Configure Update rings for Windows 10 and later policy in Intune (2024)

  • Article

Create update rings that specify how and when Windows as a Service updates your Windows 10/11 devices with feature and quality updates. With Windows 10/11, new feature and quality updates include the contents of all previous updates. As long as you've installed the latest update, you know your Windows devices are up to date. Unlike with previous versions of Windows, you now must install the entire update instead of part of an update.

Update rings can also be used to upgrade your eligible Windows 10 devices to Windows 11. To do so, when creating a policy you use the setting named Upgrade Windows 10 devices to Latest Windows 11 release by configuring it as Yes. When you use update rings to upgrade to Windows 11, devices install the most current version of Windows 11. If you later set the upgrade setting back to No, devices that haven't started the upgrade won't start while devices that are in the process of upgrading will continue to do so. Devices that have completed the upgrade will remain with Windows 11. For more information on eligibility, see Windows 11 Specs and System Requirements | Microsoft.

Windows update rings support scope tags. You can use scope tags with update rings to help you filter and manage sets of configurations that you use.

Prerequisites

The following prerequisites must be met to use Windows Update Rings for Windows 10/11 devices in Intune.

  • Devices must have access to endpoints. To get a detailed list of endpoints required for the associated service listed here, see Network endpoints.

    • Windows Update
  • Devices must run Windows 10 version 1607 or later, or Windows 11.

    Note

    Although not required to configure Windows Update for Business, if the Microsoft Account Sign-In Assistant (wlidsvc) service is disabled, Windows Update doesn't offer feature updates to devices running Windows 10 1709 or later, or Windows 11. For more information, see Feature updates are not being offered while other updates are.

  • Devices must be one of the following supported Windows editions:

Limitations for Workplace Joined devices

Intune Update rings for Windows 10 and later require the use of Windows Update for Business (WUfB), which supports devices that are Workplace Joined (WPJ). However, the following Intune Windows Update policy types use WUfB and Windows Update for Business deployment service (WUfB ds), which provides for additional capabilities that are not supported for WPJ devices.

  • Driver updates for Windows 10 and later
  • Feature updates for Windows 10 and later
  • Quality Updates updates for Windows 10 and later (also known as Expedited updates)

For more information about WPJ limitations for Intune Windows Update policies, see Policy limitations for Workplace Joined devices in Manage Windows 10 and Windows 11 software updates in Intune.

Create and assign update rings

  1. Sign in to the Microsoft Intune admin center.

  2. Select Devices > Windows > Update rings for Windows 10 and later > Create profile.

  3. Under Basics, specify a name, a description (optional), and then select Next.Configure Update rings for Windows 10 and later policy in Intune (1)

  4. Under Update ring settings, configure settings for your business needs. For information about the available settings, see Windows update settings. After configuring Update and User experience settings, select Next.

  5. Under Scope tags, select + Select scope tags to open the Select tags pane if you want to apply them to the update ring. Choose one or more tags, and then click Select to add them to the update ring and return to the Scope tags page.

    When ready, select Next to continue to Assignments.

    Note

    When configuring or editing Intune policies, some policy types might not display the Scope Tags configuration page if there are no custom defined scope tags for the tenant.If you don't see the Scope Tag option, ensure that at least one tag in addition to the default scope tag has been defined.

  6. Under Assignments, choose + Select groups to include and then assign the update ring to one or more groups. Use + Select groups to exclude to fine-tune the assignment. Select Next to continue.

    In most cases, we recommend deploying update rings to device groups. Use of device groups aligns to our guidance for deploying feature updates and removes the need for a user to sign-on to a device before the policy can apply.

  7. Under Review + create, review the settings, and then select Create when ready to save your Windows update ring. Your new update ring is displayed in the list of update rings.

Manage your Windows Update rings

In the portal, navigate to Devices > Windows > Update rings for Windows 10 and later and select the ring policy that you want to manage. Intune displays details similar to the following for the selected policy:

This view includes:

Configure Update rings for Windows 10 and later policy in Intune (3)

This view also includes:

  • Essentials: A list of details about the policy, including when it was created, last modified, and a count of groups that are assigned to the policy.

