Microsoft 365 Apps, in both the "for business" and "for enterprise" editions, updates through Microsoft's Click-to-Run service rather than a standalone installer. When Automox updates Microsoft 365 Apps, it triggers the device's own Click-to-Run client (OfficeC2RClient.exe) to pull the latest build for the configured update channel. Choosing the right policy comes down to understanding that difference. This article explains which policy to use and how to keep the updates reliable.
Applies to
- Windows devices running Microsoft 365 Apps for business or for enterprise (Click-to-Run).
- Administrators deciding how to keep Microsoft 365 Apps updated with Automox.
Use a third-party patch policy, not a first-party one
Automox treats Microsoft 365 Apps as a third-party application title. Include it in your third-party patch policy so that Automox triggers Click-to-Run to bring Office to the latest build on its channel.
A first-party (Windows Update) patch policy is not a reliable way to update Click-to-Run Office. First-party policies depend entirely on the Windows Update API to report what a device needs. Click-to-Run builds are delivered from the Office content delivery network based on the update channel, so Windows Update usually does not report them as needed. When that happens, a first-party policy skips Microsoft 365 Apps with no error and no failure, which can look like a missed patch.
Keep the two different "Office" update types straight:
- Microsoft 365 Apps (Click-to-Run): updated by your third-party patch policy through Click-to-Run.
- MSI-based Office (for example, "Security Update for Microsoft Office 2016 (KB...)"): delivered through Windows Update and handled by your first-party patch policy.
A device typically has one or the other, so confirm which type is installed before deciding which policy should cover it.
Keep the update channel consistent
Click-to-Run only applies builds that match the update channel configured on the device. If another management tool sets a different channel than the one the installed build belongs to (Intune Cloud Update, Group Policy, the Office Deployment Tool, Microsoft Configuration Manager, or the Microsoft 365 admin center), updates can conflict and time out. For Microsoft 365 Apps for business the channel is often left at the default and managed from the Microsoft 365 admin center, so make sure it matches everywhere. See Microsoft Office 365 not updating due to update channel conflict (Windows) for the channel list and how to resolve a mismatch.
Make sure Office can be updated during the window
Click-to-Run cannot replace files that are in use, so open Office applications are a common reason an update does not complete. Schedule the policy for a window when Office is likely closed, or otherwise plan for the apps to be closed during the run. For how Automox handles applications that are open or in an active call, see How Automox Sources and Updates Third-Party Applications.
How to read the results
After the policy runs, verify Microsoft 365 Apps from Manage → Software using the Impacted filter, or on the device page under Details → Software by comparing the Installed Version to the Available Version.
If a Microsoft 365 Apps update reports as failed but the device is actually already at the latest build for its channel, that can be a reporting mismatch rather than a real failure. Click-to-Run reports that Office is already current, and the policy records the attempt as failed. Confirm the installed versus available version on the device before treating it as a genuine failure, and contact Automox Support if a device that is genuinely behind keeps reporting failures.
When you need more control
For environments that need to force Office to the latest build on demand, or to enforce a specific update channel across the fleet, Automox offers Worklets that drive Click-to-Run directly and that pin the channel in the registry. Use these alongside your patch policy when scheduling alone is not enough.