← Previous day

Next day →
Day in brief

Expedited Windows quality updates and PowerShell installers sharpen Intune operations

The strongest operational signal is newly explicit guidance for expediting eligible Windows security updates in Intune, including a required Update Health Tools check for Windows versions earlier than 24H2. The period also adds a gated feature-update migration sequence, a co-management timing caveat, a Hybrid Entra joined Autopilot OOBE issue, and a PowerShell installer workflow for Win32 apps. Most remaining Update Rings edits are table, heading, navigation, or link restructuring rather than evidence of policy-behavior changes; no preview or general-availability transition is identified.

  • The Quality Updates Policy article now describes expedited Windows quality updates in Intune. Only eligible Windows security updates can be expedited; regular monthly quality updates remain an Update Rings workload. The guidance says expedited policies temporarily override deferrals and other settings, select one update by release date, and require Microsoft Update Health Tools on Windows versions earlier than 24H2, installable through KB4023057 or manually.

  • Feature Updates Policy guidance now warns that applying update-ring deferrals alongside a feature-updates policy can delay an update because both policy conditions must be met. The prescribed sequence is to create and assign the feature-update policy, wait until the Windows feature updates Organizational report shows OfferReady for all devices, and then set Feature update deferral period (days) in the update ring to 0. Windows Update processing can take up to 10 minutes. This is migration guidance, not a stated new

  • The Windows Autopilot Known Issues page adds an issue, dated January 13, 2026, in which Quality Update scans offered during OOBE may time out during Hybrid Entra joined provisioning when Allow OOBE Updates is configured in the Enrollment Status Page profile. Affected devices do not receive those Quality Updates during OOBE. The issue affects KB5041571 and later and is under investigation.

  • The What's New entry for the week of January 12 describes a PowerShell script installer for Win32 apps. Administrators can upload a script instead of specifying a command line; Intune packages it with the app content, runs it in the same context as the app installer, and reports installation results from the script's return code. The workflow supports prerequisite checks, configuration changes, and post-install actions.

  • Feature Updates Policy now adds a co-management warning: when the Windows Update policies workload is newly configured for Intune, feature-update policies might not take effect immediately. The temporary delay can initially allow devices to update to a later feature-update version than the one configured in policy. This is a rollout caveat added to the guidance, not a stated change to policy behavior.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

60 updates

35

Update Rings Policy Settings

Doc update

The article removes the Use deadline settings heading and its statement that deadline settings can be configured.

Quality Updates Policy

Doc update

The quality updates policy article adds an Expedite Windows quality updates in Microsoft Intune section.

Update Rings Policy Settings

Doc update

The Update settings heading changes from level three to level two while the former settings table is removed.

Update Rings Policy Settings

Doc update

The article removes its Setting, Description, and CSP Reference table and begins converting Microsoft product updates guidance to a section-based layout.

Update Rings

Doc update

The article deletes a commented legacy introduction describing feature and quality servicing updates.

Settings

Doc update

The settings table adds Windows drivers Allow/Block with the ExcludeWUDriversInQualityUpdate CSP and explains 0–30 day quality update deferrals; it also corrects the Microsoft Update CSP link.

Feature Updates

Doc update

A commented legacy description about holding devices at a specific feature update version is removed.

Update Rings Policy Settings

Doc update

The reference removes Automatic behavior frequency, Scheduled install day, and Scheduled install time from its automatic update behavior guidance.

Update Rings Policy Settings

Doc update

Microsoft product updates is converted from a heading and list to a bold setting label with Allow and Block choices.

Feature Updates Policy

Doc update

The Validation and reporting section is removed and a Co-management considerations section is introduced.

Settings

Doc update

The settings table adds the BranchReadinessLevel CSP reference to Enable pre-release builds and removes a general behavior-reference sentence.

Update Rings Policy Settings

Doc update

The reference now states that feature update deferrals can be set from 0 to 365 days and adjusts prerelease build formatting.

Update Rings

Doc update

The article removes wording that update rings shape installation timing and removes the direct link to the policy settings reference from the creation step.

