Forum Discussion
Windows 10 update rings not applying patches
Could you share your settings? Like deferral, deadline settings and service channel?
You could take a look at the end user status report (when you opened the update ring)
Or take a look at this site, to implement update ring reporting
https://www.jeffgilb.com/update-compliance-with-intune/
And
Updatenalevingsrapporten voor Windows-updates gebruiken in Microsoft Intune - Microsoft Intune | Microsoft Docs
If you have an additional rmm tool (like we have) you could monitor it from there
https://call4cloud.nl/2020/08/reservoir-update-logs/
But security center shows patches older than 30 days are missing
- DBR14May 24, 2021Iron ContributorDid you have any luck figuring this out? I'm trying to get 150 Surface 3 laptops to move up from 1909 to 20H2 and despite my settings I'm just seeing them listed as 1909 Up to Date in the Update Ring information. Deferral for quality and feature are set to 0 and then 2 deadline deferral days, otherwise these things should be rocking an rolling. I'm more confused about the 1909 "Up to Date" readout.
- May 25, 2021
Hi,
Just like I mentioned in another post about update rings ,what happens when you try it out with the feature update deployment?
And did you make sure Telemetry is configured and the sign in assistant service is running?
- DBR14Jun 01, 2021Iron Contributor
I've had a Feature update ring on for as long as I've had the Update Ring going. I had it set to go to 20H2. But some laptops that I forced an interactive update scan using usoclient.exe startinteractivescan went to 21h1 rather than holding at 20H2 as I had indicated with the Feature Update Ring, not a huge deal but it clearly didn't listen to the policy -- which I'm not surprised because preview features are generally junk anyways and rarely work.
I turned on telemetry - now it no longer has a "basic" selection there is:
Not Configured (what was on)
Diagnostic Data OffRequired (What I changed it to)
Enhanced - 1903 and Earlier
OptionalAs for the Sign-in Assistant, these are all AAD machines so there isn't any sort of group policy and no reason I could see that service being turned off. But when spot-checking a few machines using sc query "wlidsvc" I do see it in a stopped state.
- Apr 01, 2021Just looked at your update ring, They are sort of okay 🙂 . I prefer some lower deadline and deferral days... Kenneth created a great article about it
https://www.vansurksum.com/2021/03/30/configuring-windows-update-for-business-settings-for-your-microsoft-endpoint-manager-managed-modern-workplace/
Could you also share the picture from the security center? Thanx