Windows quality updates policy
Doc updateA dedicated quality updates policy article was added, covering Hotpatch security updates without restart.
Windows Update policy and reporting content was extensively reorganized this week, but the consequential guidance is specific: Windows Update for Business Deployment Service-backed policies exclude Microsoft Entra-registered devices, Hotpatch has a defined eligibility chain, and driver approvals have documented constraints. Outside Windows servicing, Configuration Manager's MDT retirement carries an immediate cleanup sequence, while a February Intune release will extend Managed Home Screen permissions in built-in roles.
The Windows updates overview now states that Feature updates, Quality updates, Driver updates, and Hotpatch policies rely on the Windows Update for Business Deployment Service and aren't supported on Microsoft Entra-registered devices. Those devices remain supported through Windows Update client policies and update rings. This is a documented eligibility boundary, not a newly announced enforcement change.
The dedicated quality-update guidance documents Hotpatch as Monthly B release security updates that install and take effect without a restart. It lists Autopatch, Windows 11 Enterprise version 24H2 or later, the latest baseline release, an Intune quality update policy with Hotpatch enabled, and VBS turned on among the prerequisites. This adds concrete deployment guidance rather than announcing a new Hotpatch launch.
The driver-update FAQ states that Driver Updates don't support Assignment Filters or Windows Autopilot, and that Windows Update client policies don't support driver rollback. Multiple policies per device are supported but not recommended: if one policy approves an update and another pauses it, the approved status wins and the driver installs. The guidance points to small deployment rings and manual approval or monitoring for safer rollout.
Configuration Manager release notes now warn that Microsoft Deployment Toolkit integration and MDT Standalone are retired and unsupported. Administrators must remove all MDT task-sequence steps first and then remove MDT integration to prevent task-sequence corruption and modification failures; Windows Autopilot or supported Configuration Manager OSD are suggested alternatives.
The planned February Intune release adds TemporarilySuspendManagedHomeScreen and RestoreManagedHomeScreen to the School Administrator and Help Desk Operator built-in roles. Microsoft says no administrator action is required, but organizations using those roles should review role assignments and update their internal permissions documentation.
Prioritize the documented Windows Update eligibility and prerequisite checks, and remove MDT task-sequence steps before removing MDT integration. Driver administrators should use staged deployment rings and avoid conflicting policies. The Managed Home Screen change requires no action, although role assignments and internal documentation may merit review. Treat ordinary retitles, link moves, and prerequisite consolidation as documentation maintenance. Also, removal of the “public preview” label from the Admin Tasks article does not establish general availability; the in-development page still says the capability will soon be generally available.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
A dedicated quality updates policy article was added, covering Hotpatch security updates without restart.
The article description now covers managing Windows quality updates with quality update policies, expedited updates, and Hotpatch to maintain security and compliance.
The article is retitled Manage Windows driver updates and adds context that OEM driver and firmware releases can affect reliability, security, and hardware support, so organizations may prefer controlled approval.
The article adds an overview of update ring policies: they control deferrals, restart settings, deadlines, active hours, and notifications, and can define test, pilot, and production stages alongside feature, quality, and driver policies.
A dedicated article was added for feature update policy settings and creating feature update releases.
The expedited updates article removes its How expedited updates work section as content is reorganized.
The overview now describes Autopatch as an Intune-integrated service for keeping Windows devices protected, and explains that feature, quality, and driver update policies use the same orchestration service but can be managed directly without Autopatch enrollment.
The article title changes from Configure Windows feature updates releases to Manage Windows feature updates and replaces its introductory description.
The quality update policy prerequisites visually separate the update-ring settings table, which requires Enable pre-release builds to remain Not configured because Beta and Dev builds are unsupported for expedited updates.
The driver updates article adds a shared network-prerequisites include.
The index advises tenants blocked from creating Autopatch-required policies under EA licensing to contact their account team or licensing partner.
The feature update article removes a shared cloud-requirements block.
The driver policy article removes its former Create Windows driver update policies heading and introductory procedure text.
The article is retitled Windows driver update management and updates its introductory wording and applicable-platform presentation.
The driver updates article removes shared platform and other prerequisite blocks as content is consolidated into reusable requirement sections.
The article warns that update rings and Settings Catalog can block drivers, and specifies Windows driver = Allow and Exclude WU Drivers in Quality Update = Allow Windows Update drivers.
The article removes the earlier detailed callout about update-ring and Settings Catalog settings that block drivers.
The Windows updates index removes the table comparing manual and Autopatch update coordination.
The Windows driver and Exclude WU Drivers setting guidance received indentation fixes.
