Forum Discussion
Intune Update Ring not applying to co-managed Windows 11 device
Wua will not go over internet using the Windows Update for business channel if there is a policy for using on-prem update source. You can check the Windows Update->Advanced Options->Configuration update policies to verify if the policy provider is still showing as GPO\local policy etc. If that is the case, then you must address the source for conflicts.
I am not using WAU over the internet. this was already addressed in the original post. I have already checked Configured update policies, Group Policy, local policy, WSUS, and the per-category scan-source settings. I am aware that the device isn't currently reaching Microsoft Update, but we haven't found an active on-premises update-source policy causing this behavior, so this does not appear to be the issue in this case.
- rahuljindalSep 05, 2026Bronze Contributor
Did you check under the configure update policies as I mentioned before? GPO, Local policy (ConfigMgr) will take precedence over Intune for WU. You can also run RSOP to check which all WU policies are still being applied by on-prem.
- FaisalMSep 08, 2026Tin Contributor
The issue was caused by an Intune policy conflict with another policy assigned to the device. After removing the device from the conflicting policy assignments, the expected Windows Update policies applied successfully. The issue was not related to WSUS, Configuration Manager Software Update policies, or Group Policy, as those configurations had already been removed from the system during troubleshooting.
I also uninstalled the MECM client to make it Intune-managed, which helped isolate the problem to Intune.