Inheriting an unmanaged Windows fleet is common in Indian mid-market companies that grew faster than their IT function did — laptops purchased at different times, imaged inconsistently or not at all, and patched whenever an individual user happened to click 'update now'. The instinct is to push a mandatory update to everything at once, and that instinct is what causes an outage rather than fixing one.
Start with inventory before touching anything, because you cannot patch what you cannot see. A tool that reports current patch level, installed software and last check-in time across every device gives you the actual starting point rather than an assumption. It will usually reveal a wider spread of patch levels than anyone expected, and some machines that haven't checked in for months at all.
Ring-based rollout is what prevents an update from breaking the whole company at once. Patch a small group first — IT's own machines, a handful of volunteers — wait a few days, then expand to the rest in stages. A bad patch that breaks a driver or a line-of-business application is contained to a handful of people rather than the entire fleet, and it's caught before it reaches anyone whose work genuinely can't tolerate downtime.
Set a maintenance window and stick to it rather than patching whenever a user happens to be connected. Predictable patching — every second Tuesday evening, say — means users can plan around it, and IT can be watching when updates deploy rather than discovering a failed patch three days later from a support ticket. The goal isn't a perfectly patched fleet on day one, it's a fleet that gets there within a quarter and stays there without manual intervention every time.