Free tools Windows power users keep installed
One-click scans. No signup required.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Microsoft Baseline Security Analyzer (MBSA) was a free Microsoft Windows tool that checked for missing security updates and selected security misconfigurations. It is now deprecated, no longer developed, and not a reliable security or compliance solution for Windows 10, Windows 11, or current Windows Server releases.
What does MBSA stand for?
MBSA stands for Microsoft Baseline Security Analyzer. The word “baseline” refers to comparing a computer with expected security-update and configuration conditions.
MBSA was not an antivirus program, endpoint-detection platform, penetration-testing tool, or complete vulnerability-management system. It was primarily a legacy Microsoft security-assessment utility for checking patch status and a limited set of configuration settings.
What did MBSA do?
MBSA had two main functions:
- Missing-update detection: It checked whether required Microsoft security updates were installed.
- Security-configuration checks: It examined selected settings in Windows and some Microsoft products.
Historical coverage included Windows, Internet Information Services (IIS), SQL Server, Internet Explorer, and Microsoft Office. The exact checks depended on the MBSA release and the product versions being assessed. The rules were fixed and reflected older Microsoft security guidance rather than a continuously maintained modern baseline.
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
MBSA offered both a graphical interface and command-line operation. Administrators could use it for local checks or, with the necessary network and administrative prerequisites, scan remote computers. It was especially useful to small organizations and administrators managing standalone systems without Windows Server Update Services (WSUS) or Configuration Manager.
How MBSA checked for missing updates
An online MBSA scan could use Microsoft update services to determine whether applicable security updates were missing. For systems that could not connect directly to Microsoft Update, MBSA also supported an offline method based on the Microsoft-signed Wsusscn2.cab catalog.
Wsusscn2.cab contained metadata about Microsoft security updates, update rollups, and service packs. It did not contain the update files themselves. A scan could identify updates that appeared to be required, but an administrator still had to obtain and install those updates through an approved process.
Recommended Free Tools
This distinction matters: MBSA was a detection and reporting tool, not an automatic patch-deployment system. Microsoft’s historical patch-detection guidance discussed MBSA alongside Windows Update, Microsoft Update, WSUS, and Configuration Manager; those products and services had different roles in the broader update process. See Microsoft’s update detection and deployment guidance.
What was the final MBSA version?
The final commonly documented release was MBSA 2.3, archived as build 2.3.2211. Its documented additions included Windows 8.1, Windows 8, Windows Server 2012, and Windows Server 2012 R2.
That version history should not be confused with current support. The archived download record is a historical copy of Microsoft’s former Download Center page, and it notes that the original Microsoft download was deleted. An archived installer is not the same thing as a current, supported Microsoft download channel.
For the release history and archived product details, see the archived MBSA 2.3 record.
Is MBSA supported on Windows 10 or Windows 11?
No—not as a current supported security-assessment solution. Microsoft states that MBSA 2.3 was not updated for full support of Windows 10 or Windows Server 2016. Windows 11 is newer still, so old MBSA documentation should not be treated as Windows 11 support guidance.
That does not necessarily mean the old program will fail to launch on every modern installation. The important practical point is that it is deprecated, not maintained for current Windows versions, and unsuitable as evidence of present-day security or patch compliance.
Rank #2
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
Microsoft’s MBSA removal and guidance article explains the product’s current status and limitations.
Why was MBSA retired?
Microsoft gives two central reasons:
- MBSA’s additional configuration checks had not been actively maintained since the Windows XP and Windows Server 2003 era.
- Later Windows and Microsoft product changes made some old checks obsolete, while some recommendations could become counterproductive on newer systems.
A scan can therefore produce results that look authoritative but are based on outdated assumptions. A clean report also does not prove that a modern computer is secure. It does not provide current asset discovery, comprehensive vulnerability correlation, exploit prioritization, third-party software coverage, or continuous reassessment.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWhy old offline-scan instructions may fail
Readers following old MBSA tutorials may encounter the error:
“The catalog file is damaged or an invalid catalog.”
Microsoft says that beginning with the August 2020 catalog, Wsusscn2.cab was signed with SHA-256 only rather than being dual-signed with SHA-1 and SHA-256. Older MBSA installations may not handle that signing change correctly.
This is a major reason not to treat MBSA as a dependable current offline scanner. Do not work around the error by trusting an unverified catalog or an unofficial installer. For legitimate offline update assessment, Microsoft now documents a Windows Update Agent method that uses the current signed catalog.
What should replace MBSA?
There is no single one-for-one replacement because MBSA combined two different tasks: update detection and configuration checking. Choose the replacement based on the result you need.
| Need | Better current direction |
|---|---|
| Microsoft security configuration baselines | Microsoft Security Compliance Toolkit |
| Offline Microsoft update detection | Windows Update Agent with Wsusscn2.cab |
| Continuous Microsoft endpoint vulnerability management | Microsoft Defender Vulnerability Management |
| CIS configuration compliance | CIS-CAT Lite or CIS-CAT Pro |
| Broad, multi-vendor vulnerability management | A currently supported enterprise vulnerability-management platform selected for the organization’s required operating-system, application, cloud, and reporting coverage |
For Microsoft security baselines: Security Compliance Toolkit
The Microsoft Security Compliance Toolkit (SCT) is Microsoft’s current direction for recommended configuration baselines. It provides baseline packages and utilities for analyzing, comparing, editing, testing, storing, and applying security configurations.
