we have hundred of servers and a patch round takes weeks. So the time when I start to install updated an I reach the end, other updates a released. Is there a way to create an update-set to get sure all servers have the same and not the latest updates installed?
I would recommend that you utilize the ‘Update Date Filtering’ setting under ‘Tools > Settings > Windows Update.’ The setting allows you to “only install updates that were published / approved at least X days ago.” I think this will give you what you need. For example, if you set it to 30, then it will only install updates that were published or approved at least 30 days ago. Any updates released in the past 30 days will be skipped.