Usually Windows clients should install the Updates automatically. Since some clients are powered on forever, the Windows way of installation is not working. If e.g. an update requires a reboot, Windows is waiting forever and no more updates are installed on the machine.
For such cases, we found following solution:
We have tested this "Cron Job" at several customers and the user acceptance was good. Nobody likes to install Windows Updates but with this job we found a good balance between security (=installing the Updates) and needling the users. For special users, you can add a Exclude Hardware tag.