  • Device and user check-in status: The default report view for this policy. In addition to this default view, the following report details and options are available:

    • View report: A button opens a more detailed report view for Device and user check-in status.

    • Two additional report tiles: You can select the tiles for the following reports to view additional details:

      • Device assignment status – This report shows all the devices that are targeted by the policy, including devices in a pending policy assignment state.
      • Per setting status – View the configuration status of each setting for this policy across all devices and users.

    For details about this report view, see Reports for Update rings for Windows 10 and later policy.

  • Properties: View details for each configuration page of the policy, including an option to Edit each area of the policy.

Policy actions

Delete

Select Delete to stop enforcing the settings of the selected Windows update ring. Deleting a ring removes its configuration from Intune so that Intune no longer applies and enforces those settings.

Deleting a ring from Intune doesn't modify the settings on devices that were assigned the update ring. Instead, the device keeps its current settings. Devices don't maintain a historical record of what settings they held previously. Devices can also receive settings from other update rings that remain active.

To delete a ring
  1. While viewing the overview page for an Update Ring, select Delete.
  2. Select OK.

Pause

Select Pause to prevent assigned devices from receiving feature or quality updates for up to 35 days from the time you pause the ring. After the maximum days have passed, pause functionality automatically expires and the device scans Windows Updates for applicable updates. Following this scan, you can pause the updates again.If you resume a paused update ring, and then pause that ring again, the pause period resets to 35 days.

To pause a ring
  1. While viewing the overview page for an Update Ring, select Pause.
  2. Select either Feature or Quality to pause that type of update, and then select OK.
  3. After pausing one update type, you can select Pause again to pause the other update type.

When an update type is paused, the Overview pane for that ring displays how many days remain before that update type resumes.

Important

After you issue a pause command, devices receive this command the next time they check into the service. It's possible that before they check in, they might install a scheduled update. Additionally, if a targeted device is turned off when you issue the pause command, when you turn it on, it might download and install scheduled updates before it checks in with Intune.

Resume

While an update ring is paused, you can select Resume to restore feature and quality updates for that ring to active operation. After you resume an update ring, you can pause that ring again.

To resume a ring
  1. While viewing the overview page for a paused Update Ring, select Resume.
  2. Select from the available options to resume either Feature or Quality updates, and then select OK.
  3. After resuming one update type, you can select Resume again to resume the other update type.

Extend

While an update ring is paused, you can select Extend to reset the pause period for both feature and quality updates for that update ring to 35 days.

To Extend the pause period for a ring
  1. While viewing the overview page for a paused Update Ring, select Extend.
  2. Select from the available options to resume either Feature or Quality updates, and then select OK.
  3. After extending the pause for one update type, you can select Extend again to extend the other update type.

Uninstall

An Intune administrator can use Uninstall to uninstall (roll back) the latest feature update or the latest quality update for an active or paused update ring. After uninstalling one type, you can then uninstall the other type. Intune doesn't support or manage the ability of users to uninstall updates.

Important

When you use the Uninstall option, Intune passes the uninstall request to devices immediately.

  • Windows devices start removal of updates as soon as they receive the change in Intune policy. Update removal isn't limited to maintenance schedules, even when they're configured as part of the update ring.
  • If the update removal requires a device restart, the device restarts without offering device users an option to delay.

For Uninstall to be successful:

  • A device must run the Windows 10 April 2018 update (version 1803) or later, or Windows 11.

A device must have installed the latest update. Because updates are cumulative, devices that install the latest update will have the most recent feature and quality update. An example of when you might use this option is to roll back the last update should you discover a breaking issue on your Windows machines.

Consider the following when you use Uninstall:

  • Uninstalling a feature or quality update is only available for the servicing channel the device is on.

  • Using uninstall for feature or quality updates triggers a policy to restore the previous update on your Windows machines.

  • On a Windows 10/11 device, after a quality update is successfully rolled back, device users continue to see the update listed in Windows settings > Updates > Update History.

  • When you initiate an uninstall of feature or quality updates on an Update Ring, Intune also pauses updates of the same type on that Update Ring.

  • Once the feature or quality update pause elapses on an Update Ring, devices will reinstall previously uninstalled feature or quality updates if they're still applicable.

