Lab 24: Windows Update Ring Pilot

Configured a Windows Update ring for the Intune pilot device group with controlled deferrals, active hours, restart deadlines and device-based targeting ahead of wider rollout.

Overview

This lab continued the MD-102 endpoint-management build by adding Windows Update for Business policy control through Microsoft Intune. The policy was created as a pilot update ring and assigned only to the existing Intune Windows pilot device group.

The lab focused on safe update governance rather than forcing an operating system update during the build. The final validation used Intune device check-in reporting to confirm that the update ring applied successfully to the CL2 pilot device.

I created WIN-UPD-01-Windows-Update-Ring-Pilot in the Intune Windows updates area. The update ring allowed Microsoft product updates, blocked driver updates, used a 3-day quality update deferral and a 30-day feature update deferral, and kept Windows Insider pre-release builds disabled.

I configured active hours from 8 AM to 6 PM, disabled the user option to pause updates, allowed users to check for updates, enabled default Windows Update notifications and applied deadline controls for quality and feature updates. The policy was assigned to GRP_Intune_Windows_Pilot_Devices, which contained the CL2 pilot device.

Objective

The objective was to create a controlled Windows Update ring for Nietz Ltd pilot devices, configure sensible quality and feature update deferrals, block driver updates, protect user active hours, enable deadline controls and validate successful policy deployment to CL2.

Environment

Environment
ComponentValue
CompanyNietz Ltd
Tenant admin[email protected]
Management platformMicrosoft Intune
Policy typeUpdate ring for Windows 10 and later
Update ring policyWIN-UPD-01-Windows-Update-Ring-Pilot
Assigned groupGRP_Intune_Windows_Pilot_Devices
Pilot deviceCL2
Logged-in pilot user[email protected]
Previous labLab 23: Edge Security Baseline
Next labLab 25: Feature Update Policy Windows 11

Configuration and Evidence

1. Update Rings Area Reviewed Before Creation

I opened the Windows Update rings area in Intune before creating the pilot update ring.

Intune Windows Update rings page before the pilot update ring was created
Figure 1Intune Windows Update rings page before creating the Nietz Ltd pilot update ring policy.
Context: The empty update rings list established the starting state before the new policy was created.

2. Pilot Update Ring Basics Configured

I named the update ring WIN-UPD-01-Windows-Update-Ring-Pilot and added a description explaining its pilot scope and update-management purpose.

Windows Update ring basics showing policy name and description
Figure 2Windows Update ring basics configured with the pilot policy name and description.
Context: Clear naming separates the update ring from security baselines, configuration profiles and future production rollout rings.

3. Update Settings Configured

I configured the update settings to allow Microsoft product updates, block Windows driver updates, defer quality updates for 3 days and defer feature updates for 30 days.

Windows Update ring update settings showing Microsoft product updates, driver blocking and update deferrals
Figure 3Update settings configured with driver updates blocked, quality updates deferred for 3 days and feature updates deferred for 30 days.
Context: This configuration provides a safer pilot rollout by delaying feature updates, reducing driver-change risk and avoiding pre-release builds.

4. User Experience and Deadline Settings Configured

I configured user experience settings to install updates during maintenance time, protect business active hours, disable update pausing and apply deadline controls for quality and feature updates.

Windows Update ring user experience settings showing active hours, pause option, check option and deadline controls
Figure 4User experience settings configured with active hours, update deadlines, grace period and automatic reboot before deadline.
Context: Active hours and deadline settings balance user disruption control with the need to keep managed devices updated.

5. Pilot Device Group Assigned

I assigned the update ring to GRP_Intune_Windows_Pilot_Devices so the policy targeted the CL2 pilot device before any wider deployment.

Windows Update ring assigned to GRP_Intune_Windows_Pilot_Devices
Figure 5Windows Update ring assigned to the Intune Windows pilot device group containing the CL2 test device.
Context: Device-based assignment keeps the rollout tied to the pilot endpoint rather than relying on a user assignment.

6. Update Ring Created

I confirmed that the update ring was created and visible in the Intune Windows updates list with the expected quality and feature deferral values.

Intune Windows Update rings list showing WIN-UPD-01-Windows-Update-Ring-Pilot created
Figure 6The pilot Windows Update ring appeared in Intune with 3-day quality deferral and 30-day feature deferral settings.
Context: The policy list confirms the profile exists after creation and is available for deployment reporting.

7. CL2 Manually Synced

I manually synced CL2 from the Windows work or school account settings after assigning the update ring.

CL2 work or school account settings showing successful sync after update ring assignment
Figure 7CL2 manually synced after the Windows Update ring policy was assigned to the Nietz Ltd pilot device group.
Context: Manual sync speeds up policy check-in and provides endpoint-side evidence that the device contacted the management service.

8. Deployment Status Confirmed

I reviewed Intune deployment reporting and confirmed that the update ring check-in status succeeded for CL2 with Chloe Bennett signed in.

Intune update ring reporting showing CL2 with Success check-in status
Figure 8Intune reporting confirmed the Windows Update ring applied successfully to CL2 with Chloe Bennett as the logged-in user.
Context: Deployment reporting was used as the validation point instead of forcing a live Windows update installation on the pilot device.

Validation

The lab was validated when the update ring existed in Intune, showed the intended deferral settings, was assigned only to the Windows pilot device group, CL2 was manually synced, and Intune reporting showed one successful check-in for CL2 with no errors, conflicts or in-progress devices.

Key Technical Outcomes

Nietz Ltd now has a controlled pilot Windows Update ring for Intune-managed Windows devices. The configuration can be used to test update behaviour on CL2 before creating broader deployment rings for additional devices.

Summary

  • Created WIN-UPD-01-Windows-Update-Ring-Pilot in Microsoft Intune.
  • Allowed Microsoft product updates and blocked Windows driver updates.
  • Configured a 3-day quality update deferral and 30-day feature update deferral.
  • Configured active hours, user update options, notifications and update deadline controls.
  • Assigned the policy only to GRP_Intune_Windows_Pilot_Devices.
  • Manually synced CL2 after assignment.
  • Confirmed successful Intune check-in status for CL2.