Manage Insider Preview builds across your organization
If you're an administrator, you can manage installations of Windows 10 Insider Preview Builds across multiple devices in your organization using Group Policy, MDM solutions such as Intune, Configuration Manager, or Windows Server Update Services.
Register your domain
First, register your Azure Active Directory domain through our website. By registering your domain, you won't have to register each device or user in the program and can set important policies around preview builds.
To register your domain:
- You must already be registered with the work email address tied to your Azure Active Directory (AAD) Global Administrator account. Learn more about registering with your work email address.
- It must be in Azure Active Directory. We don't support Active Directory on premises in the Windows Insider Program.
- Use a production tenant of AAD, not a test tenant, to make the most of the program. The AAD tenant is just used for authentication, so you won't need to worry about changes to it from the the program.
Join devices to Azure Active Directory
To receive Insider Preview builds, devices must be joined to the same AAD domain that you used to register with the program.
To join individual devices, go to Settings > Accounts > Access work or school, select Join this device to Azure Active Directory, and log in with your AAD account. Get more detailed instructions for this on Microsoft Azure Docs.
If you have your organization's devices attached to Active Directory Domain Services, you can also bulk import all of them with Azure AD Connect.
Choose your diagnostic data settings
Your privacy is important to us. But, to run Insider Preview builds on a device updating directly from Windows Update, you must allow us to see a certain amount of diagnostic data, so we can investigate issues you might see.
- If you’re setting up Insider Preview builds for the first time, you must have optional data turned on to get started.
- If you're already running Insider Preview builds in the Dev Channel on devices, use these instructions to update your diagnostic data settings.
Create and manage policies
You can use Windows Update for Business (Group Policy or Mobile Device Management (MDM) tools, such as Intune,) or Windows Server Update Service (WSUS) tools, such as Configuration Manager, to control how and when Windows 10 Insider Preview Builds are installed on devices in your organization.
Set up Insider Preview builds using Group Policy
In the Group Policy Management Console (GPMC), create a Group Policy Object and add it to the Organizational Unit that has the devices you want to manage in it.
Go to Computer Configuration > Administrative Templates > Windows Components > Data Collection and Preview Builds > Allow Telemetry.
Inside Allow Telemetry, select the Enabled radio button. Under Options, set the dropdown to 3 - Full, and apply.
Go to Computer Configuration > Administrative Templates > Windows Components > Windows Update > Windows Update for Business and open Manage preview builds.
Inside Manage preview builds, select the Enabled radio button, and apply. (Under the Options section's Enable preview builds dropdown, you can also prevent installation on selected devices or set it to stop Insider Preview builds once a release is public.)
Go back to Computer Configuration > Administrative Templates > Windows Components > Windows Update > Windows Update for Business and open Select when Preview Builds and Feature Updates are received.
Inside Select when Preview Builds and Feature Updates are received, select the Enabled radio button. Under Options, choose the channel you'd like to get Insider Preview builds from the dropdown. (You can also choose to defer or pause builds here.)
You can also schedule update installations, choose active hours, and set policies for restart. Learn more about managing device restarts after updates.
Set up Insider Preview builds using Intune
Log in to the Azure portal and select Intune.
Go to Software Updates > Windows 10 Update Rings and select + Create to make an Update Ring policy.
Add a name and select the Settings section to configure its settings.
Under Servicing Channel, choose the channel you want to receive Insider Preview builds from.
Under Feature update deferral period, you can also choose to defer Insider Preview builds for a certain number of days after a release.
Select OK to comfirm your settings.
Select Create to save the policy.
Go to Assignments and assign your policy to specific users, devices or groups. You can create groups with one or more users or devices in Intune under Groups.
Select Save to deploy your new policy to these users, devices, or groups.
Set up Insider Preview builds using other MDM service providers
To set up Insider Preview builds through other MDM service providers, use these CSP settings:
Set up Insider Preview builds using Configuration Manager
- In the Products tab of Software Update Point Component Properties, select the checkbox next to Windows Insider Pre-Release. Select OK.
While this option will be visible on every version of Configuration Manager, you must be running Configuration Manager, version 1906 or newer to select it.
- If you already manage your organization’s deployments using Configuration Manager, go to Software Library > Overview > Windows 10 Servicing > All Windows 10 Updates to use the same procedure you currently use to deploy Windows 10 feature updates. In the list of All Windows 10 Updates, you'll see an option for Windows Insider Pre-release Feature Update to Windows 10 Version 1909.
- Deploy the release the same way you would any other feature update.
Set up Insider Preview builds with Windows Server Update Services (WSUS)
From Products and Classifications in WSUS, check the Windows Insider Pre-release Product and Upgrades. Sync WSUS.
Once the sync completes and shows up on the WSUS console, approve it for the computer group you want the update deployed to, and deploy as you would any other update.
Once a policy has been set, restart the device to activate the policy. Then, to confirm that your policies have been set correctly, go to Settings > Update & Security > Windows Update on one of the targeted devices and select View configured update policies.
You can also check this key in the Registry Editor on the device:
Devices set to receive an Insider Preview build show:
BranchReadinessLevel = 2 (Dev Channel), 4 (Beta Channel) or 8 (Release Preview Channel)
ManagePreviewBuilds = 1