Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium
A Microsoft 365 Endpoint Administrator is configuring Microsoft Intune to manage corporate-owned Windows 11 devices. The security team requires that all devices automatically install Windows quality updates within 5 days of release and feature updates within 30 days of release. They also want to ensure that devices are rebooted outside of active hours if an update requires a restart. Which Intune policy component should the administrator configure?
- AUpdate rings for Windows 10 and later
- BEndpoint security policies
- CFeature updates for Windows 10 and later
- DDevice configuration profiles
Show answer & explanationAnswer & explanation
Correct answer: A. Update rings for Windows 10 and later
Update rings for Windows 10 and later are specifically designed in Intune to manage the deployment of both quality and feature updates, including deferral periods and restart behavior, for Windows devices.
Why the other options are wrong
- B. Endpoint security policies focus on security features like antivirus, firewall, and disk encryption, not Windows update deployment schedules.
- C. While related to feature updates, this component is used for targeting specific feature update versions, not the general deferral and restart behavior for all updates.
- D. Device configuration profiles manage various settings but not the comprehensive update deployment logic required.
Intune Update Rings
A Microsoft Intune policy type used to manage the timing and behavior of Windows 10/11 quality and feature updates for managed devices.
- Configures deferral periods for both quality and feature updates.
- Controls restart behavior, including active hours.
- Allows for phased deployment by assigning different rings to groups.
Memory trick: Updates Really Need Good Control, Everywhere.