Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Easy
A company uses Microsoft Intune for device management. They want to ensure that all corporate-owned iOS devices receive critical security updates immediately upon release. Which Intune feature allows administrators to control and deploy iOS/iPadOS updates to managed devices?
- AEndpoint security > Security baselines > iOS/iPadOS
- BDevices > Configuration profiles > Create profile > iOS/iPadOS > Device restrictions > General > Software updates
- CApps > iOS/iPadOS > App update policies
- DDevices > iOS/iPadOS > Update policies for iOS/iPadOS
Show answer & explanationAnswer & explanation
Correct answer: D. Devices > iOS/iPadOS > Update policies for iOS/iPadOS
Intune provides a dedicated feature for managing iOS/iPadOS software updates. Update policies allow administrators to defer updates, schedule installations, and enforce compliance on managed devices.
Why the other options are wrong
- A. Security baselines apply recommended security configurations, but do not directly manage the deployment schedule of OS updates.
- B. Device restrictions can control some aspects of updates (e.g., preventing users from delaying), but a dedicated 'Update policy' offers more comprehensive control over deployment schedules and deferrals.
- C. This option relates to application updates, not operating system updates.
Intune iOS/iPadOS Update Policies
A Microsoft Intune feature that allows administrators to manage and control the deployment of iOS/iPadOS operating system updates on supervised and managed devices.
- Allows deferring updates for a specified period.
- Enables scheduling forced update installations.
- Requires devices to be supervised for full control.
Memory trick: Device OS: Update Policies Directly Lead.