🔒 Guided

Pre-launch preview. Authorised access only.

Incorrect code

Guided by A Guide to Cloud
Explore AB-900 AI-901
Guided MD-102 Domain 4
Domain 4 — Module 4 of 5 80%
26 of 27 overall

MD-102 Study Guide

Domain 1: Prepare Infrastructure for Devices

  • Device Identity: Join, Register & Hybrid Free
  • Build the Right Device Groups
  • Intune Enrollment Essentials Free
  • Auto-Enrollment & Bulk Enrollment
  • Intune RBAC & Windows Hello for Business
  • Compliance Policies & Conditional Access
  • Windows LAPS & Local Group Management

Domain 2: Manage and Maintain Devices

  • Windows Autopilot: Choose Your Path Free
  • Autopilot: Device Names, ESP & Rollout
  • Provisioning Packages & Windows 11 Upgrades
  • Windows 365: Your PC in the Cloud
  • Configure Windows Devices with Intune
  • Config Profiles: Android, iOS & macOS
  • Control Admin Rights with EPM
  • Intune Suite: Apps, Analytics & Remote Help
  • Cloud PKI & Tunnel for MAM
  • Remote Actions & Device Queries

Domain 3: Manage Applications

  • App Deployment: Prepare & Package
  • Deploy Apps with Intune & App Stores
  • Microsoft 365 Apps: Deploy, Customize & Manage
  • App Protection Policies & Conditional Access
  • App Configuration: Managed Apps & Managed Devices

Domain 4: Protect Devices

  • Endpoint Security: Antivirus, Firewall & Encryption
  • Attack Surface Reduction & Security Baselines
  • Defender for Endpoint: Integrate & Onboard
  • Plan and Manage Windows Updates
  • Cross-Platform Updates & Delivery Optimization

MD-102 Study Guide

Domain 1: Prepare Infrastructure for Devices

  • Device Identity: Join, Register & Hybrid Free
  • Build the Right Device Groups
  • Intune Enrollment Essentials Free
  • Auto-Enrollment & Bulk Enrollment
  • Intune RBAC & Windows Hello for Business
  • Compliance Policies & Conditional Access
  • Windows LAPS & Local Group Management

Domain 2: Manage and Maintain Devices

  • Windows Autopilot: Choose Your Path Free
  • Autopilot: Device Names, ESP & Rollout
  • Provisioning Packages & Windows 11 Upgrades
  • Windows 365: Your PC in the Cloud
  • Configure Windows Devices with Intune
  • Config Profiles: Android, iOS & macOS
  • Control Admin Rights with EPM
  • Intune Suite: Apps, Analytics & Remote Help
  • Cloud PKI & Tunnel for MAM
  • Remote Actions & Device Queries

Domain 3: Manage Applications

  • App Deployment: Prepare & Package
  • Deploy Apps with Intune & App Stores
  • Microsoft 365 Apps: Deploy, Customize & Manage
  • App Protection Policies & Conditional Access
  • App Configuration: Managed Apps & Managed Devices

Domain 4: Protect Devices

  • Endpoint Security: Antivirus, Firewall & Encryption
  • Attack Surface Reduction & Security Baselines
  • Defender for Endpoint: Integrate & Onboard
  • Plan and Manage Windows Updates
  • Cross-Platform Updates & Delivery Optimization
Domain 4: Protect Devices Premium ⏱ ~12 min read

Plan and Manage Windows Updates

Update rings, feature update policies, and quality update policies give you granular control over how and when Windows devices receive updates. No more surprise reboots.

Windows update management in Intune

☕ Simple explanation

Think of update rings like traffic lights on an on-ramp to the motorway.

Instead of letting all 500 cars (devices) merge at once and causing a pile-up, you let a few through at a time. First the IT team (green light), then finance (green after 7 days), then everyone else (green after 14 days). If the IT team’s cars crash (update causes issues), you turn the light red for everyone else before they merge.

That’s what update rings do — they stagger when devices receive updates, giving you time to spot problems before they hit your entire fleet.

Intune provides three update management tools for Windows: Update rings (control timing and behaviour of all update types), Feature update policies (target a specific Windows version), and Quality update policies (expedite critical security updates). Together, they give administrators granular control over the Windows Update experience for enrolled devices.

