A dedicated quality updates policy article was added, covering Hotpatch security updates without restart.
Entra-registered devices remain limited to Windows update rings
Windows Update policy and reporting content was extensively reorganized this week, but the consequential guidance is specific: Windows Update for Business Deployment Service-backed policies exclude Microsoft Entra-registered devices, Hotpatch has a defined eligibility chain, and driver approvals have documented constraints. Outside Windows servicing, Configuration Manager's MDT retirement carries an immediate cleanup sequence, while a February Intune release will extend Managed Home Screen permissions in built-in roles.
- WUfB DS-backed update policies exclude Microsoft Entra-registered devices
Intune · Device updates
The Windows updates overview now states that Feature updates, Quality updates, Driver updates, and Hotpatch policies rely on the Windows Update for Business Deployment Service and aren't supported on Microsoft Entra-registered devices. Those devices remain supported through Windows Update client policies and update rings. This is a documented eligibility boundary, not a newly announced enforcement change.
- Hotpatch guidance ties eligibility to Autopatch, Windows 11 24H2, and VBS
Intune · Device updates
The dedicated quality-update guidance documents Hotpatch as Monthly B release security updates that install and take effect without a restart. It lists Autopatch, Windows 11 Enterprise version 24H2 or later, the latest baseline release, an Intune quality update policy with Hotpatch enabled, and VBS turned on among the prerequisites. This adds concrete deployment guidance rather than announcing a new Hotpatch launch.
- Driver FAQ documents approval conflicts, Autopilot, filters, and rollback limits
Intune · Device updates
The driver-update FAQ states that Driver Updates don't support Assignment Filters or Windows Autopilot, and that Windows Update client policies don't support driver rollback. Multiple policies per device are supported but not recommended: if one policy approves an update and another pauses it, the approved status wins and the driver installs. The guidance points to small deployment rings and manual approval or monitoring for safer rollout.
- MDT retirement requires task-sequence cleanup before integration removal
Configuration Manager · Fundamentals
Configuration Manager release notes now warn that Microsoft Deployment Toolkit integration and MDT Standalone are retired and unsupported. Administrators must remove all MDT task-sequence steps first and then remove MDT integration to prevent task-sequence corruption and modification failures; Windows Autopilot or supported Configuration Manager OSD are suggested alternatives.
- Managed Home Screen adds two permissions to built-in roles in February
Intune · Tenant administration
The planned February Intune release adds TemporarilySuspendManagedHomeScreen and RestoreManagedHomeScreen to the School Administrator and Help Desk Operator built-in roles. Microsoft says no administrator action is required, but organizations using those roles should review role assignments and update their internal permissions documentation.
Prioritize the documented Windows Update eligibility and prerequisite checks, and remove MDT task-sequence steps before removing MDT integration. Driver administrators should use staged deployment rings and avoid conflicting policies. The Managed Home Screen change requires no action, although role assignments and internal documentation may merit review. Treat ordinary retitles, link moves, and prerequisite consolidation as documentation maintenance. Also, removal of the “public preview” label from the Admin Tasks article does not establish general availability; the in-development page still says the capability will soon be generally available.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Intune
154 updatesThe article description now covers managing Windows quality updates with quality update policies, expedited updates, and Hotpatch to maintain security and compliance.
The article is retitled Manage Windows driver updates and adds context that OEM driver and firmware releases can affect reliability, security, and hardware support, so organizations may prefer controlled approval.
Windows Update rings policy
UpdatedThe article adds an overview of update ring policies: they control deferrals, restart settings, deadlines, active hours, and notifications, and can define test, pilot, and production stages alongside feature, quality, and driver policies.
A dedicated article was added for feature update policy settings and creating feature update releases.
Expedite Updates
UpdatedThe expedited updates article removes its How expedited updates work section as content is reorganized.
Index
UpdatedThe overview now describes Autopatch as an Intune-integrated service for keeping Windows devices protected, and explains that feature, quality, and driver update policies use the same orchestration service but can be managed directly without Autopatch enrollment.
The article title changes from Configure Windows feature updates releases to Manage Windows feature updates and replaces its introductory description.
Quality Updates Policy
UpdatedThe quality update policy prerequisites visually separate the update-ring settings table, which requires Enable pre-release builds to remain Not configured because Beta and Dev builds are unsupported for expedited updates.
Driver Updates
UpdatedThe driver updates article adds a shared network-prerequisites include.
Index
UpdatedThe index advises tenants blocked from creating Autopatch-required policies under EA licensing to contact their account team or licensing partner.
