Reader small image

You're reading from  Mastering Microsoft Intune - Second Edition

Product typeBook
Published inMar 2024
PublisherPackt
ISBN-139781835468517
Edition2nd Edition
Right arrow
Authors (2):
Christiaan Brinkhoff
Christiaan Brinkhoff
author image
Christiaan Brinkhoff

Christiaan Brinkhoff works as a Principal Program Manager and Community Director for Windows 365 and AVD at Microsoft, in his role at Microsoft, he works on features such as Windows 11, Windows 365 app, Switch and Boot. Christiaan is also an Author (3 books) and Inventor (3 patents). His mission is to drive innovation while bringing Windows 365, Windows, and Microsoft Intune closer together, drive community efforts around virtualization to empower Microsoft customers in leveraging new cloud virtualization scenarios. Christiaan joined Microsoft in 2018 as part of the FSLogix acquisition. He has also been rewarded with the Microsoft MVP, Citrix CTP, and VMware vExpert community achievements - for his continued support in the EUC community.
Read more about Christiaan Brinkhoff

Per Larsen
Per Larsen
author image
Per Larsen

Per Larsen works as a Senior Program Manager for Microsoft Endpoint Manager - Customer Acceleration Team - Commercial Management Experiences (CMX) Engineering, where he takes learnings from Microsoft's largest and most strategic customers back into the rest of engineering to drive improvements for the service so that customers have a continuously improving product experience. He also helps deploy and adopt Microsoft Endpoint Manager - Microsoft Intune. Per mainly focuses on the management of Windows and special devices such as HoloLens 2, Surface Hub, and Microsoft Teams Room System. Per was also an MVP in Enterprise Mobility, from 1st July 2016 to when he joined Microsoft on 1st April 2018.
Read more about Per Larsen

View More author details
Right arrow

Windows Deployment and Management

In this chapter, you will get a clear understanding of how to deploy and update Windows in enterprises with Microsoft Intune and Windows Update for Business. You’ll learn about the different deployment methodologies and other features that you can use to provide Windows updates and management at the enterprise level, such as with Windows Autopatch!.

In this chapter, we’ll go through the following topics:

  • Deploying existing Windows devices into Microsoft Intune
  • What about on-premises devices?
  • Co-management
  • Tenant attach
  • Microsoft Surface and other Original Equipment Manufacturer (OEM) devices
  • Windows Update for Business (WUFB)
  • Windows 10 and Windows 11 update rings
  • Windows Autopatch
    • Windows Autopatch requirements
    • How to enable Windows Autopatch
    • Optimize Windows Update Rings
    • Enable Autopatch for Cloud PCs

Deploying existing Windows devices into Microsoft Intune

This scenario applies to physical Windows endpoints only.

In enterprise companies today, the normal approach is to leverage OS deployment either from Configuration Manager or Microsoft Deployment Toolkit.

Microsoft Deployment Toolkit (MDT) is simpler as it only requires access to a share, where the Windows 10 OS drivers and applications are stored. Microsoft does not support MDT Windows 11 OS deployment.

Both Configuration Manager and MDT often require the device to be on-premises to join the corporate Active Directory (AD) and have access to the Preboot Execution Environment (PXE) server to even get started with OS deployment.

Over the last few decades, enterprise companies have started to remove all the work that the OEM put into making a device run in the most optimal way with Windows 10, drivers, and the combination of settings that are needed on a brand-new device to perform in the best way possible. This...

Windows Update for Business

When you have devices that use Windows Update for Business to manage and control the update workflow, there are several policies that are of interest. We will cover them in this section. Update rings and features update policies are the basic policies that you, as the IT admin, should start configuring. To maximize the update velocity while remaining mindful of the impact on user productivity, Microsoft suggests a specific set of policies with recommended values. In this section, we will walk through these policies and how to configure them. Some of the benefits of using Windows Update for Business are:

  • You can control the types of Windows updates that are offered to devices in your organization, such as feature updates, quality updates, cumulative updates, and optional updates.
  • You can control when updates are applied to the devices, such as immediately after they are released, after a specified period of time, or after a specified date...

Feature updates for Windows 10 and later

Feature updates for Windows 10 and later policies work in conjunction with your Update rings for Windows 10 and later policies from Microsoft Intune, to prevent a device from receiving a Windows feature version that is later than the specified Windows version in the feature updates policy. Feature updates for Windows 10 and later leverage the Windows Update for Business deployment service.

