Hi elizarov . We are doing some final testing so that we can update our documentation on the scenario of using Drivers in Intune without moving the entire Windows Update co-management workload over to Intune. Currently, the solution appears to be to use "domain" group policy to set the scan source policy to Windows Update for Drivers, and also keeping DisableDualScan = 0, false, disabled. The reason is that the CM agent is resetting that value back to WSUS when co-management is enabled, but the Windows Update workload is still set to Configuration Manager, and Domain Group Policy overrides that. There is a change being worked on to add the scan source policy setting to Configuration Manager, so that the agent knows which way to set that, and Domain Group Policy will no longer be needed, so it's a temporary workaround for now. I hope that his helpful... would love to hear if this works for you! -David