Feature Updates
UpdatedThe feature update article removes a shared cloud-requirements block.
Driver Updates Policy
UpdatedThe driver policy article removes its former Create Windows driver update policies heading and introductory procedure text.
The article is retitled Windows driver update management and updates its introductory wording and applicable-platform presentation.
Driver Updates
UpdatedThe driver updates article removes shared platform and other prerequisite blocks as content is consolidated into reusable requirement sections.
Driver Updates Policy
UpdatedThe article warns that update rings and Settings Catalog can block drivers, and specifies Windows driver = Allow and Exclude WU Drivers in Quality Update = Allow Windows Update drivers.
Driver Updates Policy
UpdatedThe article removes the earlier detailed callout about update-ring and Settings Catalog settings that block drivers.
Index
UpdatedThe Windows updates index removes the table comparing manual and Autopatch update coordination.
Driver Updates Policy
UpdatedThe Windows driver and Exclude WU Drivers setting guidance received indentation fixes.
Index
UpdatedThe overview says feature, quality, and driver update policies share the Autopatch orchestration layer and have the same prerequisites across those three types.
Driver Updates
UpdatedThe driver updates article replaces the inline RBAC-permissions list with shared tenant and RBAC prerequisite content.
Index
UpdatedThe Windows updates index adds that updates fail when the Microsoft Account Sign-In Assistant service is blocked or disabled, and notes its default Manual (Trigger Start) setting.
Quality Updates
UpdatedThe quality updates article now includes a reusable licensing-prerequisites section.
Expedite Updates
UpdatedThe expedited updates article removed its explicit unsupported-cloud notice for GCC and GCC High/DoD environments.
Index
UpdatedThe index changes feature, quality, and driver update references to explicitly say policy.
Index
UpdatedThe note about the Microsoft Account Sign-In Assistant service was formatted as a nested callout.
Index
UpdatedThe index corrects plural wording for feature, quality, and driver update policies.
Index
UpdatedThe prerequisites emphasize Microsoft Entra joined or hybrid joined devices; Microsoft Entra registered devices remain limited to Windows Update client policies and update rings.
Driver Updates
UpdatedA blank line was removed from the driver updates article.
Driver Updates Overview
RemovedThe Markdown driver-updates-overview article was removed in a table-of-contents update.
Rollout Options
UpdatedThe rollout options article removes the warning that gradual rollout would be unavailable after October 14, 2025.
Index
UpdatedThe Windows updates overview simplifies the policy list and specifies that quality updates include monthly security and reliability updates, expedited updates, and Hotpatch for eligible security patches without reboot.
The update-ring-to-feature-update migration guide now links OfferReady validation to the dedicated feature update reports article.
Driver Updates Faqs
RemovedThe Markdown driver-updates-faqs article was removed in an md-to-yml content migration.
A complete Windows Driver update management overview was added, documenting approvals, pauses, prerequisites, supported editions, cloud limitations, RBAC, deployment planning, and reporting.
Driver Updates
UpdatedThe driver update overview restructures cloud, licensing, device, and configuration prerequisites into shared requirements content.
Index
UpdatedThe overview describes Autopatch as an Intune-integrated service that orchestrates existing policies and adds dynamic grouping, phased rollout, health monitoring, compliance reporting, Hotpatch, and expedited delivery; its comparison table is reformatted.
Feature Updates
UpdatedThe feature updates article standardizes status formatting, clarifies that a user logon starts the initial USO scan for Last Scanned Time, and generalizes Windows 10/11 reporting text to Windows devices.
The driver policy article is retitled Manage Windows driver update policies, adds a Before you begin section linking overview requirements, and clarifies that admins can create, approve, deploy, and pause individual driver updates.
Driver Updates
UpdatedThe driver update article removed a shared cloud-requirements block as its prerequisites were reorganized.
Update Rings
UpdatedThe update rings article replaces links in its unsupported-setting list with plain setting names: pause, feature deferral, uninstall period, and pre-release builds.
The FAQ title and description now explicitly identify it as frequently asked questions about Windows driver update policies.
Driver Updates
UpdatedDriver update licensing and supported-edition wording was generalized and an image path was corrected.
Driver Updates Overview
UpdatedThe driver updates overview removed its explicit GCC and GCC High/DoD Autopatch subscription-activation notice.
Driver Updates
UpdatedThe article removed its standalone Workplace Joined limitation section and link to the former configure page.