The overview says feature, quality, and driver update policies share the Autopatch orchestration layer and have the same prerequisites across those three types.
The driver updates article replaces the inline RBAC-permissions list with shared tenant and RBAC prerequisite content.
The Windows updates index adds that updates fail when the Microsoft Account Sign-In Assistant service is blocked or disabled, and notes its default Manual (Trigger Start) setting.
The quality updates article now includes a reusable licensing-prerequisites section.
The expedited updates article removed its explicit unsupported-cloud notice for GCC and GCC High/DoD environments.
The index changes feature, quality, and driver update references to explicitly say policy.
The note about the Microsoft Account Sign-In Assistant service was formatted as a nested callout.
The index corrects plural wording for feature, quality, and driver update policies.
The prerequisites emphasize Microsoft Entra joined or hybrid joined devices; Microsoft Entra registered devices remain limited to Windows Update client policies and update rings.
A blank line was removed from the driver updates article.
The Markdown driver-updates-overview article was removed in a table-of-contents update.
The rollout options article removes the warning that gradual rollout would be unavailable after October 14, 2025.
The Windows updates overview simplifies the policy list and specifies that quality updates include monthly security and reliability updates, expedited updates, and Hotpatch for eligible security patches without reboot.
The update-ring-to-feature-update migration guide now links OfferReady validation to the dedicated feature update reports article.
The Markdown driver-updates-faqs article was removed in an md-to-yml content migration.
A complete Windows Driver update management overview was added, documenting approvals, pauses, prerequisites, supported editions, cloud limitations, RBAC, deployment planning, and reporting.
The driver update overview restructures cloud, licensing, device, and configuration prerequisites into shared requirements content.
The overview describes Autopatch as an Intune-integrated service that orchestrates existing policies and adds dynamic grouping, phased rollout, health monitoring, compliance reporting, Hotpatch, and expedited delivery; its comparison table is reformatted.
The feature updates article standardizes status formatting, clarifies that a user logon starts the initial USO scan for Last Scanned Time, and generalizes Windows 10/11 reporting text to Windows devices.
The driver policy article is retitled Manage Windows driver update policies, adds a Before you begin section linking overview requirements, and clarifies that admins can create, approve, deploy, and pause individual driver updates.
The driver update article removed a shared cloud-requirements block as its prerequisites were reorganized.
The update rings article replaces links in its unsupported-setting list with plain setting names: pause, feature deferral, uninstall period, and pre-release builds.
The FAQ title and description now explicitly identify it as frequently asked questions about Windows driver update policies.
Driver update licensing and supported-edition wording was generalized and an image path was corrected.
The driver updates overview removed its explicit GCC and GCC High/DoD Autopatch subscription-activation notice.
The article removed its standalone Workplace Joined limitation section and link to the former configure page.
The expedited update article removes a duplicate data-collection statement and changes the Policy CSP link label.
A formatting-only block was added to the Windows updates index as part of redirect maintenance.
The update rings article removed its Validation and reporting section and link to the former shared Windows update reports page.
Windows Holographic for Business guidance now links to the Windows software updates index.
A new FAQ covers driver policy conflicts, reboot coordination, driver availability and removal, synchronization, pause behavior, extension drivers, co-management, deadlines, deferrals, user experience settings, and inventory timing.
The driver updates overview removed its Frequently Asked Questions section, including assignment filters, Autopilot, rollback, policy conflict, pauses, deadlines, deferrals, and co-management guidance, following publication of a separate FAQ article.
The expedited quality update reporting steps were renumbered using Markdown auto-numbering without changing the report navigation or actions.
The article states feature update policies are public-cloud only and not supported in GCC High or DoD, distinguishes Intune Plan 1 from Autopatch-entitled licensing for gradual rollout and optional updates, and clarifies LTSC is unsupported.
The overview renames the Workplace Joined limitation section for Microsoft Entra registered devices and states that feature, quality, driver, and Hotpatch policies relying on WUfB DS cannot be used on those devices.
The Windows updates overview moves Microsoft Entra registered-device restrictions into its general prerequisites: WUfB DS-backed feature, quality, driver, and Hotpatch policies are unsupported, while update rings remain available.
The update rings article clarifies that Intune Plan 1 is required for core policy creation and assignment and updates platform and edition wording.
The registered-device limitation sentence received a formatting-only correction.
The update rings article made a minor wording change to the statement that Windows Holographic for Business supports a subset of Windows update settings.
The article replaced a hard-coded list of qualifying Windows licenses with a link to the Autopatch entitlement licensing documentation for gradual rollout and optional feature updates.
