The manual process would be to convert the template to a VM power it up and patch following your organizations process for patching
Convert the template as a VM assign a temporary IP and follow the standard process for patching the normal guest OS VM's
It can be scripted but would be rather extensive. IE convert to vm poweron assign ip, if not DHCP, initiate MS update push, initiate 3party push, then power down, and convert back to template. It would be a homegrown script, completely variable based on your environment. There was and may still exist a 3rd party product to manage this. Shavlik, I believe, but I haven't done it so I wouldn't know for sure.