Without a 3rd party product, or script that you write yourself, you can't selectively automatically approve updates as both are within the same category and product.
Server CU:
| This update will automatically sync with Windows Server Update Services (WSUS) if you configure Products and Classifications as follows: Product: Microsoft Server operating system-24H2 Classification: Security Updates | |
|---|---|
| This update will automatically sync with Windows Server Update Services (WSUS) if you configure Products and Classifications as follows: Product: Microsoft Server operating system-24H2 Classification: Security Updates |
.NET CU:
This update will automatically sync with WSUS if you configure as follows: Product: Windows 11, version 25H2 and Microsoft server operating system 24H2 Classification: Security Updates
At AJ Tek we're currently in beta testing of a new product called Approvals which will allow you fine-grained control over approvals with the ability to even create a ring-based approach to approving updates to mimic Intune and WUfB's ring-based approach. With Approvals, this would be easy - add the approval rule and then exclude the title that includes anything other than "Cumulative Update for Microsoft server operating system version 24H2 for x64-based systems". Expected date of GA release: October/November 2026.