Windows Update
Microsoft Intune and Intune for Education can configure many Windows Update configuration settings. This article summarizes the configurations that are most commonly used for student and teacher devices.
Use Microsoft Intune or Intune for Education to manage the install of Windows 10/11 software updates from Windows Update for Business. You can configure update settings on devices and configure deferral of update installation. You can also prevent devices from installing features from new Windows versions to help keep them stable, while allowing those devices to continue installing updates for quality and security.
Update rings for Windows 10 and later
Update ring policies are a collection of settings that configure when devices that run Windows 10 and Windows 11 updates get installed.
To learn more, see:
- Update rings for Windows 10 and later policy in Intune
- The Windows Update policies you should set and why
- YouTube: Windows Update for Business Fundamentals
- YouTube: Windows Update for Business Fundamentals (Japanese)
Update settings | Value | Notes | CSP |
---|---|---|---|
Microsoft product updates | Allow | Don't set to Block. In order to revert the configuration, PowerShell commands have to be run on each device. | AllowMUUpdateService |
Windows drivers | Allow | ExcludeWUDriversInQualityUpdate | |
Quality update deferral period (days) | 7 | DeferQualityUpdatesPeriodInDays | |
Feature update deferral period (days) | 30 | Select 0 if using a Feature update policy otherwise select 30 days. | DeferFeatureUpdatesPeriodInDays |
Upgrade Windows 10 devices to Latest Windows 11 release | No | ProductVersion | |
Set feature update uninstall period (2 - 60 days) | 14 | ConfigureFeatureUpdateUninstallPeriod | |
Enable pre-release builds | Not configured | ManagePreviewBuilds |
User experience settings | Value | Notes | CSP |
---|---|---|---|
Automatic update behavior | Reset to default | Auto install and restart. Updates are downloaded automatically on non-metered networks and installed during "Automatic Maintenance" when the device isn't in use and isn't running on battery power. Note: If Windows Update policy is configured via the settings catalog, the value should be Auto install and restart. |
AllowAutoUpdate |
Restart checks (EDU Restart) | Allow | Must not be disabled in existing Windows Update Rings. This setting is no longer available when creating a new Windows Update Ring policy. |
SetEDURestart |
Option to pause Windows updates | Disable | SetDisablePauseUXAccess | |
Option to check for Windows updates | Disable | SetDisableUXWUAccess | |
Change notification update level | Turn off all notifications, excluding restart warnings | UpdateNotificationLevel | |
Use deadline settings | Allow | Only enables the setting configuration. | |
Deadline for feature updates | 7 | ConfigureDeadlineForFeatureUpdates | |
Deadline for quality updates | 3 | ConfigureDeadlineForQualityUpdates | |
Grace period | 2 | ConfigureDeadlineGracePeriod ConfigureDeadlineGracePeriodForFeatureUpdates |
|
Auto reboot before deadline | Yes | ConfigureDeadlineNoAutoReboot |
Settings catalog
Settings described in this section aren't available in an Update ring policy and should be configured using a settings catalog type configuration profile.
To learn more, see Use the settings catalog to configure settings on Windows, iOS/iPadOS, and macOS devices.
Tip
When creating a settings catalog profile in the Microsoft Intune admin center, you can copy a policy name from this article and paste it into the settings picker search field to find the desired policy.
Category | Name | Value | Notes | CSP |
---|---|---|---|---|
Windows Update For Business | No update notifications during active hours | Enabled | NoUpdateNotificationsDuringActiveHours |
Windows Update Feature Control
Windows feature updates contain new Windows features to improve the user experience. Windows feature versions are supported differently depending on the edition. It's important to ensure that the Windows version installed remains supported so that it can receive the latest security updates and support required applications such as testing apps.
Use the support lifecycle websites for each Windows operating system version and edition:
- Windows 10 Home, Pro, and Pro Education;
- Windows 10 Enterprise and Education;
- Windows 11 Home, Pro, and Pro Education;
- Windows 11 Enterprise and Education.
There are two ways to control how and when Windows feature updates are installed on Windows.
Feature update control type | Configuration | Advantages | Disadvantages |
---|---|---|---|
Automatically keep up to date (recommended) | Use only Update ring policies and set a feature update deferral to 30 or more days | Devices are always kept up to date and receive access to the latest Windows features | Users may not have had training on new features, and some apps may not be compatible with the new feature version |
Control feature version | Use feature update policies to keep devices at a particular version of Windows | Devices are kept at a particular Windows version until the policy is changed | The policy must be reviewed and changed periodically to ensure Windows remains supported |
Automatically keep Windows up to date
Using the update ring you configured earlier, set the Feature update deferral period (days) to 30 days. The deferral period can be increased or decreased based on the school needs.
Control feature version
A Feature update policy can be configured to set devices to a particular version of Windows. Devices running older versions of Windows will update to the specified version. Devices with newer versions of Windows won't perform any feature updates.
To set a feature update policy:
- Sign in to the Microsoft Intune admin center.
- Select Devices > By platform > Windows > Manage updates > Windows 10 and later updates > Feature updates tab > Create profile.
- Under Deployment settings:
- Specify a name, a description (optional), and for Feature update to deploy, select the version of Windows with the feature set you want, and then select Next.
- Configure Rollout options to As soon as possible.
- Under Assignments, choose + Select groups to include and then assign the feature updates deployment to one or more device groups. Select Next to continue.
- Under Review + create, review the settings. When ready to save the Feature updates policy, select Create.
Warning
If you don't review the feature update version at least every 18 months, your Windows devices may no longer receive security updates. Ensure you review and update the feature version to stay supported.