You assigned a feature update policy, yet days later devices are still on the old version with nothing waiting in Windows Update. These policies depend on licensing, device identity, telemetry, other update settings and Microsoft's own safeguards. In this post I'll give you a checklist to work through in order, show how to read the report states, and confirm the fix on the device.
Symptoms#
- Settings › Windows Update on the device never shows the targeted Windows 11 version.
- The Windows Feature Update Report shows the device stuck in a state such as Pending: Validation, On Hold: Deferred or Canceled: Not Supported, or doesn't list it at all.
- Update rings report Succeeded, so nothing looks wrong on the policy side.
Why it happens#
Intune stores the policy and passes it to the Windows Autopatch service, which decides what each device is approved to receive; the device gets the offer when it scans Windows Update. Deferrals, deadlines and restarts still come from update rings. If Windows Update can't identify the device, the device scans somewhere else, a deferral interferes, the hardware isn't eligible or a safeguard hold applies, no offer arrives.
How to fix it#
1. Read the report first#
Go to Reports › Windows updates, open the Reports tab, select Windows Feature Update Report, pick the profile and select Generate report. The state tells you where to look:
| State | What it means | Check |
|---|---|---|
| Pending: Validation | Windows Update can't validate the device for the offer | Steps 2 and 3 |
| Canceled: Not Supported | Windows Update can't match the device to a valid Microsoft Entra device | Step 2 |
| On Hold: Deferred | A Windows Update client policy on the device is deferring the update | Step 4 |
| Scheduled | Rollout options set a later start date | Nothing, if intended |
2. Confirm the device and tenant qualify#
- The device is Intune-managed and Microsoft Entra joined or Microsoft Entra hybrid joined;
dsregcmd /statusconfirms the join. - The edition is Pro, Pro Education, Enterprise or Education. Enterprise LTSC isn't supported; use update rings there.
- The tenant has Microsoft Intune Plan 1 plus a Windows license that includes the Windows Autopatch entitlement.
- The device can reach the Intune, Windows Update and Windows Autopatch endpoints.
3. Check telemetry and the sign-in assistant#
- Windows diagnostic data must be at least Required (older policy labels call it Basic), set through a device restrictions profile, the settings catalog or Group Policy.
- The Microsoft Account Sign-In Assistant service (
wlidsvc) must not be disabled. A device restrictions profile that blocks the Microsoft Account sign-in assistant stops feature updates from being offered, so set it to Not configured. - For full report data, go to Tenant administration › Connectors and tokens › Windows data and turn on Enable features that require Windows diagnostic data in processor configuration, which is off by default.
4. Remove update ring roadblocks#
- In every update ring that targets the device, set Feature update deferral period (days) to 0 and make sure feature updates aren't paused.
- Look for a target version (
TargetReleaseVersion,ProductVersion) set in the settings catalog or Group Policy that pins the device to another release. - If a device is in several feature update policies, Windows Update offers the newest applicable version.
5. Rule out WSUS, Group Policy and Configuration Manager#
- If a GPO points the device at WSUS, Windows 11 takes all updates from WSUS unless the scan source policy says otherwise: Specify source service for specific classes of Windows Updates in Group Policy, or all four
Update/SetPolicyDrivenUpdateSourceFor...CSP settings. Dual Scan isn't supported on Windows 11. - On co-managed devices, move the Windows Update policies workload to Intune (or Pilot Intune) and set the Configuration Manager client setting for software updates to No.
MDMWinsOverGPdoesn't cover the Update policy CSP, so remove conflicting update GPOs instead of relying on it.
6. Check hardware readiness#
Windows 10 devices that don't meet the Windows 11 requirements, such as TPM 2.0 and a supported processor, won't install it and stay on their current version. On the same Reports tab, generate the Windows Feature Update Device Readiness Report for your target version. Replace device means the hardware can't upgrade; the system requirement, app and driver issue columns explain the rest. This report also needs the license confirmation toggle on the Windows data page.
7. Look for a safeguard hold#
Microsoft holds an update back from devices with a known compatibility issue until it's fixed. On the device, GStatus under HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Appraiser\GWX is 0 while a hold applies and 2 when none does. The 8-digit hold ID is in GatedBlockId under ...\AppCompatFlags\TargetVersionUpgradeExperienceIndicators, in the subkey for the target version; search for it in Windows release health. Opting out with Update/DisableWUfBSafeguards is meant for validation, not production. If a hold should be long gone, check whether TLS inspection intercepts adl.windows.com, which can leave an outdated hold in place.
Watch out: Feature update policies don't apply during Autopilot OOBE; they start at the first Windows Update scan afterwards. And a device removed from its feature update policy stays enrolled in Autopatch and gets no feature update until it's assigned a new policy.
Verify the fix#
On the device, open Settings › Windows Update › Advanced options › Configured update policies; the policy type should be Mobile Device Management, not Group Policy. Then check the details from an elevated PowerShell window:
# Update policy delivered by Intune
Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\PolicyManager\current\device\Update' -ErrorAction SilentlyContinue
# Update policy delivered by Group Policy: look for a WSUS server address or a target version
Get-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate' -ErrorAction SilentlyContinue
# Safeguard hold: 0 = hold in effect, 2 = no hold
(Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Appraiser\GWX' -ErrorAction SilentlyContinue).GStatus
# Sign-in assistant: StartType must not be Disabled
Get-Service wlidsvc | Select-Object Status, StartTypeGood looks like a zero feature update deferral from Intune, no WSUS server from Group Policy, GStatus of 2 and an enabled service. Applications and Services Logs › Microsoft › Windows › WindowsUpdateClient › Operational shows scan and download activity, and the report moves through Offering and Installing to Installed: Update Installed.
Prevent it next time#
- Keep update ring feature deferrals at 0 whenever feature update policies control the version.
- Clear legacy WSUS and Windows Update GPOs from cloud-managed devices before moving them to Intune.
- Turn on the Windows data settings early, and run the readiness report before you target a new version.
- Keep every device in a feature update policy, moving it between policies rather than removing it.