  • Uninstallation will not be successful when the feature update was applied using an Enablement Package. An Enablement Package is the most common way devices update to Windows 10 22H2 from Windows 10 2004, 20H2, and 21H2 via Windows Update for Business. To learn more about Enablement Packages, see KB5015684: Featured update to Windows 10, version 22H2 by using an enablement package - Microsoft Support. To learn more about using a script to uninstall Enablement Packages, see Uninstalling Windows updates on managed devices using Intune

  • For feature updates specifically, the time you can uninstall the update is limited from 2-60 days. This period is configured by the update rings Update setting Set feature update uninstall period (2 – 60 days). You can't roll back a feature update that's been installed on a device after the update has been installed for longer than the configured uninstall period.

    For example, consider an update ring with a feature update uninstall period of 20 days. After 25 days you decide to roll back the latest feature update and use the Uninstall option. Devices that installed the feature update over 20 days ago can't uninstall it as they've removed the necessary bits as part of their maintenance. However, devices that only installed the feature update up to 19 days ago can uninstall the update if they successfully check in to receive the uninstall command before exceeding the 20-day uninstall period.

For more information about Windows Update policies, see Update CSP in the Windows client management documentation.

To uninstall the latest Windows update
  1. While viewing the overview page for a paused Update Ring, select Uninstall.
  2. Select from the available options to uninstall either Feature or Quality updates, and then select OK.
  3. After you trigger the uninstall for one update type, you can select Uninstall again to uninstall the remaining update type.

Validation and reporting

There are multiple options to get in-depth reporting for Windows 10/11 updates with Intune. To learn more about the reports for update rings, including details for the default view and the additional report tiles, see Windows update reports.

Next steps

  • Use Windows feature updates in Intune
  • Use Windows update compatibility reports
  • Use Windows update reports for Windows updates
  • Also see Windows Autopatch in the Windows deployment content for an alternative solution
Configure Update rings for Windows 10 and later policy in Intune (2024)

FAQs

How do I update Windows 10 with Intune? ›

Create and assign Feature updates for Windows 10 and later policy. Sign in to the Microsoft Intune admin center. Select Devices > Windows > Feature updates for Windows 10 and later > Create profile.

What are the prerequisites must be met to use Windows 10 feature updates in Intune? ›

Prerequisites
  • Licensing:
  • Supported Windows 10/11 versions:
  • Supported Windows 10/11 editions:
  • Devices must:
  • Device settings:
  • Enable Windows Health Monitoring:
  • Before you can monitor results and update status for expedited updates, your Intune tenant must enable Windows Health Monitoring.
Mar 26, 2024

How do I change the configured update policy in Windows 10? ›

Newline Technical Services
  1. At the bottom left of our Windows Taskbar, please type gpedit and we will see the option Edit group policy.
  2. Select Administrative Templates.
  3. Double-click Windows Component.
  4. Scroll down to Windows Updates.
  5. Look for Configure Automatic Updates.
Dec 28, 2023

How do I set up update rings? ›

Create and assign update rings
  1. Sign in to the Microsoft Intune admin center.
  2. Select Devices > Windows > Update rings for Windows 10 and later > Create profile.
  3. Under Basics, specify a name, a description (optional), and then select Next.
  4. Under Update ring settings, configure settings for your business needs.
Sep 22, 2023

How to configure Windows Update via Intune? ›

Setup
  1. Go to Intune admin center.
  2. Navigate to Devices>Windows 10 and later updates>Driver updates.
  3. Create a profile, name it and choose the approval method.
  4. Assign to a group.
  5. Regularly review and approve updates (if approval method is manual)
Jul 5, 2023

What is the difference between feature update and update ring? ›

Feature update profiles are preferred over using the update deferrals in update rings. You have better control over the process, and it is more automated. You should set feature update deferral to 0 days when using the feature update profiles.

How do Windows Update rings work? ›

These are admin-defined groups of machines where you can pre-test some updates and decide how quickly they receive updates. A typical set of rings would include: Your “testing” ring: This ring would have no delay in updates. As soon as they are released, a ring of initial computers would receive the updates to test.

