Intune doesn't host Windows updates; it hands the Windows Update client a policy that says how long to wait, when to install and when to force a restart, and (for the newer policy types) tells Windows Autopatch which content a device may receive. In this post I'll cover the prerequisites, the update ring settings worth understanding, a two-ring design that works for most tenants, expedited and driver update policies, and where to look when you need to prove a device is patched.
Prerequisites#
- Join type: update rings work on Microsoft Entra joined, hybrid joined and Entra registered devices enrolled in Intune, but the Autopatch-backed policies (feature updates, quality updates including expedite and hotpatch, driver updates) need Microsoft Entra joined or hybrid joined devices.
- Editions: rings support Pro, Pro Education, Enterprise, Education, IoT Enterprise, Windows Team and (quality updates only) Enterprise LTSC. The Autopatch-backed policies support Pro, Pro Education, Enterprise and Education, not LTSC.
- Licensing: rings need Intune Plan 1. Feature, quality and driver update policies also need a Windows licence that includes the Windows Autopatch entitlement; at the time of writing that means Windows Enterprise E3/E5, Education A3/A5 or Microsoft 365 Business Premium.
- Diagnostic data: at least Required for the Autopatch-backed policies and for reporting, with Tenant administration › Connectors and tokens › Windows data turned on for Intune's update reports.
- Services and network: the Microsoft Account Sign-In Assistant (
wlidsvc) must not be disabled (its default Manual (Trigger Start) is fine), and devices must reach the Windows Update, Intune and Windows Autopatch endpoints.
Step-by-step#
1. Know the ring settings#
Update rings live under Devices › Windows › Manage updates › Windows updates › Update rings. The settings that shape behaviour:
| Setting | Range or options | Notes |
|---|---|---|
| Microsoft product updates | Allow / Block | Office and other Microsoft Update content |
| Windows drivers | Allow / Block | Must be Allow for driver update policies |
| Quality update deferral period | 0–30 days | Counted from the client's first scan that saw the update |
| Feature update deferral period | 0–365 days | Counted from Microsoft's release date |
| Upgrade Windows 10 devices to Latest Windows 11 release | Yes / No | Eligible Windows 10 devices move to current Windows 11 |
| Set feature update uninstall period | 2–60 days | After this, the rollback bits are gone |
| Enable pre-release builds | Release Preview, Beta, Dev | Leave Not configured in production |
| Automatic update behavior | Notify download; Auto install at maintenance time; Auto install and restart at maintenance time; Auto install and restart at a scheduled time; Auto install and reboot without end-user control; Reset to default | Pair with Active hours start and end |
| Option to pause / check for Windows updates | Enable / Disable | What users can do in Settings |
| Change notification update level | Default, or turn off notifications with or without restart warnings | Keep restart warnings on |
| Use deadline settings | Feature deadline 2–30 days, quality deadline 2–30 days, grace period 0–7 days, auto reboot before deadline Yes/No | The core compliance lever |
Deadlines count from when the client's scan first saw the update (so after the deferral), the grace period adds days after the deadline before a forced restart, and Auto reboot before deadline set to Yes lets Windows restart outside active hours early rather than at the last moment, which Microsoft recommends.
2. Design the rings#
Two rings cover most organisations; add a small "preview" ring if you have the devices. Assign rings to device groups so policy applies without waiting for a sign-in, and make sure no device sits in two rings.
| Setting | Pilot ring (IT plus volunteers, 5–10% of devices) | Broad ring (everyone else) |
|---|---|---|
| Quality update deferral | 0 days | 7 days |
| Feature update deferral | 7 days | 60 days or longer, with a feature update policy pinning the version |
| Quality deadline / grace | 2 / 1 | 5 / 2 |
| Feature deadline / grace | 5 / 2 | 7 / 2 |
| Automatic update behavior | Reset to default, active hours set to the working day | Reset to default, active hours set to the working day |
| Auto reboot before deadline | Yes | Yes |
With a ring selected, the toolbar offers Pause (stops feature or quality updates for up to 35 days), Extend, Resume and Uninstall for the latest feature or quality update. Pause is the emergency brake when a monthly update misbehaves on the pilot ring.
3. Expedite a security update#
An expedite policy pushes one specific security update as soon as possible, overriding the quality deferral for that update only, without touching your rings. Go to Devices › Windows › Manage updates › Windows updates › Quality updates › Create › Expedite policy and pick the update (names with B are Patch Tuesday releases, OOB marks out-of-band security releases, and non-security D releases appear for Windows 11 only when no newer security update exists). Then set If a reboot is required, select the number of days before it's enforced to 0, 1 or 2 days: 0 tells the user to restart immediately, 1 or 2 give 24 or 48 hours regardless of active hours. Extra requirements: devices before Windows 11 24H2 need the Update Health Tools (KB4023057), while 24H2 and later must not have them; the ring's pre-release setting should be Not configured, automatic update behaviour Reset to default, and the notification level must not silence restart warnings. Expect a newer update to install if one is released and not deferred before the device checks in.
4. Add a driver update policy#
Under the Driver updates tab, create a profile and choose Automatically approve all recommended driver updates (with a number of days before each approved driver becomes available) or Manually approve and deploy driver updates, where each new driver waits for review. Drivers only flow if the ring's Windows drivers setting is Allow (or the settings catalog's Exclude WU Drivers in Quality Update allows them), Microsoft advises one driver policy per device, and you can pause an individual driver without touching the rest.
Verify#
In Intune#
- Open the ring: Device and user check-in status shows who received it, and Device assignment status and Per setting status show pending assignments and settings that conflicted with another policy.
- Reports › Windows updates: the Summary tab shows expedited update progress, and the Reports tab holds the Windows Feature Update Report and the Windows Expedited Update Report (pick a profile and generate). The failures reports and Expedited quality update policies with alerts list per-device alerts with error codes.
Windows Update for Business reports#
For compliance across the whole estate, enable Windows Update for Business reports from the Azure portal. It stores client diagnostic data in a Log Analytics workspace you own (no ingestion charges for this data), ships a workbook covering quality, feature and driver updates plus Delivery Optimization, and exposes tables such as UCClient, UCClientUpdateStatus, UCUpdateAlert and UCDeviceAlert for your own KQL. Devices must be Microsoft Entra joined or hybrid joined and send Required diagnostic data; device names appear only if you enable the AllowDeviceNameInDiagnosticData policy.
On the device#
Settings › Windows Update › Advanced options › Configured update policies lists the policies the device received with value and source. The MDM values are also in the registry, and the Windows Update log can be merged for reading:
Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\PolicyManager\current\device\Update' |
Select-Object DeferQualityUpdatesPeriodInDays, DeferFeatureUpdatesPeriodInDays,
ConfigureDeadlineForQualityUpdates, ConfigureDeadlineGracePeriod
Get-Service wlidsvc | Select-Object Status, StartType
Get-Service -Name 'Microsoft Update Health Service' -ErrorAction SilentlyContinue
Get-WindowsUpdateLogMissing values mean the ring hasn't applied; a disabled wlidsvc explains a device that gets quality updates but never a feature update.
Tips & gotchas#
- Don't mix update rings and the settings catalog's Windows Update settings on the same devices; they write the same CSP values and conflicts leave settings unapplied.
- Autopatch-managed devices get service-created rings; don't assign your own rings to them as well.
- Devices still pointed at WSUS or carrying legacy Group Policy update settings ignore or fight the Intune policy. Remove the GPOs first.
- Control feature update rollout with a feature update policy rather than deferral alone; it pins the version and gives you a dedicated report.
- Expedite is for emergencies, not monthly servicing.