IntuneHow-to

Windows Update for Business in Intune: update rings, expedited updates and reports

Prerequisites, the update ring settings and their ranges, a pilot/broad ring design, expedite and driver update policies, the Intune and Windows Update for Business reports, and how to check a device locally.

Intune doesn't host Windows updates; it hands the Windows Update client a policy that says how long to wait, when to install and when to force a restart, and (for the newer policy types) tells Windows Autopatch which content a device may receive. In this post I'll cover the prerequisites, the update ring settings worth understanding, a two-ring design that works for most tenants, expedited and driver update policies, and where to look when you need to prove a device is patched.

How this guide is organised: Prerequisites → Step-by-step → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. Prerequisites. 2. Step-by-step (4 steps: Know the ring settings; Design the rings; Expedite a security update; Add a driver update policy). 3. Verify. 4. Tips & gotchas. Toolbox: Create › Expedite policy, Reports › Windows updates, UCClientUpdateStatus, UCUpdateAlert, UCDeviceAlert.1Prerequisites2Step-by-step3Verify4Tips & gotchas1Know the ring settings2Design the rings3Expedite a securityupdate4Add a driver updatepolicyTOOLBOXCreate › Expedite policyReports › Windows updatesUCClientUpdateStatusUCUpdateAlertUCDeviceAlertHow this guide is organised: Prerequisites → Step-by-step → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. Prerequisites. 2. Step-by-step (4 steps: Know the ring settings; Design the rings; Expedite a security update; Add a driver update policy). 3. Verify. 4. Tips & gotchas. Toolbox: Create › Expedite policy, Reports › Windows updates, UCClientUpdateStatus, UCUpdateAlert, UCDeviceAlert.1Prerequisites2Step-by-step1Know the ring settings2Design the rings3Expedite a security update4Add a driver update policy3Verify4Tips & gotchasTOOLBOXCreate › Expedite policyReports › Windows updatesUCClientUpdateStatusUCUpdateAlertUCDeviceAlert
At a glance: how this guide is organised · 4 steps · 5 key settings and tools

Prerequisites#

  • Join type: update rings work on Microsoft Entra joined, hybrid joined and Entra registered devices enrolled in Intune, but the Autopatch-backed policies (feature updates, quality updates including expedite and hotpatch, driver updates) need Microsoft Entra joined or hybrid joined devices.
  • Editions: rings support Pro, Pro Education, Enterprise, Education, IoT Enterprise, Windows Team and (quality updates only) Enterprise LTSC. The Autopatch-backed policies support Pro, Pro Education, Enterprise and Education, not LTSC.
  • Licensing: rings need Intune Plan 1. Feature, quality and driver update policies also need a Windows licence that includes the Windows Autopatch entitlement; at the time of writing that means Windows Enterprise E3/E5, Education A3/A5 or Microsoft 365 Business Premium.
  • Diagnostic data: at least Required for the Autopatch-backed policies and for reporting, with Tenant administration › Connectors and tokens › Windows data turned on for Intune's update reports.
  • Services and network: the Microsoft Account Sign-In Assistant (wlidsvc) must not be disabled (its default Manual (Trigger Start) is fine), and devices must reach the Windows Update, Intune and Windows Autopatch endpoints.

Step-by-step#

1. Know the ring settings#

Update rings live under Devices › Windows › Manage updates › Windows updates › Update rings. The settings that shape behaviour:

SettingRange or optionsNotes
Microsoft product updatesAllow / BlockOffice and other Microsoft Update content
Windows driversAllow / BlockMust be Allow for driver update policies
Quality update deferral period0–30 daysCounted from the client's first scan that saw the update
Feature update deferral period0–365 daysCounted from Microsoft's release date
Upgrade Windows 10 devices to Latest Windows 11 releaseYes / NoEligible Windows 10 devices move to current Windows 11
Set feature update uninstall period2–60 daysAfter this, the rollback bits are gone
Enable pre-release buildsRelease Preview, Beta, DevLeave Not configured in production
Automatic update behaviorNotify download; Auto install at maintenance time; Auto install and restart at maintenance time; Auto install and restart at a scheduled time; Auto install and reboot without end-user control; Reset to defaultPair with Active hours start and end
Option to pause / check for Windows updatesEnable / DisableWhat users can do in Settings
Change notification update levelDefault, or turn off notifications with or without restart warningsKeep restart warnings on
Use deadline settingsFeature deadline 2–30 days, quality deadline 2–30 days, grace period 0–7 days, auto reboot before deadline Yes/NoThe core compliance lever

Deadlines count from when the client's scan first saw the update (so after the deferral), the grace period adds days after the deadline before a forced restart, and Auto reboot before deadline set to Yes lets Windows restart outside active hours early rather than at the last moment, which Microsoft recommends.

