Index
Doc updateThe Windows updates overview simplifies the policy list and specifies that quality updates include monthly security and reliability updates, expedited updates, and Hotpatch for eligible security patches without reboot.
The substantive work centered on Windows update administration rather than a new Intune policy launch. A new Windows Driver Update Management overview documents approval, pause, and automatic-versus-manual deployment choices; refreshed prerequisites state public-cloud scope, Intune Plan 1, and a Windows license with the Autopatch entitlement. Autopatch guidance says it orchestrates existing Intune policies and should not be paired with custom rings, while the quality-updates overview folds Hotpatch into the policy description and says eligible security patches can apply without a reboot. Feature-update reporting also gains a precise initial-scan note. Most other edits were link, title, formatting, or wording maintenance: the removed Markdown driver FAQ was an md-to-yml migration, not a capability retirement. Admin Tasks should not be treated as confirmed GA: its article removes the public-preview label, but the in-development entry still says general availability is forthcoming and supplies no date.
A new overview page describes Windows Driver Update Management as a controlled workflow: admins can review, approve, or pause updates. Automatic-approval policies deploy each new driver version identified as recommended, while manual-approval policies add newer versions but leave them inactive until approved. This is new documentation for the capability, not evidence of a new service launch.
The Windows updates index removes the standalone Hotpatch block and folds it into quality updates. The revised text defines monthly cumulative updates as security and reliability updates, with expedited updates able to override deferrals and deadlines and Hotpatch applying eligible security patches without reboot. This clarifies placement and documented behavior; it is not a separate Intune policy launch.
The revised comparison describes Windows Autopatch as integrated with Intune and orchestrating existing update policies instead of introducing new policy types. It says Autopatch creates and manages its own rings, so administrators shouldn't assign custom rings to Autopatch devices. This is guidance clarification, not evidence of a new Autopatch rollout.
The Feature Updates article now states that End user update status Last Scanned Time returns Not scanned yet until a user logs on and Update Session Orchestrator initiates a scan. It also points readers to the dedicated feature-update reports article. The edit clarifies report interpretation and navigation rather than announcing changed scan behavior.
The catalog guidance now explicitly says Microsoft doesn't assert compliance, authorization, authenticity, or integrity for apps distributed through Intune; customers remain responsible for their requirements. It also states that Service Level Objectives are guidelines, not guarantees. This is security and due-diligence guidance, not a change to catalog app validation.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
The Windows updates overview simplifies the policy list and specifies that quality updates include monthly security and reliability updates, expedited updates, and Hotpatch for eligible security patches without reboot.
The update-ring-to-feature-update migration guide now links OfferReady validation to the dedicated feature update reports article.
The Markdown driver-updates-faqs article was removed in an md-to-yml content migration.
A complete Windows Driver update management overview was added, documenting approvals, pauses, prerequisites, supported editions, cloud limitations, RBAC, deployment planning, and reporting.
The driver update overview restructures cloud, licensing, device, and configuration prerequisites into shared requirements content.
The overview describes Autopatch as an Intune-integrated service that orchestrates existing policies and adds dynamic grouping, phased rollout, health monitoring, compliance reporting, Hotpatch, and expedited delivery; its comparison table is reformatted.
The feature updates article standardizes status formatting, clarifies that a user logon starts the initial USO scan for Last Scanned Time, and generalizes Windows 10/11 reporting text to Windows devices.
The driver policy article is retitled Manage Windows driver update policies, adds a Before you begin section linking overview requirements, and clarifies that admins can create, approve, deploy, and pause individual driver updates.
The driver update article removed a shared cloud-requirements block as its prerequisites were reorganized.
The update rings article replaces links in its unsupported-setting list with plain setting names: pause, feature deferral, uninstall period, and pre-release builds.
The FAQ title and description now explicitly identify it as frequently asked questions about Windows driver update policies.
Driver update licensing and supported-edition wording was generalized and an image path was corrected.
The driver updates overview removed its explicit GCC and GCC High/DoD Autopatch subscription-activation notice.
The article removed its standalone Workplace Joined limitation section and link to the former configure page.
The expedited update article removes a duplicate data-collection statement and changes the Policy CSP link label.
A formatting-only block was added to the Windows updates index as part of redirect maintenance.
The update rings article removed its Validation and reporting section and link to the former shared Windows update reports page.
Windows Holographic for Business guidance now links to the Windows software updates index.
The archive updates links for feature update, optional feature update, and Windows update distribution reports to their new dedicated articles.
The planned integration entry was restored: it describes turning offboarding recommendations into assignable, monitored, and completable Admin Tasks.
The report article is now titled Reports for Windows feature updates policies and its description focuses on reports for those policies; the data-collection prerequisite wording was simplified.
The article title and description now specifically identify reports for Windows quality update policies.
The article title and description now specifically identify reports for Windows update rings policies.
The article removed its standalone Workplace Joined limitations text and former configure-page reference.
The iOS/iPadOS line-of-business app article updates its date and clarifies existing app-addition instructions without changing the workflow.
The article clarifies that multiple Intune app instances can share a bundle ID but targeting separate instances can create unexpected device behavior; beta and production apps need different bundle identifiers.
The in-development page temporarily removed the planned Device Offboarding Agent and Admin Tasks integration entry.
The in-development page corrects the Markdown emphasis for the planned general availability of Admin tasks.
The Admin Tasks article updates its date and removes the statement that the feature is in public preview.
The guide now links directly to Reports for update rings policies.
The cloud-native Windows endpoint guide updates a reference as part of the Windows updates documentation reorganization.
The Windows Holographic custom-setting guidance now links to the Windows updates index for Windows Update client policies.
The Windows Holographic UpdateServiceUrl custom-setting guidance now links to the Windows updates index.
The device protection article now links its Windows update-management reference to the Windows updates index.
The privacy article corrects the audit-log retention phrase to two years.
The settings catalog article updates its date and removes a redundant feature-applies-to section.
The planning guide now points Manage Windows software updates in Intune to the Windows updates index.
The FAQ describes its Configuration Manager coexistence procedure as supported for Windows 11 and redirects its driver/firmware data-collection link to the overview prerequisites.
The article refreshes wording around the Intune Suite add-on and customer responsibility for application compliance and authorization.
A FAQ heading now asks how Microsoft can detect whether an Enterprise App Catalog application is in use.