← Previous day

Next day →
Day in brief

Expedite policy guidance sets CVSS 9.0 triage and Windows prerequisites

14 January was primarily a documentation-consolidation day, but several updates have direct planning value. A new Expedite Policies for Windows Quality Updates how-to defines emergency-update scope and prerequisites, while Vulnerability Remediation Agent guidance points “Expedite” recommendations at CVEs with CVSS risk values of 9.0 or greater. Updated Win32 app guidance describes PowerShell script installers, and Windows feature-update guidance clarifies optional installation and persistent version targeting. Rollout Options adds specific offer-group and Windows Autopatch processing requirements, while Advanced Analytics documents saved device-query workflows. The removed Expedite Quality Updates item is a documentation-page retirement, not evidence that expedite policies themselves were retired; no preview or general-availability status is supplied.

  • New Intune guidance describes an expedite policy as targeting one supported Windows security update. It says the update installs as soon as possible, bypassing deferral settings and normal deployment timing without pausing or changing monthly quality-update policies; regular monthly servicing remains with update rings or Windows quality-update policies. Before using it, the page calls for Windows quality-update prerequisites, **Enable pre-release builds = Not configured**, **Automatic update behavior = Reset to

  • Updated Win32 app guidance describes an **Installer type** choice between **Command line** and **PowerShell script**. The script is packaged with app content, replaces the standard install command, runs in the app installer's system or user context, and uses its return code for Intune success or failure reporting. Scripts are limited to **50 KB** and should run silently. With Multi-Admin Approval enabled, scripts can't be uploaded during app creation; create the app first, then add or modify scripts. The guidance И

  • Updated feature-update policy guidance says a device already on a newer Windows version isn't downgraded, and the policy remains in effect until modified or removed; an update-ring pause expires after **35 days**. For an **Optional** feature update, users must open **Windows Update** in device settings and select **Download**; without that action, it isn't installed unless an admin later changes it to **Required**. This is an explicit user-experience and policy-behavior clarification in the guidance, not a stated

  • Updated Rollout Options guidance says **First group availability** must be at least two days in the future; **Final group availability** controls when remaining devices receive the offer, and **Days between groups** determines offer-group frequency. Groups are assigned randomly and evenly with a minimum of 100 devices; changing dates or spacing recalculates groups for devices that have not yet received the offer. For intelligent rollouts, enable **Allow Windows Update for Business Cloud Processing** in a settings-c

  • Updated Advanced Analytics guidance documents the **Saved Queries** workflow in **Devices > Device query**. Admins can save **Personal queries** visible only to themselves or **Shared queries** available to other Intune admins; personal queries can be changed or deleted, while shared queries can't be edited or deleted. A personal query can be converted to shared, so the page advises finalizing it first. This is a documented workflow addition; no preview or GA state is stated.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

30 updates

16

Rollout Options

Updated

Updated Microsoft Intune documentation in intune/device-updates/windows/rollout-options.md.

Feature Updates

Updated

Updated Microsoft Intune documentation in intune/device-updates/windows/feature-updates.md.

Feature Updates

Updated

Updated Microsoft Intune documentation in intune/device-updates/windows/feature-updates.md.

Driver Updates Policy

Updated

Updated Microsoft Intune documentation in intune/device-updates/windows/driver-updates-policy.md.

Index

Updated

Updated Microsoft Intune documentation in intune/device-updates/windows/index.md.

Expedite Quality Updates

Removed

Removed Microsoft Intune documentation in intune/device-updates/windows/expedite-quality-updates.md.

6

**Summary report**

Updated

Updated Microsoft Intune documentation in intune/device-updates/windows/expedite-quality-updates.md.

**Device report**

Updated

Updated Microsoft Intune documentation in intune/device-updates/windows/expedite-quality-updates.md.

4
2

Role Based Access Control

Updated

Updated Microsoft Intune documentation in intune/intune-service/fundamentals/role-based-access-control.md.

2
Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…