Ubuntu security updates using azure update manager best practices for enterprise

What are the best practice to follow for security updates for ubuntu in an enterprise using azure update manager. Should the infra team install all the recommended updates from azure update manager or will will cause chaos and the application will go down.