I would offer two possible approaches, but both involve the same fundamental setup.
Step 1: Create a WSUS Target Group designed to hold machines with new OS installations. Approve ALL current and valid OS updates for this target group.
From there, you have two approaches, one requires the Extension Pack, the other is applicable to any native WSUS environment.
Option 1: Using the Extension Pack, the Update Management Wizard can be used to "Install all approved/needed updates". You may need to run this tool with two or three passes to account for exclusive updates that may also be required.
Option 2: Assign expired deadlines to the WSUS Target Group you created so that all updates approved for that group are expired. Initiate a detection on the client system, and then sit back and watch for the next few hours. Workign through the entire list of approved updates, the client system should complete installation of all updates, including exclusive updates with additional system restarts, in 2-3 hours time.