Software Update Patching Options With Intune Setup Guide (2024)

This post will get more details about Windows 10 or Windows 11 Software Update Patching Options with Intune. How do you patch Windows 10/11 devices managed with Intune? If you are interested to know more about Intune Vs SCCM And WSUS Vs WUfB Patching Method Differences?

Microsoft Software Update Patching process for Intune admins. Intune helps configure Windows Update for Business (WUfB) policies to patch. This is the simplified patch management using Intune and WUfB.

Latest Post for Monthly Patching using Intune – Windows 11 Monthly Patch Deployment Using Intune HTMD Blog (anoopcnair.com)

The latest update guide for Intune monthly patching is available in the following Cloud PC Monthly Patching Process Using Intune. You can also configure Windows 10 and 11 Feature Update using Intune policies.

Software Update Patching Options With Intune Setup Guide (1)

The troubleshooting on Cloud PC and physical PC is also the same for monthly patching and feature update scenario.

In the following blog post, we have explained the troubleshooting methods to identify the issue with event logs and registry keys https://howtomanagedevices.com/intune/2319/uninstall-windows-10-feature-update/.

Introduction

Software update deployment with IntuneMicrosoft Intune provides Windows 10/11 Update Rings management to enable Windows as a Service via the Software Updates feature.

This enrolls a Windows PC into Windows Update for Business to manage features and quality updates the device receives and how quickly it updates to new releases.

Software Update Patching Options With Intune Setup Guide (2)

Software update deployment with Intune is straightforward. A few configuration steps, profile creation, and deployment are all done.

In this blog post, I will describe how to configure the windows update deployment through Intune on Windows 10 devices enrolled with Windows autopilot.

Update rings are policies that you assign to groups of devices. You can check out the following video to get more details on Intune based patching strategies. Intune Patch Management Methods for Windows iOS iPadOS macOS – Intune Design Decisions Part 7.

Prerequisites

The following prerequisites must be fulfilled to use the Windows updates feature for Windows 10 devices in Intune. Server Operating Systems are not supported with Intune and Windows Update for Business.

Additional prerequisites to use Windows Update for Business (WUfB) are given below as per Microsoft. This includes the licensing requirements and others.

Windows 10/11 Enterprise E3 or E5 (included in Microsoft 365 F3, E3, or E5)
Windows 10/11 Education A3 or A5 (included in Microsoft 365 A3 or A5)
Windows Virtual Desktop Access E3 or E5
Microsoft 365 Business Premium

Additionally, devices managed by the Windows Update for Business deployment service must have the following:

Windows 10 version 1709 or later
Azure AD joined, or Hybrid AD joined
Windows 10 or Windows 11 editions installed: Pro Enterprise Education Pro for Workstations

Create a windows update policy

To create the policy for software updates, you need to Microsoft Intune – Overview and software updates, then click on Software updates. You will see the blade-like following.

Software Update Patching Options With Intune Setup Guide (3)

Click on Windows 10 update ring, then click on Create.

Software Update Patching Options With Intune Setup Guide (4)

Enter the Name and Description of the Intune Patching or Software Updates policy.

Software Update Patching Options With Intune Setup Guide (5)

Intune Patching Update Settings

I have segregated this monthly patch policy configuration intotwosections 1.Update Settings2.User experience settingsfor easy understanding. This is the policy I created for theDay 0 deployment ringof Windows 11 devices.

In the update settings, you will see many options that need to be configured. Microsoft removed this section about Servicing channel from Intune update policy.

You must select the update servicing based on your requirement and the organization’s need; here, I have chosen a semi-annual channel.

1) You need to configure several days for a quality update and feature update at different times, from how many days these updates will install after release. For feature updates, I would recommend using different policies with more granular control.

  • Update settings
    • Microsoft product updates– Allow.
    • Windows drivers– Allow.
    • Quality update deferral period (days)0– Defer quality updates for the specified number of days for Windows 11 PCs. The allowed value is between0-30days.
    • Feature update deferral period(days) –0– Defer feature updates for the specified number of days for Windows 11 PCs. The allowed value is between 0-365 days.
    • Set feature update uninstall period(2 – 60 days) –10– This is to set the feature update to uninstall period. The allowed value is between 2-60 days.
    • Upgrade Windows 10 devices to the Latest Windows 11 release – NO
    • Enable pre-release builds – Enable?
    • Select Pre-Release Channel – Windows Insider Channels (DEV or BETA)
Software Update Patching Options With Intune Setup Guide (6)

User Experience Setting

User experience settings are those settings you configure to provide a better experience for end-users to do their day-to-day work without any interruption.

The first setting is automatic update behavior, where you have to configure how updates will install on your devices.

It either installs automatically or notifies the users to download the updates, install updates during maintenance time, or install the updates automatically and restart the device in the scheduled time.

The next setting is to provide an active start time and active end time; theseare very important to configure the maintenance window for installing updates.

