing updates ahead of the schedule can occasionally pull in a problem patch before we've had a chance to screen it, and may prompt a restart in the middle of your workday. Letting the schedule do its job is the safer path.
If Windows shows you an update prompt you're unsure about, or anything on the update screen concerns you, we're glad to take a look — just email [email protected].