Update rings

What update rings control

SettingWhat It DoesSam’s Config
Quality update deferralDelay quality (security) updates by X days7 days for most users
Feature update deferralDelay feature (version) updates by X days14 days for most users
Quality update pauseTemporarily halt quality updates for up to 35 daysNot paused (only for emergencies)
Feature update pauseTemporarily halt feature updates for up to 35 daysNot paused
Automatic update behaviourAuto download, schedule install, or notify userAuto install at scheduled time
Active hoursHours when the device shouldn’t restart8 AM – 6 PM
Restart grace periodDays before forced restart after update install2 days
Deadline for quality updatesMaximum days before forced install5 days
Deadline for feature updatesMaximum days before forced install14 days

Sam’s ring strategy at Tui Solutions

RingTargetDeferral (Quality)Deferral (Feature)Purpose
Ring 0 — IT PreviewIT team (15 devices)0 days0 daysFirst to receive updates — spot issues early
Ring 1 — Early AdoptersVolunteers (50 devices)3 days7 daysBroader testing with motivated users
Ring 2 — Broad DeploymentAll remaining (435 devices)7 days14 daysProduction rollout after validation

Feature update policies

Feature update policies target a specific Windows version, different from update rings which defer updates by days.

SettingWhat It Does
Target versionThe Windows version devices should run (e.g., Windows 11, version 24H2)
Rollout optionsMake available immediately or set start date
DeadlineDays after availability before forced install

When to use feature updates vs update rings

FeatureUpdate RingsFeature Update Policies
ControlsTiming of ALL updates (quality + feature)Specific Windows VERSION to target
Best forOngoing update managementUpgrading to a specific Windows 11 version
Can block a versionNo — only deferYes — pin to a version, blocking newer ones
Works withQuality updates, feature updates, driversFeature updates only
ExampleDefer feature updates 14 days for all usersUpgrade all devices to Windows 11 24H2 by March 1st

Quality update policies (expedited updates)

When a critical security patch drops and you can’t wait for normal deferral windows:

  1. Intune admin center → Devices → Manage updates → Quality updates
  2. Select the update to expedite
  3. Assign to device groups
  4. Devices install the update within 24-48 hours, bypassing deferral settings

Chen Wei uses expedited updates for zero-day patches at Meridian Bank — banking regulators require critical patches within 48 hours.

💡 Exam tip: update rings vs feature updates vs quality updates

The exam expects you to know all three:

  • Update rings = ongoing management of update TIMING (deferral days, restart behaviour, active hours)
  • Feature update policies = target a specific Windows VERSION (upgrade to 24H2)
  • Quality update policies = EXPEDITE critical patches (bypass deferral for urgent fixes)

Scenario mapping:

  • “Stagger updates across departments” → Update rings
  • “Upgrade all devices to Windows 11 24H2” → Feature update policy
  • “Install this zero-day patch on all devices within 48 hours” → Quality update policy (expedited)

iOS/iPadOS and macOS update policies

iOS/iPadOS updates

Intune can manage iOS/iPadOS updates for supervised devices:

SettingWhat It Does
Software update policySchedule when updates install (e.g., outside business hours)
Defer updatesDelay visibility of updates for up to 90 days
Force updateRequire a specific iOS version by a deadline

macOS updates

SettingWhat It Does
Software update policyConfigure when macOS checks for and installs updates
Defer updatesDelay software updates for up to 90 days
Force update by deadlineRequire a specific macOS version
ℹ️ Deep dive: iOS update management requires supervised

Full iOS update management (deferral, forcing specific versions) requires supervised devices (enrolled via ADE). Unsupervised devices:

  • Can receive update notifications
  • Cannot be forced to defer or install specific versions
  • Users control when they update

Riko at Pixel & Co can only fully manage updates on corporate iPads (supervised via ADE). Designers’ personal iPhones (unsupervised) update on their own schedule.

Windows Autopatch

Windows Autopatch is a managed service that automates Windows quality and feature updates, Microsoft 365 Apps updates, Microsoft Edge updates, and Teams updates. Instead of manually creating update rings and monitoring rollouts, Autopatch handles the entire process.

