← Previous day

Next day →
Day in brief

Certificate Sync guidance and expedited-update prerequisites sharpen Intune patch planning

The 9 January period is dominated by substantive Microsoft Learn reorganization around Windows update policy surfaces and Mobile Threat Defense connector guidance. The most actionable material documents prerequisites that can block expedited quality updates and adds certificate-inventory sharing details for iOS/iPadOS MTD connectors. New feature-update guidance also clarifies safeguard holds and persistent version targeting, while Autopatch documentation reinforces service-managed update rings. The supplied evidence shows no Message Center announcements, removals, retirements, or confirmed preview/general-availability changes; reviewer-metadata edits have no administrator impact.

  • The new Windows quality update policy how-to says Beta and Dev preview builds aren't supported with expedited updates, so Enable pre-release builds should be Not configured. It recommends Automatic update behavior = Reset to default and a notification setting other than Turn off all notifications, including restart warnings. It also identifies CorpWuURL, AutoUpdateCfg, DeferFeatureUpdates, and Disable Dual Scan as Group Policy settings that can interfere and should be restored to device defaults. This is explicit s

  • The connector setup guidance now documents Enable Certificate Sync for iOS/iPadOS devices, allowing an MTD partner to request installed-certificate lists for threat analysis. Certificate data is updated during device check-in. Personally owned devices have a separate full-inventory setting: On shares managed and unmanaged certificates, while Off sends no certificate data; the setting has no effect on corporate devices, for which Intune sends both types when requested.

  • The Windows Update rings policy overview says rings control deferrals, restart settings, deadlines, active hours, and notifications, and can stage test, pilot, and production groups. Its Autopatch note says the service may create and maintain rings for rollout cadence and restart behavior, so administrators typically shouldn't assign custom rings to Autopatch-managed devices. The removal of the earlier Microsoft Entra registered-device limitations section is a documentation change, not evidence of expanded support.

  • The new Windows feature update policies article states that a device already running a later Windows version remains on that version, while a safeguard hold blocks installation until the known issue is resolved. Unlike an update-ring pause, which expires after 35 days, the feature-updates policy remains until modified or removed. The article also says cloud-deployed feature updates automatically include the latest monthly quality update and documents the Devices > Windows > Windows updates > Feature updates >Create

  • The revised Manage Windows driver updates article explains that OEM driver and firmware releases can affect reliability, security, and hardware support. It describes Intune driver updates policies as supporting automatic or manual approval workflows, giving administrators a documented way to review recommended drivers before deployment rather than deploying them automatically.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

48 updates

34

Mobile Threat Defense

Feature update

Mobile Threat Defense connector guidance was expanded with certificate synchronization content and refreshed connector-status material.

Mtd Connector Enable

Feature update

The connector setup guidance states that Certificate Sync data is sent to Mobile Threat Defense partners at an interval based on device check-in.

Mobile Threat Defense

Doc update

The only changed line updates the reviewer metadata from demerson to ilwu.

Mtd Connector Enable

Doc update

The only changed line updates the reviewer metadata from aanavath to ilwu.

9

Windows quality update policy

Doc update

The article description now covers managing Windows quality updates with quality update policies, expedited updates, and Hotpatch to maintain security and compliance.

Manage Windows driver updates

Doc update

The article is retitled Manage Windows driver updates and adds context that OEM driver and firmware releases can affect reliability, security, and hardware support, so organizations may prefer controlled approval.

Windows Update rings policy

Doc update

The article adds an overview of update ring policies: they control deferrals, restart settings, deadlines, active hours, and notifications, and can define test, pilot, and production stages alongside feature, quality, and driver policies.

Expedite Updates

Doc update

The expedited updates article removes its How expedited updates work section as content is reorganized.

Index

Doc update

The overview now describes Autopatch as an Intune-integrated service for keeping Windows devices protected, and explains that feature, quality, and driver update policies use the same orchestration service but can be managed directly without Autopatch enrollment.

Manage Windows feature updates

Doc update

The article title changes from Configure Windows feature updates releases to Manage Windows feature updates and replaces its introductory description.

Quality Updates Policy

Feature update

The quality update policy prerequisites visually separate the update-ring settings table, which requires Enable pre-release builds to remain Not configured because Beta and Dev builds are unsupported for expedited updates.

2
1
1
1

Properties Catalog

Doc update

The requirements now include Microsoft Entra hybrid joined devices alongside corporate-owned, Intune-managed, and Entra joined devices.

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…