Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium
A Microsoft 365 Endpoint Administrator is configuring Microsoft Intune to manage corporate-owned Windows 11 devices. The organization requires that all devices automatically install critical and security updates as soon as they are available, but feature updates should be deferred for 30 days to allow for compatibility testing. You need to configure an update policy to meet these requirements. Which Intune configuration should you use?
- AQuality updates for Windows 10 and later
- BUpdate policies for Windows 10 and later
- CWindows update rings
- DFeature updates for Windows 10 and later
Show answer & explanationAnswer & explanation
Correct answer: C. Windows update rings
Windows update rings allow for the configuration of both quality (critical/security) and feature update deferrals within a single policy, meeting all specified requirements. Feature updates for Windows 10 and later and Quality updates for Windows 10 and later are more granular policies, but the update ring is the comprehensive solution for both.
Why the other options are wrong
- A. This policy type specifically manages quality updates and would not address the deferral requirement for feature updates.
- B. This is a general category, not a specific configurable policy type within Intune that combines both requirements in one place as efficiently as update rings.
- D. This policy type specifically manages feature updates and would not address the immediate installation requirement for critical and security updates.
Intune Windows Update Rings
A configuration profile in Microsoft Intune used to manage how and when Windows devices receive updates, including deferral periods for both quality and feature updates.
- Manages both feature and quality updates.
- Allows deferral of updates for testing.
- Can be assigned to device groups.
Memory trick: Rings of Protection defer updates, but critical ones ring true immediately.