Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Easy

A company uses Microsoft Intune for device management. They want to ensure that all corporate-owned iOS devices receive critical security updates immediately upon release. Which Intune feature allows administrators to control and deploy iOS/iPadOS updates to managed devices?

  1. AEndpoint security > Security baselines > iOS/iPadOS
  2. BDevices > Configuration profiles > Create profile > iOS/iPadOS > Device restrictions > General > Software updates
  3. CApps > iOS/iPadOS > App update policies
  4. DDevices > iOS/iPadOS > Update policies for iOS/iPadOS
Show answer & explanation

Correct answer: D. Devices > iOS/iPadOS > Update policies for iOS/iPadOS

Intune provides a dedicated feature for managing iOS/iPadOS software updates. Update policies allow administrators to defer updates, schedule installations, and enforce compliance on managed devices.

Why the other options are wrong

  • A. Security baselines apply recommended security configurations, but do not directly manage the deployment schedule of OS updates.
  • B. Device restrictions can control some aspects of updates (e.g., preventing users from delaying), but a dedicated 'Update policy' offers more comprehensive control over deployment schedules and deferrals.
  • C. This option relates to application updates, not operating system updates.

Intune iOS/iPadOS Update Policies

A Microsoft Intune feature that allows administrators to manage and control the deployment of iOS/iPadOS operating system updates on supervised and managed devices.

  • Allows deferring updates for a specified period.
  • Enables scheduling forced update installations.
  • Requires devices to be supervised for full control.

Memory trick: Device OS: Update Policies Directly Lead.

More Manage devices and apps (55-60%) questions