Muistiinpano
Tämän sivun käyttö edellyttää valtuutusta. Voit yrittää kirjautua sisään tai vaihtaa hakemistoa.
Tämän sivun käyttö edellyttää valtuutusta. Voit yrittää vaihtaa hakemistoa.
Windows quality update policies allow you to manage Windows quality updates and supported .NET Framework updates for Windows devices. By using targeted policies, you can approve or expedite a specific quality update to your tenant. See Use Intune to expedite Windows quality updates for more information.
Quality update policies provide granular control over the rollout of Windows updates. You can use these policies for monthly OS updates and .NET Framework updates, including security, non-security, and out-of-band releases. These policies also include .NET Framework update controls, so you can manage approvals and rollout timing in the same policy experience. You can decide whether to approve updates automatically or require manual review and approval before deployment. Customize these settings for each update type. This way, help align update deployment with organizational needs while reducing unnecessary user disruption.
Automatic and manual modes
You can configure an approval method for Windows quality updates by individual update type. Approval settings apply uniformly to both OS and .NET Framework update types under each release category.
- Monthly security updates approval settings apply to both Windows OS cumulative quality updates and .NET Framework security updates. These updates are typically released on the second Tuesday of the month.
- Monthly non-security preview updates approval settings apply to both Windows OS preview updates and .NET Framework preview updates. These updates are typically released in the fourth week of the month.
- Out-of-band (OOB) security updates approval settings apply to both Windows OS security OOB releases and .NET Framework security OOB releases.
- Out-of-band non-security updates approval settings apply to both Windows OS non-security OOB releases and .NET Framework non-security updates.
Note
The quality update policy settings also govern supported .NET Framework updates in Windows Autopatch.
A single policy can use both automatic and manual methods across different update types. When you create a quality update policy, the default approval configuration of monthly security updates is automatic. The default approval configuration of other updates is manual.
For automatic approvals, you can specify a deferral period (in days) before the update is offered to devices. Do this for gradual deployments across policies. For supported scenarios, Windows OS quality updates and .NET Framework updates follow the approval and deferral settings that you configure in the same quality update policy.
Windows Autopatch recommends automatic approvals for security updates and manual approvals for optional updates.
- Automatic approval: Recommended for security updates. Updates are auto-approved and deployed according to configured schedule, reducing administrative effort. You can still pause updates if issues arise or expedite critical patches as needed.
- Manual approval: Recommended for optional or non-security updates in special cases. This configuration provides full control, deploying updates only with explicit manual approval. This is ideal for environments needing strict change management or extensive testing before rollout. Use this setting with care, since timely approval of critical updates is essential to maintain security compliance.
You can combine automatic and manual modes to fit your organization’s needs.
Create quality update policies
To configure a quality update policy:
Go to the Microsoft Intune admin center.
Navigate to Windows Updates.
Select Devices > Manage updates > Windows updates > Quality updates.
Select Create.
Select Windows quality update policy.
Under Basics, enter a name for your new policy and select Next.
Under Settings, choose your approval method configuration for security updates, non-security updates, and out-of-band updates.
- If you choose automatic approval, select Make updates available after. Here, specify the number of days to wait before updates are offered to devices.
- For supported devices, these policy settings apply to both Windows OS quality updates and .NET Framework updates managed through Windows Autopatch.
Select Next.
Note
Use the same policy to also configure update approvals for Quick machine recovery and hotpatch update settings. Quick machine recovery settings determine whether affected devices can receive a Microsoft-provided remediation fix when a boot-critical issue occurs. Learn more about Quick machine recovery management in Windows Autopatch here.
Note
For .NET Framework update management in Windows Autopatch, only Windows 11 devices added to the policy follow the quality update policy experiences. Windows 10 devices enrolled in Extended Security Updates (ESU) continue to receive .NET Framework updates from Windows Update based on client-side settings. Therefore, quality update policy approval settings apply only to OS quality updates on those devices. Expect a separate restart.
Note
You can't manage .NET Framework 3.5 updates through Windows Autopatch quality update policies. These updates don't appear in the quality updates workflow. Windows Update delivers these updates as standalone. Client-side settings govern these updates. As a result, their deployment timing and behavior might differ from OS and other .NET Framework updates that you manage through Windows Autopatch.
