Update Rings Policy Settings
Doc updateThe article removes the Use deadline settings heading and its statement that deadline settings can be configured.
The strongest operational signal is newly explicit guidance for expediting eligible Windows security updates in Intune, including a required Update Health Tools check for Windows versions earlier than 24H2. The period also adds a gated feature-update migration sequence, a co-management timing caveat, a Hybrid Entra joined Autopilot OOBE issue, and a PowerShell installer workflow for Win32 apps. Most remaining Update Rings edits are table, heading, navigation, or link restructuring rather than evidence of policy-behavior changes; no preview or general-availability transition is identified.
The Quality Updates Policy article now describes expedited Windows quality updates in Intune. Only eligible Windows security updates can be expedited; regular monthly quality updates remain an Update Rings workload. The guidance says expedited policies temporarily override deferrals and other settings, select one update by release date, and require Microsoft Update Health Tools on Windows versions earlier than 24H2, installable through KB4023057 or manually.
Feature Updates Policy guidance now warns that applying update-ring deferrals alongside a feature-updates policy can delay an update because both policy conditions must be met. The prescribed sequence is to create and assign the feature-update policy, wait until the Windows feature updates Organizational report shows OfferReady for all devices, and then set Feature update deferral period (days) in the update ring to 0. Windows Update processing can take up to 10 minutes. This is migration guidance, not a stated new
The Windows Autopilot Known Issues page adds an issue, dated January 13, 2026, in which Quality Update scans offered during OOBE may time out during Hybrid Entra joined provisioning when Allow OOBE Updates is configured in the Enrollment Status Page profile. Affected devices do not receive those Quality Updates during OOBE. The issue affects KB5041571 and later and is under investigation.
The What's New entry for the week of January 12 describes a PowerShell script installer for Win32 apps. Administrators can upload a script instead of specifying a command line; Intune packages it with the app content, runs it in the same context as the app installer, and reports installation results from the script's return code. The workflow supports prerequisite checks, configuration changes, and post-install actions.
Feature Updates Policy now adds a co-management warning: when the Windows Update policies workload is newly configured for Intune, feature-update policies might not take effect immediately. The temporary delay can initially allow devices to update to a later feature-update version than the one configured in policy. This is a rollout caveat added to the guidance, not a stated change to policy behavior.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
The article removes the Use deadline settings heading and its statement that deadline settings can be configured.
The quality updates policy article adds an Expedite Windows quality updates in Microsoft Intune section.
The Update settings heading changes from level three to level two while the former settings table is removed.
A new reference article documents Windows Update settings available through Intune Update Ring policies.
A reference article was added for Windows Update settings manageable through Intune Update Ring policies.
The article removes its Setting, Description, and CSP Reference table and begins converting Microsoft product updates guidance to a section-based layout.
The article deletes a commented legacy introduction describing feature and quality servicing updates.
The article date is updated from July 15, 2024 to January 12, 2026 and the Microsoft product update setting is reformatted.
The settings table adds Windows drivers Allow/Block with the ExcludeWUDriversInQualityUpdate CSP and explains 0–30 day quality update deferrals; it also corrects the Microsoft Update CSP link.
A commented legacy description about holding devices at a specific feature update version is removed.
The reference removes Automatic behavior frequency, Scheduled install day, and Scheduled install time from its automatic update behavior guidance.
Only blank lines were added to the update rings policy settings article.
Microsoft product updates is converted from a heading and list to a bold setting label with Allow and Block choices.
The Validation and reporting section is removed and a Co-management considerations section is introduced.
The settings table adds the BranchReadinessLevel CSP reference to Enable pre-release builds and removes a general behavior-reference sentence.
The reference now states that feature update deferrals can be set from 0 to 365 days and adjusts prerelease build formatting.
The article removes wording that update rings shape installation timing and removes the direct link to the policy settings reference from the creation step.
The reference removes Restart checks (EDU Restart), the user option to pause updates, and the user option to check for updates while retaining expanded automatic update behavior guidance.