The article heading changed from Manage your Windows Update rings to Manage update rings.
The feature update policy prerequisites removed the instruction to enable data collection for reporting.
A new article documents using the Windows quality update policy to deploy Hotpatch security updates through Autopatch, including benefits and prerequisites.
A new consolidated article documents driver update policies: automatic or manual approval, pausing and approving drivers, prerequisites, supported editions, GCC limitations, RBAC, deployment planning, and reporting.
The driver update overview replaced its telemetry guidance with the shared device-configuration requirements, including enrollment, Entra join state, required telemetry, the Sign-In Assistant service, and Windows Update and Autopatch endpoints.
The overview renamed the Windows Update client policy section and clarified that each update policy type has its own prerequisites, while feature, quality, driver, and Hotpatch use the same backend service as Autopatch.
The guidance for devices ineligible for Windows 11 now points administrators to the central feature update policy workflow for policy behavior, creation, and licensing requirements.
The driver policy article now links its prerequisite, deployment-planning, and FAQ reference to the renamed driver-updates article.
The Windows 10-to-Windows 11 upgrade link now directs to the separate feature-updates-windows-10 article rather than an anchor in the main article.
The Windows updates index changed its quality updates Learn more link from quality-updates-policy.md to the renamed quality-updates.md article.
The driver overview removed the Windows diagnostic-data reporting section and its steps to enable the Windows data setting in Intune.
The former driver-updates-overview.md article was removed as part of the documentation rename to the consolidated driver-updates.md article.
The article removed the Microsoft Entra registered-device limitations section and its next-steps links, leaving the core policy guidance in the main article.
The former quality-updates-policy.md article was removed as part of the documentation rename to quality-updates.md.
Mobile Threat Defense connector guidance was expanded with certificate synchronization content and refreshed connector-status material.
The connector setup guidance states that Certificate Sync data is sent to Mobile Threat Defense partners at an interval based on device check-in.
The only changed line updates the reviewer metadata from aanavath to ilwu.
The only changed line updates the reviewer metadata from aanavath to ilwu.
The only changed line updates the reviewer metadata from aanavath to ilwu.
The only changed line updates the reviewer metadata from aanavath to ilwu.
The only changed line updates the reviewer metadata from aanavath to ilwu.
The only changed line updates the reviewer metadata from aanavath to ilwu.
The CrowdStrike Falcon Defense connector article changes its reviewer metadata.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from demerson to ilwu.
The only changed line updates the reviewer metadata from demerson to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
The only changed line updates the reviewer metadata from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
Only the reviewer metadata changed from aanavath to ilwu.
The only changed line updates the reviewer metadata from aanavath to ilwu.
The device protection article now links its Windows update-management reference to the Windows updates index.
The privacy article corrects the audit-log retention phrase to two years.
The EPM plan replaced a support note with a dedicated statement that Endpoint Privilege Management supports specified virtual platforms.
The privacy data-storage article changed the documented Intune audit-log retention period from up to one year to up to two years; personal data deletion remains described as within 30 days after deletion.
The Windows diagnostic data page now links the Windows driver updates report to driver-updates.md rather than the retired overview article.
The reports article removes the detailed prerequisites section in favor of consolidated requirements content.
The report article removes its standalone prerequisites content during requirements consolidation.
The archive updates links for feature update, optional feature update, and Windows update distribution reports to their new dedicated articles.
The planned integration entry was restored: it describes turning offboarding recommendations into assignable, monitored, and completable Admin Tasks.
The report article is now titled Reports for Windows feature updates policies and its description focuses on reports for those policies; the data-collection prerequisite wording was simplified.
The article title and description now specifically identify reports for Windows quality update policies.
The article title and description now specifically identify reports for Windows update rings policies.
The article removed its standalone Workplace Joined limitations text and former configure-page reference.
The feature update reports article reorganized diagnostic-data requirements into tenant and device sections, explains that Windows update reports require sharing diagnostic data with Intune, and removes older duplicate collection text.
The driver reports article reorganized prerequisites into shared device and tenant requirement sections and states Windows diagnostic data must be collected at Required or higher for complete status and event reporting.
The report requirements now separate tenant configuration from device configuration and direct admins to enable Windows diagnostic data at Required or higher for driver-update reporting.
The quality update reports article removed blank lines only.
The driver reports article now states that Windows diagnostic data must be enabled and gives the Intune path: Tenant administration > Connectors and tokens > Windows data, then enable the processor-configuration setting.
The article removed duplicate device prerequisite text and corrected the organizational-report anchor from Windows 10 feature updates to Windows feature updates.