2. Design the rings#

Two rings cover most organisations; add a small "preview" ring if you have the devices. Assign rings to device groups so policy applies without waiting for a sign-in, and make sure no device sits in two rings.

SettingPilot ring (IT plus volunteers, 5–10% of devices)Broad ring (everyone else)
Quality update deferral0 days7 days
Feature update deferral7 days60 days or longer, with a feature update policy pinning the version
Quality deadline / grace2 / 15 / 2
Feature deadline / grace5 / 27 / 2
Automatic update behaviorReset to default, active hours set to the working dayReset to default, active hours set to the working day
Auto reboot before deadlineYesYes

With a ring selected, the toolbar offers Pause (stops feature or quality updates for up to 35 days), Extend, Resume and Uninstall for the latest feature or quality update. Pause is the emergency brake when a monthly update misbehaves on the pilot ring.

3. Expedite a security update#

An expedite policy pushes one specific security update as soon as possible, overriding the quality deferral for that update only, without touching your rings. Go to Devices › Windows › Manage updates › Windows updates › Quality updates › Create › Expedite policy and pick the update (names with B are Patch Tuesday releases, OOB marks out-of-band security releases, and non-security D releases appear for Windows 11 only when no newer security update exists). Then set If a reboot is required, select the number of days before it's enforced to 0, 1 or 2 days: 0 tells the user to restart immediately, 1 or 2 give 24 or 48 hours regardless of active hours. Extra requirements: devices before Windows 11 24H2 need the Update Health Tools (KB4023057), while 24H2 and later must not have them; the ring's pre-release setting should be Not configured, automatic update behaviour Reset to default, and the notification level must not silence restart warnings. Expect a newer update to install if one is released and not deferred before the device checks in.

4. Add a driver update policy#

Under the Driver updates tab, create a profile and choose Automatically approve all recommended driver updates (with a number of days before each approved driver becomes available) or Manually approve and deploy driver updates, where each new driver waits for review. Drivers only flow if the ring's Windows drivers setting is Allow (or the settings catalog's Exclude WU Drivers in Quality Update allows them), Microsoft advises one driver policy per device, and you can pause an individual driver without touching the rest.

Verify#

In Intune#

  • Open the ring: Device and user check-in status shows who received it, and Device assignment status and Per setting status show pending assignments and settings that conflicted with another policy.
  • Reports › Windows updates: the Summary tab shows expedited update progress, and the Reports tab holds the Windows Feature Update Report and the Windows Expedited Update Report (pick a profile and generate). The failures reports and Expedited quality update policies with alerts list per-device alerts with error codes.

Windows Update for Business reports#

For compliance across the whole estate, enable Windows Update for Business reports from the Azure portal. It stores client diagnostic data in a Log Analytics workspace you own (no ingestion charges for this data), ships a workbook covering quality, feature and driver updates plus Delivery Optimization, and exposes tables such as UCClient, UCClientUpdateStatus, UCUpdateAlert and UCDeviceAlert for your own KQL. Devices must be Microsoft Entra joined or hybrid joined and send Required diagnostic data; device names appear only if you enable the AllowDeviceNameInDiagnosticData policy.

On the device#

Settings › Windows Update › Advanced options › Configured update policies lists the policies the device received with value and source. The MDM values are also in the registry, and the Windows Update log can be merged for reading:

PowerShell
Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\PolicyManager\current\device\Update' |
    Select-Object DeferQualityUpdatesPeriodInDays, DeferFeatureUpdatesPeriodInDays,
                  ConfigureDeadlineForQualityUpdates, ConfigureDeadlineGracePeriod
Get-Service wlidsvc | Select-Object Status, StartType
Get-Service -Name 'Microsoft Update Health Service' -ErrorAction SilentlyContinue
Get-WindowsUpdateLog

Missing values mean the ring hasn't applied; a disabled wlidsvc explains a device that gets quality updates but never a feature update.

Tips & gotchas#

  • Don't mix update rings and the settings catalog's Windows Update settings on the same devices; they write the same CSP values and conflicts leave settings unapplied.
  • Autopatch-managed devices get service-created rings; don't assign your own rings to them as well.
  • Devices still pointed at WSUS or carrying legacy Group Policy update settings ignore or fight the Intune policy. Remove the GPOs first.
  • Control feature update rollout with a feature update policy rather than deferral alone; it pins the version and gives you a dedicated report.
  • Expedite is for emergencies, not monthly servicing.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)