How Autopatch works

  1. Enroll your tenant in Windows Autopatch (Intune admin center → Tenant administration → Windows Autopatch)
  2. Devices are automatically sorted into deployment rings (Test, First, Fast, Broad) based on analytics data
  3. Quality updates roll out automatically: Test ring first, then progressively to Broad over ~21 days
  4. Feature updates are deployed with the same staged approach
  5. Autopatch monitors for issues — if devices in early rings show problems (crashes, rollbacks), later rings are paused automatically

Autopatch vs manual update rings

FeatureManual Update RingsWindows Autopatch
Ring creationAdmin creates and targets manuallyAutomatic — devices sorted by Autopatch
MonitoringAdmin reviews reports manuallyAutomated — Autopatch detects issues and pauses
Issue responseAdmin must pause rings manuallyAutopatch auto-pauses later rings if early rings fail
ScopeWindows quality and feature updates onlyWindows + M365 Apps + Edge + Teams updates
EffortMedium — ongoing manual managementLow — set up once, Autopatch handles the rest
FlexibilityFull control over every settingLess granular — trades control for automation

When to use which

  • Use Autopatch when you want hands-off update management with automated monitoring and rollback. Best for organisations without a dedicated patching team.
  • Use manual update rings when you need precise control over timing, specific deferral days, or custom ring definitions that don’t match Autopatch’s model.
  • You can use both — Autopatch for most devices, manual rings for exceptions (kiosks, specialised hardware).
💡 Exam tip: Autopatch licensing and requirements

Windows Autopatch requires:

  • Windows 10/11 Enterprise E3 or E5 (or equivalent licensing)
  • Microsoft Entra ID P1 (for dynamic groups)
  • Microsoft Intune (devices must be Intune-managed)

The exam may test: “What’s the benefit of Autopatch over manual update rings?” Key answer: automated ring progression with automatic pause on failure detection. Autopatch reduces admin effort while maintaining staged deployment safety.

🎬 Video walkthrough

🎬 Video coming soon

Plan and Manage Windows Updates — MD-102 Module 26

Plan and Manage Windows Updates — MD-102 Module 26

~12 min

Flashcards

Question

What's the difference between update rings and feature update policies?

Click or press Enter to reveal answer

Answer

Update rings control the TIMING of all updates (deferral days, restart behaviour). Feature update policies target a specific Windows VERSION (e.g., upgrade to 24H2). Use rings for ongoing management; use feature update policies for version targeting.

Click to flip back

Question

What are quality update policies (expedited updates)?

Click or press Enter to reveal answer

Answer

They bypass update ring deferral settings to install critical security patches within 24-48 hours. Used for zero-day patches and urgent security fixes. Created in Intune under Devices → Manage updates → Quality updates.

Click to flip back

Question

Can Intune fully manage iOS update timing?

Click or press Enter to reveal answer

Answer

Only on supervised devices (enrolled via ADE). Supervised devices can defer updates, force specific versions, and schedule install times. Unsupervised (BYOD) devices can't be controlled — users decide when to update.

Click to flip back

Knowledge Check

Knowledge Check

Sam wants the IT team to receive Windows updates immediately while the rest of Tui Solutions gets updates 7 days later. What should Sam configure?

Knowledge Check

A critical zero-day vulnerability is announced on Tuesday. Chen Wei needs all 10,000 Meridian Bank devices patched within 48 hours — but the current update ring has a 7-day deferral. What should Chen Wei do?


Next up: Cross-Platform Updates & Delivery Optimization — managing Android, iOS, and macOS updates, plus configuring Delivery Optimization for bandwidth management.

← Previous

Defender for Endpoint: Integrate & Onboard

Next →

Cross-Platform Updates & Delivery Optimization

Guided

I learn, I simplify, I share.

A Guide to Cloud YouTube Feedback

© 2026 Sutheesh. All rights reserved.

Guided is an independent study resource and is not affiliated with, endorsed by, or officially connected to Microsoft. Microsoft, Azure, and related trademarks are property of Microsoft Corporation. Always verify information against Microsoft Learn.