Expedite Updates
UpdatedThe expedited update article removes a duplicate data-collection statement and changes the Policy CSP link label.
Index
UpdatedA formatting-only block was added to the Windows updates index as part of redirect maintenance.
Update Rings
UpdatedThe update rings article removed its Validation and reporting section and link to the former shared Windows update reports page.
Windows Holographic for Business guidance now links to the Windows software updates index.
A new FAQ covers driver policy conflicts, reboot coordination, driver availability and removal, synchronization, pause behavior, extension drivers, co-management, deadlines, deferrals, user experience settings, and inventory timing.
Driver Updates
UpdatedThe driver updates overview removed its Frequently Asked Questions section, including assignment filters, Autopilot, rollback, policy conflict, pauses, deadlines, deferrals, and co-management guidance, following publication of a separate FAQ article.
Expedite Updates
UpdatedThe expedited quality update reporting steps were renumbered using Markdown auto-numbering without changing the report navigation or actions.
Feature Updates
UpdatedThe article states feature update policies are public-cloud only and not supported in GCC High or DoD, distinguishes Intune Plan 1 from Autopatch-entitled licensing for gradual rollout and optional updates, and clarifies LTSC is unsupported.
Index
UpdatedThe overview renames the Workplace Joined limitation section for Microsoft Entra registered devices and states that feature, quality, driver, and Hotpatch policies relying on WUfB DS cannot be used on those devices.
Index
UpdatedThe Windows updates overview moves Microsoft Entra registered-device restrictions into its general prerequisites: WUfB DS-backed feature, quality, driver, and Hotpatch policies are unsupported, while update rings remain available.
Update Rings
UpdatedThe update rings article clarifies that Intune Plan 1 is required for core policy creation and assignment and updates platform and edition wording.
Index
UpdatedThe registered-device limitation sentence received a formatting-only correction.
Update Rings
UpdatedThe update rings article made a minor wording change to the statement that Windows Holographic for Business supports a subset of Windows update settings.
Feature Updates
UpdatedThe article replaced a hard-coded list of qualifying Windows licenses with a link to the Autopatch entitlement licensing documentation for gradual rollout and optional feature updates.
Update Rings
UpdatedThe article heading changed from Manage your Windows Update rings to Manage update rings.
Feature Updates
UpdatedThe feature update policy prerequisites removed the instruction to enable data collection for reporting.
A new article documents using the Windows quality update policy to deploy Hotpatch security updates through Autopatch, including benefits and prerequisites.
A new consolidated article documents driver update policies: automatic or manual approval, pausing and approving drivers, prerequisites, supported editions, GCC limitations, RBAC, deployment planning, and reporting.
Driver Updates Overview
UpdatedThe driver update overview replaced its telemetry guidance with the shared device-configuration requirements, including enrollment, Entra join state, required telemetry, the Sign-In Assistant service, and Windows Update and Autopatch endpoints.
Index
UpdatedThe overview renamed the Windows Update client policy section and clarified that each update policy type has its own prerequisites, while feature, quality, driver, and Hotpatch use the same backend service as Autopatch.
Feature Updates Windows 10
UpdatedThe guidance for devices ineligible for Windows 11 now points administrators to the central feature update policy workflow for policy behavior, creation, and licensing requirements.
Driver Updates Policy
UpdatedThe driver policy article now links its prerequisite, deployment-planning, and FAQ reference to the renamed driver-updates article.
Feature Updates
UpdatedThe Windows 10-to-Windows 11 upgrade link now directs to the separate feature-updates-windows-10 article rather than an anchor in the main article.
Index
UpdatedThe Windows updates index changed its quality updates Learn more link from quality-updates-policy.md to the renamed quality-updates.md article.
Driver Updates Overview
UpdatedThe driver overview removed the Windows diagnostic-data reporting section and its steps to enable the Windows data setting in Intune.
Driver Updates Overview
RemovedThe former driver-updates-overview.md article was removed as part of the documentation rename to the consolidated driver-updates.md article.
Feature Updates
UpdatedThe article removed the Microsoft Entra registered-device limitations section and its next-steps links, leaving the core policy guidance in the main article.
Quality Updates Policy
RemovedThe former quality-updates-policy.md article was removed as part of the documentation rename to quality-updates.md.
Mobile Threat Defense
UpdatedMobile Threat Defense connector guidance was expanded with certificate synchronization content and refreshed connector-status material.
Mtd Connector Enable
UpdatedThe connector setup guidance states that Certificate Sync data is sent to Mobile Threat Defense partners at an interval based on device check-in.
