Hello Oscar Green,
What you experienced with Windows Update for Business (WUfB) bypassing deferral rings is usually tied to how Intune policies are applied and how the Windows Update service interprets them. In some cases, cumulative updates marked as security or reliability fixes can override deferral settings, especially if Microsoft classifies them as critical. Another common cause is policy conflicts, if a device has overlapping update rings or local Group Policy settings, the deferral may not apply consistently.
A good first step is to confirm that the affected devices are only targeted by one Intune update ring and that no legacy WSUS or Group Policy settings are still in play. Reviewing the Update Compliance logs in Intune can also help identify whether the update was categorized as mandatory. If you want stricter control, consider using the “Pause” feature in Intune for quality updates, which enforces a hard block rather than a deferral. Keeping devices aligned with the latest Intune service updates also ensures that deferral policies are respected correctly.
I hope the response provided some helpful insight. If you find this answer useful, please hit “accept answer” so I know it addressed your concern.
Jason.