The Windows Update for Business deployment service is a cloud service that allows you to control the approval, scheduling, and safeguarding of updates delivered from Windows Update to your managed devices. It is designed to work with your existing Windows Update for Business policies and reports, and it provides a direct communication channel between a management tool and the Windows Update service. You can use the deployment service to approve and schedule specific updates for deployment, such as feature updates, quality updates, security updates, driver...

Windows Autopatch

You’ll learn about Windows Autopatch in this section. We explained in the first chapter that Windows Autopatch is a cloud-based solution that streamlines the update process for Windows, Microsoft 365 apps, Microsoft Edge, and Microsoft Teams. In this section, we will explain how you can enable this service inside your Microsoft Intune tenant settings.

Windows Autopatch requirements

Windows Autopatch is a cloud-based solution that streamlines the update process for Windows, Microsoft 365 applications, Microsoft Edge, and Microsoft Teams.

Your enterprise will need active Microsoft 365 E3/E5 licenses to use the service. The service leverages Windows Update for Business, among other components, to carry out updates on devices. Its primary objectives are to enhance security, boost productivity within organizations, and simplify the upkeep of digital infrastructure. Windows Autopatch was first announced in July 2022, and it was rolled out for general...

Summary

In this chapter, you’ve learned about all the things you need to know in order to start deploying and updating Windows using Microsoft Intune and Windows Update for Business for different endpoint scenarios.

We went through the different options on how to update Windows and what policy settings you should apply. If you are used to leveraging Microsoft Configuration Manager to handle Windows Update, you probably already have some kind of ring deployment for deploying Windows updates in your business. With servicing profiles in the Microsoft 365 Apps admin center, you can start taking a similar approach as Windows Update for Business has ring-based deployments as well.

If you are not already running Windows Autopatch or Windows Insider for Business, we explained why it is a good idea to start, and now you are ready to configure Windows Insider for Business in your organization for a select group of users or devices. In the next chapter, we’re going to take...

Questions

  1. What is Windows Update for Business?
    1. A way to update Microsoft apps
    2. A way to update Microsoft Edge
    3. A way to update Windows
  2. What is the maximum number of days that can be configured for the Set feature update uninstall period option?
    1. 30
    2. 60
    3. 90
  3. Which license do you need for Windows Autopatch?
    1. EMS
    2. Windows 365
    3. Windows E3

Answers

  1. (c)
  2. (b)
  3. (c)

Further reading

If you want to learn more about the Microsoft Intune requirements after reading this chapter, please use one of the free online resources listed here:

Learn more on Discord

To join the Discord community for this book – where you can share feedback, ask questions to the author, and learn about new releases – follow the QR code below:

https://packt.link/SecNet

lock icon
The rest of the chapter is locked
You have been reading a chapter from
Mastering Microsoft Intune - Second Edition
Published in: Mar 2024Publisher: PacktISBN-13: 9781835468517
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
undefined
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at £13.99/month. Cancel anytime

Authors (2)

author image
Christiaan Brinkhoff

Christiaan Brinkhoff works as a Principal Program Manager and Community Director for Windows 365 and AVD at Microsoft, in his role at Microsoft, he works on features such as Windows 11, Windows 365 app, Switch and Boot. Christiaan is also an Author (3 books) and Inventor (3 patents). His mission is to drive innovation while bringing Windows 365, Windows, and Microsoft Intune closer together, drive community efforts around virtualization to empower Microsoft customers in leveraging new cloud virtualization scenarios. Christiaan joined Microsoft in 2018 as part of the FSLogix acquisition. He has also been rewarded with the Microsoft MVP, Citrix CTP, and VMware vExpert community achievements - for his continued support in the EUC community.
Read more about Christiaan Brinkhoff

author image
Per Larsen

Per Larsen works as a Senior Program Manager for Microsoft Endpoint Manager - Customer Acceleration Team - Commercial Management Experiences (CMX) Engineering, where he takes learnings from Microsoft's largest and most strategic customers back into the rest of engineering to drive improvements for the service so that customers have a continuously improving product experience. He also helps deploy and adopt Microsoft Endpoint Manager - Microsoft Intune. Per mainly focuses on the management of Windows and special devices such as HoloLens 2, Surface Hub, and Microsoft Teams Room System. Per was also an MVP in Enterprise Mobility, from 1st July 2016 to when he joined Microsoft on 1st April 2018.
Read more about Per Larsen