Next is restart checks, which means you can configure the restart check either for the battery power up to 40% or something else; you can skip this setting.

If you want users to have to approve for computer restart post-update installation, then you can enable this setting, and the user can authorize a computer restart,

Configure all the settings like servicing channel, product, and driver updates if you want to deploy them on Windows 10 devices, update deferral periods, user experience settings, the deadline for updates, and, most importantly, set auto-reboot settings.

All the settings are critical, I would say, and all of them would be required for all the organizations, but they would be different for them based on the security policies.

You can now configure theUser Experience settingsfor Windows 11 monthly patch deployment policy. These Intune policies are configured in the Intune Admin center portal. I have not changed the settings of any of these policies for theDay 0 deployment ring.

  • Automatic Update behavior-> AutoInstall at maintenance time.
    • Active hours start-> 8 AM
    • Active hours end-> 5 PM
  • Restart checks– Allow – This policy is set to skip all checks before restart: Battery level = 40%, User presence, Display Needed, Presentation mode, Full-screen mode, phone call state, game mode etc.
  • Option to pause Windows updates-Enable
  • Option to check for Windows updates– Enable
  • Require user approval to dismiss restart notification– No
  • Remind user prior to required auto-restart with a dismissible reminder (hours)– The allowed number of hours, 2, 4, 8, 12, or 24 – 2 Hours.
  • Remind user prior to required auto-restart with a permanent reminder (minutes)– The allowed number of minutes, 15, 30, or 60 – 30 Minutes.
  • Change notification update level– Use default Windows Update notifications.
Software Update Patching Options With Intune Setup Guide (7)

Intune Patching – Deadline Configurations

Now, you will need to configurethe deadline settingsexperience for Windows 11 PCs. You have to be careful about these configuration policies because this defines the restart behavior for the users and reminders etc.

I have not configured these deadline settings policies for Day -0 deployment ring in my lab environment. However, I recommend configuring these policies as per your business requirements.

  • Use deadline settings-> Not Configured
  • Deadline for feature updates->
  • Deadline for quality updates->
  • Grace period–>
  • Auto reboot before the deadline
  • Click onNextto continue.
Software Update Patching Options With Intune Setup Guide (8)

Deployment of Software Updates and Patches

Let’s check the Deployment of Software Updates and Patches using Intune and Windows Update for Business. You can deploy this policy either to users or device groups. Intune has the intelligence to understand the devices assigned to a user using the lookup method.

Software Update Patching Options With Intune Setup Guide (9)

Update ring assignment is straightforward, you have to look into the right hand, and you have to select the group to which your windows ten devices are added, and you need to update them.

I wanted to update you on all my windows autopilot devices, so I have selected the windows autopilot group.

Software Update Patching Options With Intune Setup Guide (10)
Software Update Patching Options With Intune Setup Guide (11)

End User Experience of Intune Patching using WUfB

In the next window, review all the settings you have configured and click on create.

When I check my windows 10 device and window update, I can see the policy are applied, and windows 10 is downloading the update, which is fast,

Software Update Patching Options With Intune Setup Guide (12)

Once it’s installed, I checked in Intune console, and I can see the following dashboard,

Software Update Patching Options With Intune Setup Guide (13)
Software Update Patching Options With Intune Setup Guide (14)

Manage Windows 10 update rings – Pause Delete Resume Extend

In the Intune portal, go to device > Windows > Windows 10 update rings > and select the policy you want to manage; you can view the status of the ring assignment.

Here you can see the following options.

  • Delete
  • Pause
  • Resume
  • Extend

Delete: Delete setting you can use if you want to remove any configured ring from Intune; while deleting, you need to under that, and deleting the ring will not remove/modify settings already assignedto the devices.

Pause: The pause setting can be used when you want to pause any update on the device, which can be done up to 35 days from the deployment.

After 35 days, the pause setting will expire automatically, and the device will scan updates for applicable updates.

Resume: If you have paused any update ring, you can use this setting to resume the updates.

Extend: if any update/ring is pushed, you can use this setting to extend the pause for another 35 eds.

Software Update Patching Options With Intune Setup Guide (15)

Resources

  • How to Setup Windows 10 Software Update Policy Rings in Intune Azure Portal
Software Update Patching Options With Intune Setup Guide (2024)
Top Articles
Latest Posts
Article information

Author: Ms. Lucile Johns

Last Updated:

Views: 5859

Rating: 4 / 5 (41 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Ms. Lucile Johns

Birthday: 1999-11-16

Address: Suite 237 56046 Walsh Coves, West Enid, VT 46557

Phone: +59115435987187

Job: Education Supervisor

Hobby: Genealogy, Stone skipping, Skydiving, Nordic skating, Couponing, Coloring, Gardening

Introduction: My name is Ms. Lucile Johns, I am a successful, friendly, friendly, homely, adventurous, handsome, delightful person who loves writing and wants to share my knowledge and understanding with you.