@Peter Haslow, Thanks for posting in Q&A.
Agree with Rahul, when the Windows Updates Workload is moved to Intune, then device will receive the windows update for business policy which configured in Intune, not Configuration manager. So for your first question, I would say no, the windows update policy can't deliver to the same machine at the same time via both Configuration Manager and Intune . Here is a link with more details:
In fact, Intune only define an update strategy (e.g. block driver installation, set deferral period, set maintenance time, etc.), they don’t actually provide the update infrastructure itself. you still need to use your existing update solution such as Windows Update or WSUS to obtain the actual updates. Here is a link with more details:
For the device on the Internet, to make the package download successfully, I think you can configure the update source as Microsoft Update instead of WSUS.
Hope it can help.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.