What is the deferral period for Intune Update rings? ›

Deferral period (8 days) - Updates are deferred for set amount of days. So here, patches will show up in Windows Update section 8 days after patch Tuesday. Deadline (7 days) - Is how long patch will stay available in Windows Update section until force installed.

How do I check Windows Update status in Intune? ›

Intune offers integrated report views for the Windows update ring policies you deploy. These views display details about the update ring deployment and status. To access reports, in the Intune admin center go to Devices > Windows > Update rings for Windows 10 and later > and select an update ring policy.

What is the best practice for Windows Update Group Policy? ›

WSUS/GPO Best Practices
  • WSUS automatically approves Critical and Security updates for all machines.
  • GPO:
  • Allow Automatic Updates immediate installation: Enabled.
  • Allow non-administrators to receive update notifications: Enabled.
  • Allow signed updates from an intranet Microsoft update service location: Enabled.
Aug 15, 2017

What is the default Windows Update configuration in Windows 10? ›

By default Windows 10 will update your computer automatically.

How to configure automatic updates by using Group Policy Windows 10? ›

Automatic Update Detection Frequency
  1. In Group Policy Object Editor, expand Computer Configuration, expand Administrative Templates, expand Windows Components, and then click Windows Update.
  2. In the details pane, click Automatic Update detection frequency, and set the option.
  3. Click OK.
Nov 21, 2021

What are the prerequisites for Intune feature update? ›

Prerequisites for Windows 11 Upgrade with Intune

You need the following licenses to leverage Intune's Feature updates for Windows 10 and later: Windows 10/11 Enterprise E3 or E5 (included in Microsoft 365 F3, E3, or E5) Windows 10/11 Education A3 or A5 (included in Microsoft 365 A3 or A5)

What is the difference between SCCM and Intune? ›

SCCM is an on-premises solution for managing heterogeneous environments, while Intune is a cloud-based MDM focused on hom*ogeneous environments, particularly for mobile devices. Network Access Protection is a crucial consideration for SCCM in on-premises environments.

When would you use the critical update Ring? ›

Question: While deploying Windows updates, when would you use the critical update ring? answerWhen deploying updates to important systems (only after the update has been vetted).

How do I manage Windows 10 with Intune? ›

When you begin working with Intune for Windows 10 and Windows 11 devices, you'll typically need to complete the following core tasks:
  1. Create and configure your Azure AD / Intune tenant. ...
  2. Configure Enrolment. ...
  3. Configure Device Configuration Profiles.
  4. Configure Device Compliance Policies.
  5. Deploy and Manage Apps.
Jan 28, 2022

How do I manually update Windows 10 firmware? ›

Install firmware or BIOS updates in Windows 11 or Windows 10
  1. Search for and open Device Manager.
  2. Expand Firmware.
  3. Double-click System Firmware.
  4. Select the Driver tab.
  5. Click Update Driver.
  6. Click Search automatically for drivers.
  7. Wait for the update to download and then follow the instructions.

How often does Windows 10 sync with Intune? ›

About every 8 hours

How do I use Intune on Windows 10? ›

All the steps provided in the article help you to add and manage devices and apps using Intune.
  1. Prerequisites. ...
  2. 1 - Review the Supported Configurations. ...
  3. 2 - Sign up for Microsoft Intune. ...
  4. 3 - Configure a custom domain name for your Intune tenant. ...
  5. 4 - Add users to Intune. ...
  6. 5 - Create groups in Intune. ...
  7. 6 - Manage licenses.
Mar 1, 2024

Top Articles
Latest Posts
Article information

Author: Rueben Jacobs

Last Updated:

Views: 6191

Rating: 4.7 / 5 (57 voted)

Reviews: 88% of readers found this page helpful

Author information

Name: Rueben Jacobs

Birthday: 1999-03-14

Address: 951 Caterina Walk, Schambergerside, CA 67667-0896

Phone: +6881806848632

Job: Internal Education Planner

Hobby: Candle making, Cabaret, Poi, Gambling, Rock climbing, Wood carving, Computer programming

Introduction: My name is Rueben Jacobs, I am a cooperative, beautiful, kind, comfortable, glamorous, open, magnificent person who loves writing and wants to share my knowledge and understanding with you.