Forums on Intune, SCCM, and Windows 11

Welcome to the forums. Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your topics and posts, as well as connect with other members through your own private inbox!

NEW Managing Windows Update Policies in Intune

Steve Cox

New Member
Messages
1
Reaction score
0
Points
1
My company recently migrated to Intune for deploying Windows updates. We have a couple of groups we'd like to deploy updates to first, before pushing them out to all the devices in our environment. We're trying to use the "Excluded groups" option to separate these groups, but this ends up blocking update policies to our 2 test groups.
  1. Update Ring “Test”
    1. A small, manually created group of 10 test machines which receives all updates, including feature updates, immediately after they’re released.
      1. Included groups: Intune | Update Group | Test
      2. Excluded groups: Intune | Update Group | Pilot, Intune | Update Group | Prod
  2. Update Ring “Pilot”
    1. A manually created group of ~300 pilot machines. This group receives quality updates in 7 days and feature updates 30 days after their release.
      1. Included groups: Intune | Update Group | Pilot
      2. Excluded groups: Intune | Update Group | Test, Intune | Update Group | Prod
  3. Update Ring “Prod”
    1. A dynamic group that includes all Windows devices, including workstations in our Test and Pilot groups. This group receives quality updates in 14 days and feature updates 60 days after their release.
      1. Included groups: Intune | Update Group | Prod
      2. Excluded groups: Intune | Update Group | Test, Intune | Update Group | Pilot

The result is that the machines in the Test and Pilot groups never receive any of the update policies and updates aren't installed.
If we don't exclude the Pilot and Test groups, the machines in these groups end up with an update policy conflict and updates aren't installed.

Any recommendations for the best way to accomplish our goal of pushing updates to a couple of groups initially and then to all devices in our environment?
Is there a way to create a dynamic group by excluding the members of another group?
 
Hy , works in the first ring with an assigned group, as you are currently doing.
In the second ring with the second assigned group that you want to use.
No group needs to be excluded in the second and first ring because you are trigering this on wellknown user or devices.
In the third ring, include the remaining devices (dynamic group) and exclude the first two groups.
Good luck!

  1. Update Ring “Test”
    1. Included groups: Intune | Update Group | Test
  2. Update Ring “Pilot”
    1. Included groups: Intune | Update Group | Pilot
  3. Update Ring “Prod”
    1. Included groups: Intune | Update Group | Prod
    2. Excluded groups: Intune | Update Group | Test, Intune | Update Group | Pilot
 

Forum statistics

Threads
7,135
Messages
27,868
Members
18,159
Latest member
jordysmits
Back
Top