Event banner
AMA: Managing Windows updates
Event details
Hi!
Thanks for the opportunity to get in touch on the Windows Update topic!
I'm currently managing a fleet of 1000+ Dell Notebooks using Microsoft Intune. Our devices are hybrid joined and we're switching from WSUS to Autopatch. At the moment I'm implementing a mix of Autopatch and the Dell Command Update tool that can be controlled by ProActive Remediations to search and scan for driver/firmware/bios updates. TBH it's a huge pain and I'm starting to think if the drivers provided by Windows Update are "good enough". Dell Command Update seems to have newer versions of drivers, firmware and especially bios though. Is this going to change in the future and drivers might get more up-to-date?
Dell seems to be working together closely with Microsoft and we really appreciate Microsoft implementing new features with Dell as a "pioneer". Things like pushing BIOS settings to our devices using a simple Intune config profile and the Dell Command Endpoint Configure for Microsoft Intune tool are a really good step in the right direction. Are there any plans to bring together Windows Update and Dell Command Update even closer in the future? BIOS updates seems to be available on Dell tools way sooner than they are in Windows Update and the updating process itself seems more stable when using the Dell tool. ProActive Remediations can't be used in this scenario because the time of execution is way too random and never as set in the script frequency. Are there any changes coming to Windows Update considerung BIOS updates? Getting them sooner, making the update process more reliable? Maybe even manage bios version "like apps" using Autopatch?
Thanks a lot for your great work, keep it up! π
Thanks for answering my question!
May I ask a (little shorter π ) Follow-Up question? Are the Teams working on the Microsoft Defender Vulnerability Management development syncing with the teams working on Windows Update driver deployment? As an Intune admin I'll keep on getting reports of missing driver, firmware and bios updates from my security colleagues (which is great, kudos to Defender). Would be even greater if Autopatch has all the updates available that Defender is asking for. Is this a scenario Microsoft is or will be providing in the future? Like "Defender and Intune using the same database for the newest / most secure version of drivers, firmwares and bios updates"?
Love to the talk. Thanks a lot!
- Jason_SandysJun 05, 2024
Microsoft
Keep in mind that most drivers aren't provided by Microsoft. Most drivers in WUfB are published and maintained by the vendors/OEMs so closing the described gap here is entirely incumbent on the vendors/OEMs and thus really a question better posed to them.- Fabian_MayJun 05, 2024Copper Contributor
Jason_Sandys Thank you, that makes sense. Guess we have to hope OEMs are handing over updates to Microsoft sooner in the future. Is Microsoft involved in this process by any means? Pushing OEMs to publish updates when Defender is reporting missing updates that havn't been transfered to Windows Update?