The only changed line updates the reviewer metadata from aanavath to ilwu.
The only changed line updates the reviewer metadata from aanavath to ilwu.
The only changed line updates the reviewer metadata from aanavath to ilwu.
The only changed line updates the reviewer metadata from aanavath to ilwu.
The only changed line updates the reviewer metadata from aanavath to ilwu.
The only changed line updates the reviewer metadata from aanavath to ilwu.
The CrowdStrike Falcon Defense connector article changes its reviewer metadata.
Only the reviewer metadata changed from aanavath to ilwu.
Jamf Mtd Connector
UpdatedOnly the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Mobile Threat Defense
UpdatedOnly the reviewer metadata changed from demerson to ilwu.
Mobile Threat Defense
UpdatedThe only changed line updates the reviewer metadata from demerson to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Mtd Connector Enable
UpdatedOnly the reviewer metadata changed from aanavath to ilwu.
Mtd Connector Enable
UpdatedThe only changed line updates the reviewer metadata from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Sophos Mtd Connector
UpdatedOnly the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
The only changed line updates the reviewer metadata from aanavath to ilwu.
Device Protect
UpdatedThe device protection article now links its Windows update-management reference to the Windows updates index.
Privacy Data Store Process
UpdatedThe privacy article corrects the audit-log retention phrase to two years.
Epm Plan
UpdatedThe EPM plan replaced a support note with a dedicated statement that Endpoint Privilege Management supports specified virtual platforms.
Privacy Data Store Process
UpdatedThe privacy data-storage article changed the documented Intune audit-log retention period from up to one year to up to two years; personal data deletion remains described as within 30 days after deletion.
Data Enable Windows Data
UpdatedThe Windows diagnostic data page now links the Windows driver updates report to driver-updates.md rather than the retired overview article.
Driver Updates Reports
UpdatedThe reports article removes the detailed prerequisites section in favor of consolidated requirements content.
Feature Updates Reports
UpdatedThe report article removes its standalone prerequisites content during requirements consolidation.
Whats New Archive
UpdatedThe archive updates links for feature update, optional feature update, and Windows update distribution reports to their new dedicated articles.
In Development
UpdatedThe planned integration entry was restored: it describes turning offboarding recommendations into assignable, monitored, and completable Admin Tasks.
The report article is now titled Reports for Windows feature updates policies and its description focuses on reports for those policies; the data-collection prerequisite wording was simplified.
The article title and description now specifically identify reports for Windows quality update policies.
The article title and description now specifically identify reports for Windows update rings policies.
Expedite Updates
UpdatedThe article removed its standalone Workplace Joined limitations text and former configure-page reference.
Feature Updates Reports
UpdatedThe feature update reports article reorganized diagnostic-data requirements into tenant and device sections, explains that Windows update reports require sharing diagnostic data with Intune, and removes older duplicate collection text.
Driver Updates Reports
UpdatedThe driver reports article reorganized prerequisites into shared device and tenant requirement sections and states Windows diagnostic data must be collected at Required or higher for complete status and event reporting.
Driver Updates Reports
UpdatedThe report requirements now separate tenant configuration from device configuration and direct admins to enable Windows diagnostic data at Required or higher for driver-update reporting.
Quality Updates Reports
UpdatedThe quality update reports article removed blank lines only.
Driver Updates Reports
UpdatedThe driver reports article now states that Windows diagnostic data must be enabled and gives the Intune path: Tenant administration > Connectors and tokens > Windows data, then enable the processor-configuration setting.
Feature Updates Reports
UpdatedThe article removed duplicate device prerequisite text and corrected the organizational-report anchor from Windows 10 feature updates to Windows feature updates.
Whats New Archive
UpdatedThe archived What's New entry now links Windows driver update policy guidance to driver-updates.md instead of driver-updates-overview.md.
Mtd App Protection Policy
UpdatedOnly the reviewer metadata changed from demerson to ilwu.
Lob Apps Ios
UpdatedThe iOS LOB app size and bundle-identifier guidance was reformatted; its app-targeting caution remains intact.
The iOS/iPadOS line-of-business app article updates its date and clarifies existing app-addition instructions without changing the workflow.
Lob Apps Ios
UpdatedThe article clarifies that multiple Intune app instances can share a bundle ID but targeting separate instances can create unexpected device behavior; beta and production apps need different bundle identifiers.
In Development
UpdatedThe in-development page temporarily removed the planned Device Offboarding Agent and Admin Tasks integration entry.
