Skip to main content

Installing Halted Updates Through the API

When an update fails the rollout criteria in your System Update Policy, TridentStack Control halts it across your organization: no automated install sends it until the halt is released. You can still install a halted update by hand, but the request has to confirm that you know it is halted.

The halted response​

An install request for a single endpoint that includes a halted update is refused with HTTP 409 and this body:

{
"error": "UPDATE_HALTED",
"code": "UPDATE_HALTED",
"message": "Halted in this organization: KB5000001. Confirm to install anyway.",
"halts": [
{
"id": "6f1c0e1a-2b4d-4e8a-9c3f-0d7b5a1e2f34",
"updateKey": "KB5000001",
"displayName": "2026-10 Cumulative Update for Windows 11 (KB5000001)",
"evidence": { "phaseName": "Pilot", "policyName": "Servers", "failures": 3, "sample": 10 }
}
]
}

Nothing is installed when this response is returned.

Confirming the install​

Send the same request again, unchanged, with one extra field: acknowledgedHaltIds, the id of each halt you accept (up to 100):

{
"acknowledgedHaltIds": ["6f1c0e1a-2b4d-4e8a-9c3f-0d7b5a1e2f34"]
}
  • Only halts that are active in your organization and match the updates in the request are accepted. Any other id is ignored.
  • If a new halt appears between your two requests, the second request is refused again and lists only the new halt. Send every id you have accepted so far.
  • The confirmation applies to this request only. It does not release the halt for automated installs.
  • An update that your organization has blocked is refused with UPDATE_BLOCKED, and confirming a halt does not change that.

Bulk installs​

A bulk install request does not fail when some of its updates are halted. Each endpoint is handled on its own:

  • An endpoint with no halted update installs as usual.
  • An endpoint with any halted update gets nothing from this request, not even its other updates. It is reported as skipped with reason halted.

The response names what was held back:

  • haltsRequiringAcknowledgement: the halts involved, in the same shape as halts above.
  • haltedSelections: one entry per held-back endpoint, with items (every update that was held back for it) and haltedItems (the ones that are halted).

To install everything that was held back, send a new request for each endpoint with its items and acknowledgedHaltIds. To install only the updates that are not halted, send its items without the ones listed in haltedItems, and without acknowledgedHaltIds. Updates your organization has blocked are never part of items.