Select the appropriate Scope tags or leave as Default. Select Next.
Assign the devices to the policy and select Next.
Review the policy and select Create.
Note
If you add devices running Windows Insider builds to the approval policy, these devices won't be enrolled in Windows Autopatch for quality updates. Therefore, approval settings from the quality update policy don't apply.
Deferral period for automatic update deployments
For deployment rings using automatic approval, you can set a deferral period with the Make updates available after setting. Devices assigned to this policy receive an update after this many days since Microsoft releases the update. Adjust each ring’s deferral as needed. Allowed range is 0 to 30 days for quality updates. Shorter deferral periods mean faster delivery. Longer periods allow for a gradual rollout.
Note
Deferral periods only apply to automatically approved updates. For manual approval, you control when updates are offered by approving policies at your chosen time.
Note
Deferrals set in cloud-based quality update policies override any client-side deferral settings from legacy update ring policies or CSP configurations. If a device is governed by both an update rings policy and a cloud-based quality update policy, updates are scheduled according to the cloud policy’s deferral setting. Other client settings, such as deadlines and grace periods, still apply.
Approve and deploy quality updates
To approve and deploy Windows quality updates and supported .NET Framework updates:
- Go to the Microsoft Intune admin center.
- Navigate to Devices > Manage updates > Windows updates > Quality updates.
- Select Manage updates.
- On the Manage quality updates blade, see the releases that you can manage, including Windows OS quality updates and supported .NET Framework updates. Review and approve each update type independently: Windows security updates, non-security updates, out-of-band updates, and .NET Framework non-security out-of-band updates.
- Select a Release name to see details, such as severity and included KBs. Use this information to review the payload before manual approval. The Approved policies column displays the number of policies that are approved and those that require manual approval.
- Select the X of Y under Approved policies to see which policies are approved. Policies that aren’t approved are marked as Needs review for that release.
- Select the desired policies and select Approve. Apply this action to Windows OS quality updates and supported .NET Framework updates shown in the release list.
You can also manually approve a single policy:
- Navigate to Devices > Manage updates > Windows updates > Quality updates.
- Select an individual policy.
- Select the horizontal ellipses (...) across a Release.
- Select Approve.
This experience remains consistent for Windows OS quality updates and supported .NET Framework updates.
Handling policy conflicts
When multiple update policies apply to a device, Windows Autopatch applies the following precedence logic to resolve conflict and maintain consistency.
- Device assigned to Windows Update ring policies and cloud-based quality update policies. The quality update policy takes priority for approval settings and deferrals. Other update ring policy settings, such as deadlines and grace periods, remain active. For supported devices, Windows Autopatch applies this quality update policy setting to both Windows OS quality updates and .NET Framework updates.
- Device assigned to multiple cloud-based quality update policies. The policy approving the latest release takes priority.
- Device assigned to cloud-based quality update policy and legacy quality update policy (with only the hotpatch update setting). The cloud-based quality update policy takes priority. That is, monthly security updates aren’t offered to the device until you either manually or automatically approve them. Check your approval settings in the configuration of the cloud-based quality update policy.
Note
All quality update approval and legacy hotpatch policies assigned to the device evaluate the hotpatch update setting. These policies honor hotpatch update enablement.
Pause a release
You can pause an approved update at any time. For example, it's helpful if you find an issue or need to temporarily stop deployment. When paused, Windows Autopatch revokes the approval of the update, and no new devices receive it. Devices that already installed the update aren't rolled back. In the portal, paused updates appear as Paused. To resume deployment, simply re-approve the update. Windows Autopatch then offers it again to devices that still need it, as if it were a newly approved update. This pause and resume experience applies to individual releases shown in the quality update management workflow, including supported .NET Framework releases.
Important
Devices can take up to eight hours to apply new update pause settings. That's because Windows Autopatch uses Microsoft Intune as its device management solution. Windows devices take on average eight hours to communicate back to Microsoft Intune with new instructions to pause, resume, or roll back updates.
