Deploying software and updates using Configuration Manager
SCCM (Microsoft Endpoint Configuration Manager) is a management platform that is installed and runs entirely within your own infrastructure. Your site server, SQL database, distribution points, management points, device collections, applications, packages, and management data all remain on servers that you own and manage. Devices communicate primarily with your on-premises Configuration Manager infrastructure.
Cloud Attach is not a migration of Configuration Manager to the cloud. Instead, it is an integration between your existing on-premises Configuration Manager environment and Microsoft Intune through Microsoft Entra ID. When you enable Cloud Attach, your Configuration Manager site continues to operate exactly as before, but selected information about managed devices is synchronized to Microsoft Intune so that you can use certain cloud-based management capabilities.
Enabling Cloud Attach does not move your SCCM server, SQL database, applications, packages, collections, or content into Azure or Microsoft Intune. Your Configuration Manager site remains on-premises unless you separately decide to migrate workloads or redesign your management infrastructure. Cloud Attach simply establishes a trusted connection between Configuration Manager and Microsoft's cloud services.
Your device collections do not become cloud objects that you manage directly in Intune. Configuration Manager collections remain stored in your on-premises site database. However, if you enable tenant attach (one of the Cloud Attach capabilities), you can view many Configuration Manager-managed devices from the Microsoft Intune admin center and perform selected Configuration Manager actions remotely, such as running scripts, viewing resource explorer information, starting CMPivot, or synchronizing policies. These actions are still executed by your on-premises Configuration Manager site.
Similarly, your applications, packages, task sequences, software update metadata, and Configuration Manager database remain on your SCCM server. Cloud Attach does not upload this management data to Intune. Only the information required to enable cloud management features and identify managed devices is synchronized. The actual application content and Configuration Manager database stay within your on-premises environment.
Cloud Attach can make device management easier, particularly for internet-connected devices and hybrid work scenarios, but it does not fundamentally change how Configuration Manager deploys Windows updates. Windows quality updates, cumulative updates, and server updates can still be deployed using the normal Software Update Point (WSUS) and Configuration Manager infrastructure. The deployment process itself remains the same unless you choose to adopt additional cloud-based update technologies.
If your goal is simpler Windows client updating, Cloud Attach allows you to gradually move update management workloads from Configuration Manager to Microsoft Intune and Windows Update for Business. This can reduce the need for devices to connect to your internal network and eliminates much of the WSUS infrastructure for Windows client updates. However, this is an optional workload migration and is separate from simply enabling Cloud Attach.
For Windows Server, Cloud Attach provides much less benefit for update management. Windows Server updates are typically still managed through Configuration Manager and WSUS because Windows Update for Business is designed primarily for Windows client operating systems. Most organizations continue using Configuration Manager to patch servers even after enabling Cloud Attach.
If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.
hth
Marcin