Forum Widgets
Latest Discussions
Automatic update settigns misconfigured alerts on autopatch mgmt status
I logged a case with Intune support and got below response after hours of troubleshooting; I am unsure where is the stale GPO policy is coming from. During troubleshooting, we reviewed an affected device and observed that under Settings > Windows Update > Advanced options > Configured update policies, the following setting was present: Configure automatic updates Value: 1 (Disable automatic updates) Type: Group Policy At the same time, we also verified that the device is receiving the expected Intune/MDM Windows Update for Business policies, including: Configure automatic updates = Value 2 (Auto install updates at maintenance window) Multiple Windows Update for Business settings showing Type: Mobile Device Management (MDM) This indicates that the device is receiving the intended Intune update configuration, while Windows is simultaneously detecting a separate Group Policy-based configuration that disables automatic updates. This conflicting configuration is what Windows Autopatch identifies and reports as "Automatic update settings misconfigured." From our investigation, this does not appear to be an Intune configuration issue because: The affected devices are Microsoft Entra joined and are successfully receiving Windows Update for Business policies from Intune. The Intune update ring settings are being applied correctly and are visible under the MDM-managed policies. A previously affected device was remediated and now reports correctly, confirming that Windows Autopatch and Intune update ring configurations are functioning as expected. The issue is related to a conflicting Group Policy-style update configuration that Windows continues to detect on the device, rather than a failure of Intune policy deployment. Additionally, we observed that affected devices had previously been domain joined and were also managed through an RMM solution. This suggests that legacy Windows Update policy configurations may still be present on some devices and are being interpreted by Windows as Group Policy settings, leading to the Autopatch alert. Since one device has already been successfully remediated, the recommended next step is to compare the remediated device against the remaining affected devices to identify the common configuration causing Windows to report: Configure automatic updates = 1 (Disable automatic updates) Once the source of this legacy configuration is identified, it can be remediated across the remaining affected devices, after which Windows Autopatch should reevaluate the devices and clear the alerts. Based on the evidence collected so far, the issue is not caused by Intune update ring deployment or Windows Autopatch functionality itself, but by a conflicting Windows Update policy detected locally on the affected devices.Burhan KachwalaAug 19, 2026Copper Contributor42Views0likes1CommentNot Ready - Must be managed by Intune
Hi, I am starting testing with AutoPatch and it says that my devices are not managed by Intune, but they look fine in the MEM portal. I was able to initiate a remote restart on them to confirm communication and I also successfully deployed a Win32 app to to the devices. Do you have any suggestions on on how I can get these devices into 'Ready' status?SolvedegoodmanJul 25, 2026Brass Contributor3.4KViews0likes7Commentswindows 10's update turned dell laptop in brick
Last security update on Jan 13th broke my laptop. Every program keeps freezing and doesn't do anything. Even when I open task manager it may run for a minute but soon it will freeze, and can't even end task. Only thing that is working is my browser. Yesterday I managed to reinstall windows using a USB and it was working again. While i was away, it forced an update and once again the same issues arise. laptop is too old to install 11, and going to try and reinstall windows again. There a way I can turn off the windows 10 update before this happens again? Don't know if there is a patch to address this soon. Dell inspiron 15 7559nerdyplayerJun 16, 2026Brass Contributor416Views3likes7CommentsRestore deleted policies
Hi there, The test and last update rings were deleted from our Autopatch policy. How can I go about restoring them, please? When I attempt to add groups to those rings and set deferrals, I get a warning message saying "Update policies from this Autopatch group are missing, usually because they’ve been deleted. Settings cannot be configured for missing policies until they are restored." The Deployment Ring and Feature Update settings are available to configure, but there's no editable settings for Quality and Driver Updates, so I'm unable to save the policy in the hopes to re-create them that way. Any help is appreciated!ljrb031Jun 09, 2026Copper Contributor141Views0likes1CommentRegistration Failed - Devices must be managed by either Intune or Co-mgt.
Now that you can use 365 Business Premium licences with autopatch, i'm trying to setup all devices in my office, but everyone is failing in the same way: I've checked every prerequisite - i just cant see what is wrong. Every device is managed by intune, and intune has always worked just fine (we don't use configmgr). Any suggestions?SolvedMarkHempsteadFeb 24, 2026Copper Contributor239Views1like7CommentsExclude Specific KB from Autopatch
Hi Expert, im wondering if there are any solution or trick to excludes KB or specific one from autopatch?lotfiyaakoubiFeb 06, 2026Copper Contributor90Views0likes0CommentsRename Autopatch Edge and M365 apps policies
Hi there, We have a standard naming convention for device configuration profiles. Autopatch creates Edge and M365 apps profiles using a convention that is not ideal for our team. Is there a problem with our team renaming these profiles that are auto generated? Thanks!A_BidDec 16, 2025Copper Contributor42Views0likes0CommentsSource of WNS Notification in Intune Expedite Update Policy
Hello, When creating an expedite update policy via Microsoft Intune, a WNS (Windows Push Notification Service) notification is sent to the device to trigger the MDM session and apply the policy. Once the policy is applied, the device installs the update immediately using the Microsoft Update Health Tools. My question is: Is the WNS notification sent by Intune to trigger the MDM session also responsible for initiating the expedite update installation? Or: Does the Windows Update for Business Deployment Service (WUfB-DS) send a separate WNS notification to trigger the scan and installation via the Update Health Tools? I’m looking for an official clarification on whether WUfB-DS plays an active role in sending WNS notifications in this scenario, or if the initial Intune-triggered WNS notification is sufficient to initiate the expedite update. Thank you in advance for your insights!MatAitAzzouzeneNov 14, 2025Brass Contributor91Views0likes0CommentsWindows Autopatch - monthly summary emails not received anymore
Hi, I am wondering whether anyone has the same experience -> I was receiving Monthly Quality Update Summary email from Windows Autopatch service configured in Intune. However, for last two months, this email has not arrived. I still receive the other notification email about Autopatch Advisory informing about how the updates will be deployed for the month, but not the summary email. Any idea if anything has changed? It was very useful for my monthly reporting....sumo83Sep 01, 2025Iron Contributor707Views3likes3CommentsAutopatch Readiness Not Ready
I've recently started rolling out Autopatch in our environment. I've started see devices registered with an Autopatch readiness state of Not ready. A majority of those devices are showing a Conflicting Configuration for the registry key SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\DoNotConnectToWindowsUpdateInternetLocations. But on all the devices I've looked at that key is set to 0. Which means that setting is explicitly disabled. So, it should allow devices access to the internet for Windows Updates. As far as I can tell we're not setting that regkey anywhere explicitly in a GPO. All of our devices are CoManaged with SCCM. So, I'm assuming this is something SCCM is setting. What's confusing to me is the Microsoft documentation I've looked at regarding conflicting configuration states it's looking at any setting for that existing registry key. But, if that registry key exists and it's explicitly allowing internet access to Windows Updates why would that be a problem? My other concern is if I do the suggested remediations and delete that registry key all together am I going to break something else? Or, if I delete the key, is SCCM just going to add it right back?edbachtaJul 01, 2025Copper Contributor777Views0likes3Comments
Tags
No tags to show