Update Rings Policy Settings

Doc update

The reference removes Restart checks (EDU Restart), the user option to pause updates, and the user option to check for updates while retaining expanded automatic update behavior guidance.

Update Rings

Doc update

The update rings article removes the listed feature deferral, uninstall period, and prerelease-build entries from its limitations text.

Update Rings Policy Settings

Doc update

Microsoft product updates and Windows drivers headings are changed from level-three to level-four headings.

Update Rings Policy Settings

Doc update

Automatic update behavior changes back from a level-five heading to a bold label and the EDU Restart heading is adjusted.

Driver Updates

Doc update

A commented legacy introduction explaining approvals, pauses, and recommended versus optional drivers is removed.

Feature Updates Windows 10

Doc update

The article links multiple-policy behavior to update-rings-policy-settings.md and replaces a creation-section link with the feature updates article root.

Update Rings

Doc update

The policy creation steps now direct administrators to update-rings-policy-settings.md instead of settings.md for available Update ring settings.

Update Rings

Doc update

The shared device-configuration include path is corrected from three parent levels to two.

Update Rings

Doc update

The Microsoft Account Sign-In Assistant service requirement is changed from a list item to a direct note.

Update Rings Policy Settings

Doc update

The policy reference expands Automatic update behavior with Notify download, maintenance-time installation and restart, scheduled installation, no end-user restart control, and reset-to-default behavior, including Active Hours and AllowAutoUpdate references.

Expedite Updates

Doc update

The former expedite-updates.md article was removed after expedited quality update guidance was incorporated into quality-updates-policy.md.

Quality Updates

Doc update

The quality updates article removes its inline prerequisites heading and shared licensing include during content reorganization.

Ring Policy Settings

Doc update

ring-policy-settings.md, another Update Ring policy settings reference, was removed.

Settings

Doc update

settings.md, the reference for Windows Update settings in Intune Update Ring policies, was removed.

7

Migrate To Intune

Doc update

The migration guidance carries a January 8, 2026 date, indicating its planned review point.

Migrate To Intune

Doc update

The article date changes from December 15, 2025 to January 8, 2026.

Whats New

Feature update

The What's New page adds a Week of January 12, 2026 section for Enterprise App Catalog Win32 installer script support.

Filters Device Properties

Doc update

The article date is updated and spacing is normalized for the iOS/iPadOS Managed property row.

Centrally manage Admin Tasks

Doc update

The title and description now describe managing common administrative tasks centrally across Intune capabilities.

Whats New

Feature update

The What's New entry replaces a delay notice with availability beginning January 13, 2026 and identifies the 2026-01 B quality update as the first offered update.

6

Reports for update rings policies

Doc update

The report introduction retains the deployment and status description but removes the detailed Intune navigation path and default-policy screenshot.

Troubleshoot

Doc update

Known issues is renamed Known issues and limitations and gains an API operator support limitations subsection.

**QU distribution**

Doc update

The article removes the Windows quality update distribution report heading and its description of per-quality-update device counts.

**QU device version**

Doc update

The QU device version tab now uses the device-version anchor instead of feature-version.

Compatibility Reports

Doc update

The article removes its Prerequisites and Licensing headings during requirements-content consolidation.

5

Update rings policy settings

Doc update

The article is retitled Update rings policy settings and moves Windows 10-to-latest Windows 11 upgrade information into the reorganized settings layout.

Expedite Updates

Doc update

The expedited-update content participates in the move toward a consolidated quality update policy experience.

3

Settings Catalog

Feature update

The article date is updated and its Windows OS Edition filter guidance is revised as part of the January release.

1

Settings Catalog

Doc update

The article explains that selecting two or more Android management modes displays settings that apply to at least one selected mode.

1

Feature Updates Policy

Feature update

The article recommends ending update-ring deferrals when using feature update policies because combining them can delay installation; user-experience settings can remain.

1

Known Issues

Doc update

Known issues now includes Devices don't get Quality Updates during Hybrid Entra joined deployments, dated January 13, 2026.

1
Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…