A Microsoft 365 Endpoint Administrator is managing a fleet of corporate-owned Windows 11 devices. The company policy dictates that all drivers and firmware updates must be thoroughly tested before being deployed to production devices. However, critical security updates should be applied as soon as possible. Which Intune feature provides the most granular control to manage both driver/firmware updates and critical security updates separately?
- ADriver and firmware update policies.
- BQuality update policies.
- CFeature update policies.
- DWindows Update rings with deferral periods.
Show answer & explanationAnswer & explanation
Correct answer: A. Driver and firmware update policies.
Dedicated 'Driver and firmware update policies' in Intune provide explicit control over the deployment of these specific update types, allowing administrators to approve, pause, or roll back individual drivers and firmware. This is separate from other update types and crucial for testing. While Windows Update rings handle general updates, they lack the granular control over individual drivers/firmware that this scenario requires.
Why the other options are wrong
- B. Quality update policies manage monthly security and bug fixes, not drivers or firmware separately.
- C. Feature update policies manage major Windows version upgrades, not drivers or firmware.
- D. Windows Update rings manage feature and quality updates, but lack granular control over individual drivers/firmware.
Intune Driver and Firmware Update Policies
Intune's Driver and firmware update policies provide granular control over the deployment of drivers and firmware updates to Windows devices, allowing administrators to approve, pause, or roll back specific updates independently from OS updates.
- Separate management from Feature and Quality Updates.
- Allows for testing and phased deployment of drivers/firmware.
- Crucial for stability and compatibility in enterprise environments.
Memory trick: Drivers/Firmware: Separate policies for precision control.