The manual Company Portal article now uses `winget download "Company Portal" --source msstore` rather than the install command, and identifies the default Downloads folder.
The Company Portal download command was indented as a PowerShell block and the Downloads-folder guidance was converted from a note to regular text.
The app monitoring article refreshed its wording and clarified several Android AOSP line-of-business app error descriptions and administrator actions, including conflicts, network failures, size limits, and download validation.
The Company Portal article now tells administrators to use `winget install "Company Portal" --source msstore` to download the Windows Company Portal app and its dependencies.
In Development
UpdatedThe in-development page corrects the Markdown emphasis for the planned general availability of Admin tasks.
The Admin Tasks article updates its date and removes the statement that the feature is in public preview.
The guide now links directly to Reports for update rings policies.
In Development
UpdatedThe in-development page added planned items: an Intune admin center link to Lenovo Device Orchestration for Windows 11, Android settings catalog filtering by management mode, DDM assignment filters for Apple software updates, expanded managed-app device-management filter values, and Zimperium certificate inventory sync.
Only the reviewer metadata changed from demerson to ilwu.
Only the reviewer metadata changed from demerson to ilwu.
Index
UpdatedThe limitation on Entra registered devices using Autopatch-backed policy types is moved into a callout.
The cloud-native Windows endpoint guide updates a reference as part of the Windows updates documentation reorganization.
The Windows Holographic custom-setting guidance now links to the Windows updates index for Windows Update client policies.
The Windows Holographic UpdateServiceUrl custom-setting guidance now links to the Windows updates index.
In Development
UpdatedThe in-development page says Apple’s Rapid Security Responses rebrand to Background Security Improvements will be reflected in iOS/iPadOS Settings Catalog restrictions, and changes Android management-mode filtering to future tense.
In Development
UpdatedThe in-development entry changed the Android Intune settings catalog settings-list link to a relative documentation path.
Properties Catalog
UpdatedThe requirements now include Microsoft Entra hybrid joined devices alongside corporate-owned, Intune-managed, and Entra joined devices.
The planning guide now points Manage Windows software updates in Intune to the Windows updates index.
Settings Catalog
UpdatedThe settings catalog article updates its date and removes a redundant feature-applies-to section.
Macos Endpoints Get Started
UpdatedThe macOS endpoints guide says Platform Single Sign-On is the most secure approach for device attestation and registration and recommends enforcing the SSO extension for Zero Trust device identity.
The quality update article title is pluralized and its Hotpatch introduction is refreshed.
Intune's February release adds two new Managed Home Screen RBAC permissions—TemporarilySuspendManagedHomeScreen and RestoreManagedHomeScreen—to the School Administrator and Help Desk Operator roles, enhancing Android device management. No admin action is needed, but reviewing role assignments and updating documentation is recommended.
Microsoft Configuration Manager
6 updatesThe MDT Integration retirement row now links to Microsoft’s MDT retirement information while retaining the direction to remove MDT task-sequence steps and integration.
The deprecated-features page changes the MDT retirement reference to a troubleshoot.microsoft.com URL.
Release Notes
UpdatedThe MDT retirement warning changed the instruction to say customers should remove MDT task-sequence steps and MDT integration to avoid corruption and modification failures.
Workloads
UpdatedThe co-management Windows Update workload guidance now links to the Windows software updates index rather than the former configure page.
Driver Updates Faqs
UpdatedThe FAQ describes its Configuration Manager coexistence procedure as supported for Windows 11 and redirects its driver/firmware data-collection link to the overview prerequisites.
Release Notes
UpdatedThe release notes now state that Microsoft Deployment Toolkit and its Configuration Manager integration are retired and unsupported, warn that retained MDT task-sequence steps can cause corruption or modification failures, and point to Autopilot or supported OSD.
Endpoint Privilege Management
3 updatesThe EPM FAQ replaces the statement that Azure Virtual Desktop is unsupported with a supported-virtual-devices section and clarifies that administrator launches matching elevation rules are reported as unmanaged elevations.
Epm Plan
UpdatedThe EPM planning article now states that EPM policies support Azure Virtual Desktop single-session VMs instead of listing Azure Virtual Desktop as unsupported.
In Development
UpdatedThe in-development page restores an Endpoint Privilege Management support on Azure Virtual Desktop entry.
Enterprise App Management
2 updatesThe article refreshes wording around the Intune Suite add-on and customer responsibility for application compliance and authorization.
A FAQ heading now asks how Microsoft can detect whether an Enterprise App Catalog application is in use.