For more information, see How long does it take for devices to get a policy, profile, or app after they’re assigned from Microsoft Intune.
Note
The pause function only pauses the selected update release. Devices continue to receive other admin-approved updates based on the defined cadence. For example, pausing a .NET Framework release doesn't pause approved Windows OS quality updates. Likewise, pausing an OS security update doesn't pause a separate approved non-security update or .NET Framework release.
To pause a cloud-based quality update deployment
- Go to the Microsoft Intune admin center.
- Navigate to Devices > Manage updates > Windows updates > Quality updates.
- Select Manage updates.
- On the Manage quality updates blade, select a Release name to see its details, such as severity and included KBs. Use this information to review the payload before manual approval. Approved policies column displays the number of polices that are approved and those that require manual approval.
- Select the X of Y under Approved policies to see which policies are approved.
- Select the desired policies and select Pause.
Remediating not ready and not up-to-date devices
To help ensure that your devices receive Windows quality updates, see how you can remediate Windows Autopatch device alerts.
Note
Managed devices that are targeted to a quality update policy are automatically enrolled with the Windows Autopatch. When a device is no longer assigned to any quality update policies, the device remains enrolled in Windows Autopatch for 24 hours. During this time, assign the device to a different policy and help protect it from receiving an unintended quality update. After 24 hours, the device is automatically unenrolled from Windows Autopatch for quality updates. From then on, the device receives updates based on Windows Update scans and client settings. This helps ensure continued security by allowing the device to keep getting security updates without compromise.
Compliance date calculation
Windows Autopatch calculates a target compliance date for each device based on its deployment schedule and configured update policies.
For devices assigned to a Quality update policy:
- For manually approved updates, the compliance date is calculated as the approval date + the configured client deadline.
- For automatically approved updates, the compliance date is calculated as release date + the configured Quality update policy deferral period + the configured client deadline.
- Configure the client deadline through Windows Update policies, such as Update rings or supported policy settings.
For devices assigned only to Update ring policy, the compliance date is calculated as the configured Update ring policy deferral period + the configured client deadline in the Update ring policy.
Important
Windows Autopatch supports registering Windows 10 and Windows 11 Long-Term Servicing Channel (LTSC) devices that are being currently serviced by the Windows 10 LTSC or Windows 11 LTSC. The service only supports managing the Windows quality updates workload for devices currently serviced by the LTSC. Windows Update client policies and Windows Autopatch don't offer Windows feature updates for devices that are part of the LTSC. You must either use LTSC media or the Configuration Manager Operating System Deployment capabilities to perform an in-place upgrade for Windows devices that are part of the LTSC.
FAQs
Can I edit the approval method in an existing quality update policy?
No, the approval method cannot be changed in an existing policy. If you need to use a different approval method, you must create a new policy. For supported devices, the quality update policy continues to govern both Windows OS quality updates and .NET Framework updates as per the policy settings.
If a policy is set to automatic approval with a deferral period, can I manually override the deferral and approve the update immediately?
Yes, you can manually override the deferral period and approve the update when needed.
Do Windows Autopatch quality update policies include .NET Framework updates?
Yes. The cloud-based Windows Autopatch quality update policies include .NET Framework updates in the same policy experience used for monthly Windows OS quality updates. Approval and deferral settings for an update type in the policy apply to both security and non-security updates as well as .NET Framework updates. However, you can manually review, approve, and pause .NET Framework releases independent from the Manage updates workflow.
Does the same behavior apply to Windows 10 ESU devices?
No. Windows 10 devices enrolled in Extended Security Updates (ESU) continue to receive .NET Framework updates from Windows Update based on client-side settings. On those devices, quality update policy approvals apply only to Windows OS quality updates. .NET Framework updates can still result in a separate restart.
If a policy has hotpatch updates enabled and non-security updates are approved, will the device receive the non-security updates?
No, the devices won’t receive non-security updates in this case. Applying the non-security updates would remove the device from the hotpatch update path and can cause unexpected restarts. The device then needs to wait until the next hotpatch cycle to resume hotpatch updates. To receive non-security updates, disable hotpatch update setting in the quality update policy.