The toolkit includes tools such as Policy Analyzer and LGPO. Administrators can compare existing Group Policy Objects with Microsoft’s recommended settings, review differences, document exceptions, test changes, and deploy policies through Active Directory Group Policy, local policy, or endpoint-management software.
Rank #3
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
The current download page lists baseline material for products including Windows 10, Windows 11, Windows Server 2016 through 2025, Microsoft Edge, and Microsoft 365 Apps. Baselines are not universal hardening instructions: read the documentation, assess application compatibility, and test them before deployment.
For offline update detection: Windows Update Agent
For an air-gapped or restricted computer, Microsoft documents using Windows Update Agent’s AddScanPackageService method with Wsusscn2.cab:
- Obtain the current Microsoft-signed
Wsusscn2.cabfile. - Transfer it to the offline computer or controlled scanning environment.
- Use Windows Update Agent to add the catalog as an offline scan package.
- Search the catalog and record updates reported as missing or required.
- Transfer or deploy the actual update packages separately.
- Install the updates through the organization’s approved process.
- Rescan after installation.
Microsoft’s sample scripts demonstrate the API but are explicitly examples rather than supported production software. Organizations should validate, secure, log, and operationalize any implementation before relying on it.
For continuous vulnerability management: Defender Vulnerability Management
Microsoft Defender Vulnerability Management is aimed at organizations that need continuous vulnerability prioritization, asset context, security recommendations, remediation workflows, and security-baseline assessment. It is a more appropriate category of tool than MBSA for organizations already using Microsoft Defender for Endpoint and requiring ongoing vulnerability operations.
It may be excessive for a home user or a small team that only needs a one-time Microsoft patch check. Microsoft’s product page provides current plan information; no numeric price is stated here because licensing depends on the applicable plan and commercial arrangement.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →For CIS configuration compliance: CIS-CAT
CIS-CAT Lite is a free, limited configuration-assessment option for supported technologies and CIS Benchmarks. It can suit learners, small teams, and organizations seeking a basic CIS-aligned check.
CIS-CAT Pro Assessor provides broader CIS Benchmark assessment and reporting capabilities through CIS SecureSuite membership. It is a better fit when an organization needs formal CIS conformance workflows, remediation content, tailored benchmarks, or broader reporting. CIS-CAT Pro should not be described as free; membership and access terms should be checked on the official CIS page.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.MBSA versus other security tools
| Tool category | Primary question answered | How MBSA compares |
|---|---|---|
| Patch scanner | Which applicable updates appear to be missing? | This was MBSA’s strongest historical function, but its current coverage and support are outdated. |
| Configuration-baseline tool | Does policy match a documented security configuration? | MBSA performed limited historical checks; SCT is the current Microsoft baseline direction. |
| Endpoint security platform | Is the device protected, monitored, and responding to threats? | MBSA was not antivirus, EDR, or a response platform. |
| Vulnerability-management platform | Which assets and vulnerabilities require prioritized remediation? | MBSA lacked modern continuous inventory, risk context, and remediation workflows. |
| Compliance benchmark scanner | Does a system conform to a framework such as a CIS Benchmark? | MBSA was not a current CIS, DISA STIG, PCI DSS, or similar compliance assessor. |
Should you download MBSA today?
Generally, no. Do not install an archived MBSA copy on a current Windows system simply because an old tutorial recommends it.
There are narrow exceptions. MBSA may be relevant when reproducing a historical audit, teaching legacy Microsoft patch-management concepts, investigating old scan results, or assessing an isolated legacy system whose software environment cannot change. In those cases, use a controlled system, verify the installer’s provenance and integrity, and label all results as historical or best-effort.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #4
- Runs UniFi Network for full-stack network management
- Manages 30+ UniFi Network devices and 300+ clients
- 1 Gbps routing with IDS/IPS
- Multi-WAN load balancing
- 0.96" LCM status display
Do not use MBSA output as proof that a current system is secure. For modern work, separate the problem into patch detection, configuration baselining, and vulnerability management, then select a supported tool for each requirement.
For students and readers encountering MBSA in old documentation
If a certification guide or older administrator manual mentions MBSA, remember the historical definition: it was Microsoft’s free analyzer for missing updates and selected Windows and Microsoft-product security settings. The exam or document may be describing the Microsoft patch-management ecosystem of its time.
For real systems, check the operating-system version, the date of the documentation, and whether the recommended tool is still supported. The existence of MBSA 2.3 as the final release does not make it suitable for Windows 11 or current compliance decisions.
Frequently Asked Questions
Is MBSA an antivirus program?
No. MBSA checked missing Microsoft updates and selected security settings; it did not provide antivirus, endpoint detection, threat monitoring, or incident response.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Does MBSA install missing updates?
No. It reported update status. Missing update packages had to be obtained and installed separately.
What is Wsusscn2.cab?
It is a Microsoft-signed offline update catalog containing update metadata, not the actual update files.
Can MBSA check third-party software?
Not as a modern third-party vulnerability-management platform. Its historical focus was Windows and selected Microsoft products.
Why does MBSA say the catalog is damaged or invalid?
Older MBSA versions may reject catalogs signed SHA-256 only, a signing change Microsoft introduced beginning with the August 2020 catalog.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

