I'm currently attempting to make our server patching more automated. We're already using WSUS and it is working well, but at the moment we have it set to notify for download and notify for install ...
I remember having this problem when Server 2012 R2 had just come out, but after searching online, I managed to solve it through some magical combination of GPO settings. Now we have a few Server 2016 ...