The update rings article removes the listed feature deferral, uninstall period, and prerelease-build entries from its limitations text.
Microsoft product updates and Windows drivers headings are changed from level-three to level-four headings.
Automatic update behavior changes back from a level-five heading to a bold label and the EDU Restart heading is adjusted.
A commented legacy introduction explaining approvals, pauses, and recommended versus optional drivers is removed.
The article links multiple-policy behavior to update-rings-policy-settings.md and replaces a creation-section link with the feature updates article root.
Automatic update behavior changes from a bold label to a level-five heading.
The policy creation steps now direct administrators to update-rings-policy-settings.md instead of settings.md for available Update ring settings.
The shared device-configuration include path is corrected from three parent levels to two.
The Microsoft Account Sign-In Assistant service requirement is changed from a list item to a direct note.
The policy reference expands Automatic update behavior with Notify download, maintenance-time installation and restart, scheduled installation, no end-user restart control, and reset-to-default behavior, including Active Hours and AllowAutoUpdate references.
A blank callout spacer separates adjacent controls in the Update Ring settings guidance.
Option to pause Windows updates changes from a level-four heading to a bold setting label.
The former expedite-updates.md article was removed after expedited quality update guidance was incorporated into quality-updates-policy.md.
The quality updates article removes its inline prerequisites heading and shared licensing include during content reorganization.
The move-from-update-ring-deferrals-to-feature-updates-policy article was removed after its guidance moved into feature-updates-policy.md.
ring-policy-settings.md, another Update Ring policy settings reference, was removed.
settings.md, the reference for Windows Update settings in Intune Update Ring policies, was removed.
The migration guidance carries a January 8, 2026 date, indicating its planned review point.
The article date changes from December 15, 2025 to January 8, 2026.
The What's New page adds a Week of January 12, 2026 section for Enterprise App Catalog Win32 installer script support.
The article date is updated and spacing is normalized for the iOS/iPadOS Managed property row.
The title and description now describe managing common administrative tasks centrally across Intune capabilities.
The article is renamed Centrally manage common admin tasks in Microsoft Intune.
The What's New entry replaces a delay notice with availability beginning January 13, 2026 and identifies the 2026-01 B quality update as the first offered update.
The article date is updated to January 12, 2026 and the User permissions to use reports heading is removed.
The report introduction retains the deployment and status description but removes the detailed Intune navigation path and default-policy screenshot.
Known issues is renamed Known issues and limitations and gains an API operator support limitations subsection.
The article removes the Windows quality update distribution report heading and its description of per-quality-update device counts.
The QU device version tab now uses the device-version anchor instead of feature-version.
The article removes its Prerequisites and Licensing headings during requirements-content consolidation.
The former settings page removes its introductory Update settings text and renames its main section to Update rings settings as content moves to policy-specific references.
The article is retitled Update rings policy settings and moves Windows 10-to-latest Windows 11 upgrade information into the reorganized settings layout.
The supported-workloads table changes Settings catalog (DDM) from unsupported to supported.
The expedited-update content participates in the move toward a consolidated quality update policy experience.
The policy settings guidance removes an interim Update rings settings section heading as the reference is reorganized around the policy configuration flow.
The article date is updated and its Windows OS Edition filter guidance is revised as part of the January release.
The supported OEMConfig app table adds FCNT Senior Care, FCNT Schema, and Sonim package identifiers.
The supported OEMConfig applications table adds X with package identifier com.X.rgoem.
The article explains that selecting two or more Android management modes displays settings that apply to at least one selected mode.
The article recommends ending update-ring deferrals when using feature update policies because combining them can delay installation; user-experience settings can remain.
Known issues now includes Devices don't get Quality Updates during Hybrid Entra joined deployments, dated January 13, 2026.
The Enterprise App Catalog article updates its date and describes the Win32 app type as supporting customizable capabilities including PowerShell script installers.