Deploying Windows Feature Updates via Intune – The Right Approach

In this post, I’m going to walk you through how to deploy Windows Feature Updates using Microsoft Intune, and more importantly:

👉 Which option should you use?
👉 Update Rings, Feature Update Policy… or both?

These are very common questions, and by the end of this article, you’ll have a clear and practical understanding of the best approach.

Understanding the Available Options in Intune

When you log in to the Microsoft Intune admin center and navigate to:

Devices → Windows → Windows Updates

You’ll notice two key options:

  • Update Rings
  • Feature Updates

Let’s break them down.

Option 1: Using Update Rings

Yes — you can deploy Feature Updates using Update Rings ✅

What Update Rings Can Do

Update Rings allow you to manage:

  • Quality updates (Patch Tuesday updates)
  • Feature updates
  • Driver updates
  • Other Microsoft updates

Key Configuration Areas

1. Deferral Period

  • Quality Updates Deferral
  • Feature Updates Deferral

Example:

  • If a Feature Update is released on Oct 1
  • Deferral = 3 days
    👉 Device receives it on Oct 4

2. Deadlines (Very Important 🔥)

Deadlines ensure updates don’t get delayed indefinitely.

  • Example:
    • Deadline = 2 days
    • If update isn’t installed → system forces installation

3. Grace Period

  • After installation, user gets time before forced restart
  • Example:
    • 2 days grace → countdown notifications (48h → 24h → 6h)
screenshot 0007

4. User Experience Settings

  • Auto install during maintenance window
  • Active hours configuration
  • Optional auto-reboot behavior

Limitations of Update Rings ❗

Here’s the key problem:

👉 You cannot choose a specific Feature Update version

Example scenario:

  • Some devices → Windows 11 24H2
  • Others → Windows 11 25H2

🚫 Not possible with Update Rings alone

You can only:

  • Delay updates (max 365 days)
  • Pause updates (not recommended long-term)

Option 2: Feature Update Policy (Recommended for Control)

This is where Feature Update Policy becomes powerful 💡

screenshot 0019

What It Does

  • Deploy a specific Windows version
  • Freeze devices on that version

Example:

  • Target = Windows 11 24H2
    👉 Devices stay on 24H2 (won’t upgrade to 25H2 automatically)

Key Benefits

  • Version control per device group
  • Safe phased rollout
  • Prevent unwanted upgrades
  • Better compatibility management

Deployment Options Available

When creating a Feature Update Policy, you can:

  1. Deploy immediately
  2. Schedule a specific date
  3. Gradual rollout (requires higher licensing)

Gradual Rollout Example

  • 100 devices
  • Rollout over 10 days
  • Reduces:
    • Network load
    • Support tickets
    • Risk

Prerequisites for Feature Update Policy ⚠️

Before using it, ensure:

1. Enable Windows Diagnostic Data

Go to:

  • Tenant Admin → Connectors & Tokens → Windows Data

Enable features that require Windows diagnostic data in processor configuration

screenshot 0024 1

    2. Configure Telemetry

    Path:

    • Devices → Configuration Profiles

    Use:

    • Device Restrictions template OR
    • Settings Catalog

    Set:

    • Telemetry = Required (Basic)
    screenshot 0026 1

    👉 This is mandatory for reporting and policy effectiveness

    screenshot 0028 1

    3. Licensing Requirements

    For full functionality:

    • Windows Enterprise E3/E5
    • Or equivalent licensing

    Do You Still Need Update Rings?

    👉 Yes — absolutely!

    Why?

    Because Feature Update Policy ONLY handles:

    ✔ Version targeting
    ✔ Upgrade control

    But it does NOT handle:

    • User experience
    • Deadlines
    • Restart behavior
    • Active hours

    👉 That’s where Update Rings come in

    Best Practice: Use Both Together 💡

    Recommended Setup

    FeatureUse
    Update RingsUser experience + deadlines
    Feature Update PolicyVersion control

    Important Considerations

    1. Do NOT Pause Feature Updates in Update Rings

    • If paused → Feature Update Policy won’t work

    2. Set Feature Deferral to 0 Days (Recommended)

    Why?

    • Feature Update Policy should control rollout
    • Deferral may delay deployment unintentionally

    3. Policies Work Together

    Even though Feature Update Policy is powerful:

    👉 It still respects Update Ring settings

    Examples:

    • Deferral = delay still applies
    • Pause = blocks update
    • Deadlines = enforced

    Final Thoughts

    If you want a modern, controlled, and scalable approach:

    👉 Use Feature Update Policy for version control
    👉 Use Update Rings for user experience

    Once you understand how both work together, you gain:

    • Full control over Windows updates
    • Better user experience
    • Reduced risk during upgrades

    Wrapping Up

    That’s all for this post!

    If you found this helpful, feel free to connect with me on LinkedIn or share your thoughts.

    Thanks for reading 🙌


    Discover more from Intune | SCCM | Device Management| Enterprise Mobility & Security

    Subscribe to get the latest posts sent to your email.