Forum Discussion
BBI-Kyle
Jun 17, 2021Copper Contributor
Is there a way to update users computers via intune?
Is there a way to set up a policy via intune or Active Directory that automates Windows updates for all our end user computers?
- Jun 17, 2021That's a great question! While we recommend you maintain the default settings, the one setting we do recommend you set it deadline. Configuring deadline will enforce users to have to take the update within X number of days you specify. If a user pauses the update, the deadline counter will start once the the pause has ended so that the user has to take the update after pause. End users will be offered a chance to update through a walkthrough before the device is forced to update and reboot. You can check out more details about setting a compliance deadline and the end user experience here: https://docs.microsoft.com/en-us/windows/deployment/update/wufb-compliancedeadlines
BBI-Kyle
Jun 17, 2021Copper Contributor
Kay_Toma Can users keep delaying the update more than 35 days? Is there any way we can force end users computers to update? I'm asking because we're trying to get users computers updated as much as possible to prevent any potential security risks or issues.
Kay_Toma
Jun 17, 2021Former Employee
That's a great question! While we recommend you maintain the default settings, the one setting we do recommend you set it deadline. Configuring deadline will enforce users to have to take the update within X number of days you specify. If a user pauses the update, the deadline counter will start once the the pause has ended so that the user has to take the update after pause. End users will be offered a chance to update through a walkthrough before the device is forced to update and reboot. You can check out more details about setting a compliance deadline and the end user experience here: https://docs.microsoft.com/en-us/windows/deployment/update/wufb-compliancedeadlines
- David_GuyerJun 18, 2021
Microsoft
I can help a little here. When pause is set via policy, such as by an admin using Intune or a local admin use GPEdit, the default pause will be for 35 days, or until the pause is removed by the admin. However, when updates are paused using the Windows Update settings in Windows, the pause lasts only 7 days and the device must scan and successfully install any offered updates before they can pause again.
Hope this helps
-DG