The archived What's New entry now links Windows driver update policy guidance to driver-updates.md instead of driver-updates-overview.md.
Only the reviewer metadata changed from demerson to ilwu.
The iOS LOB app size and bundle-identifier guidance was reformatted; its app-targeting caution remains intact.
The iOS/iPadOS line-of-business app article updates its date and clarifies existing app-addition instructions without changing the workflow.
The article clarifies that multiple Intune app instances can share a bundle ID but targeting separate instances can create unexpected device behavior; beta and production apps need different bundle identifiers.
The in-development page temporarily removed the planned Device Offboarding Agent and Admin Tasks integration entry.
The manual Company Portal article now uses `winget download "Company Portal" --source msstore` rather than the install command, and identifies the default Downloads folder.
The Company Portal download command was indented as a PowerShell block and the Downloads-folder guidance was converted from a note to regular text.
The app monitoring article refreshed its wording and clarified several Android AOSP line-of-business app error descriptions and administrator actions, including conflicts, network failures, size limits, and download validation.
The Company Portal article now tells administrators to use `winget install "Company Portal" --source msstore` to download the Windows Company Portal app and its dependencies.
The in-development page corrects the Markdown emphasis for the planned general availability of Admin tasks.
The Admin Tasks article updates its date and removes the statement that the feature is in public preview.
The guide now links directly to Reports for update rings policies.
The in-development page added planned items: an Intune admin center link to Lenovo Device Orchestration for Windows 11, Android settings catalog filtering by management mode, DDM assignment filters for Apple software updates, expanded managed-app device-management filter values, and Zimperium certificate inventory sync.
Only the reviewer metadata changed from demerson to ilwu.
Only the reviewer metadata changed from demerson to ilwu.
The limitation on Entra registered devices using Autopatch-backed policy types is moved into a callout.
The cloud-native Windows endpoint guide updates a reference as part of the Windows updates documentation reorganization.
The Windows Holographic custom-setting guidance now links to the Windows updates index for Windows Update client policies.
The Windows Holographic UpdateServiceUrl custom-setting guidance now links to the Windows updates index.
The in-development page says Apple’s Rapid Security Responses rebrand to Background Security Improvements will be reflected in iOS/iPadOS Settings Catalog restrictions, and changes Android management-mode filtering to future tense.
The in-development entry changed the Android Intune settings catalog settings-list link to a relative documentation path.
The requirements now include Microsoft Entra hybrid joined devices alongside corporate-owned, Intune-managed, and Entra joined devices.
The planning guide now points Manage Windows software updates in Intune to the Windows updates index.
The settings catalog article updates its date and removes a redundant feature-applies-to section.
The macOS endpoints guide says Platform Single Sign-On is the most secure approach for device attestation and registration and recommends enforcing the SSO extension for Zero Trust device identity.
The quality update article title is pluralized and its Hotpatch introduction is refreshed.
Intune's February release adds two new Managed Home Screen RBAC permissions—TemporarilySuspendManagedHomeScreen and RestoreManagedHomeScreen—to the School Administrator and Help Desk Operator roles, enhancing Android device management. No admin action is needed, but reviewing role assignments and updating documentation is recommended.
The MDT Integration retirement row now links to Microsoft’s MDT retirement information while retaining the direction to remove MDT task-sequence steps and integration.
The deprecated-features page changes the MDT retirement reference to a troubleshoot.microsoft.com URL.
The MDT retirement warning changed the instruction to say customers should remove MDT task-sequence steps and MDT integration to avoid corruption and modification failures.
The co-management Windows Update workload guidance now links to the Windows software updates index rather than the former configure page.
The FAQ describes its Configuration Manager coexistence procedure as supported for Windows 11 and redirects its driver/firmware data-collection link to the overview prerequisites.
The release notes now state that Microsoft Deployment Toolkit and its Configuration Manager integration are retired and unsupported, warn that retained MDT task-sequence steps can cause corruption or modification failures, and point to Autopilot or supported OSD.
The EPM FAQ replaces the statement that Azure Virtual Desktop is unsupported with a supported-virtual-devices section and clarifies that administrator launches matching elevation rules are reported as unmanaged elevations.
The EPM planning article now states that EPM policies support Azure Virtual Desktop single-session VMs instead of listing Azure Virtual Desktop as unsupported.
The in-development page restores an Endpoint Privilege Management support on Azure Virtual Desktop entry.
The article refreshes wording around the Intune Suite add-on and customer responsibility for application compliance and authorization.
A FAQ heading now asks how Microsoft can detect whether an Enterprise App Catalog application is in use.