Event banner
AMA: Windows update and driver management
Event details
Get the tips and insights you need to manage Windows updates and drivers with ease. This session is designed to answer your questions about unified update management in Microsoft Intune, Windows Autopatch, hotpatch updates, and more. Need help understanding which policies to set—and which to avoid? Curious about moving from Windows 11, version 24H2 to version 25H2 later this year via an enablement package? Looking for more automation and less end user disruption? Come Ask Microsoft Anything (AMA)!
On the panel: Surabhi Calla, Vishal Bajaj, Ken Goossens, and Ranjith Reddy
This event is part of the Tech Community Live: Windows edition.
44 Comments
- ITSTorgCopper Contributor
can hot patch policy conflict with autopatching?
- Jason_Sandys
Microsoft
No although I'm not exactly sure what you mean by "Autopatching". Autopatch is a service that delivers updates to Windows devices that all update delivery from the cloud is "Autopatching". Is there a specific scenario or challenge you are concerned about?
- EricMoe
Microsoft
Hotpatch is fully compatible with Autopatch. Hotpatch updates | Microsoft Learn
- Tomasz WoźniakCopper Contributor
What are your plans regarding enablement package for 26H2, 27H2 and so on ? Will I have to reinstall the systems every now and then again ?
- EricMoe
Microsoft
We recently announced Windows 11 25H2 will be an enablement package to Windows 11 24H2. At this time, we have nothing to disclose for future releases. I'm unsure what you mean by "reinstall the systems".
- Tomasz WoźniakCopper Contributor
What I mean is the migration from earlier version of Windows 11 to Windows 11 24H2 requires full reinstallation of Windows operating system in place in comparison to the user friendly enablement package. If I have to reinstall the systems to upgrade from 24H2 to 25H2,26h2, 27H2. It is a big hassle for the users and IT admins. Each full upgrade in place takes about 1 hour per client. Not to mention the time spent on the troubleshooting for the failed installations.
- BlueSakuraBrass Contributor
Will Intune going to provide an option under device to Check/Install Windows Update? Just like we have options to update Windows Defender. This way we can easily and silently update a device if the device for whatever reason isn't naturally updating.
- EricMoe
Microsoft
In Windows Autopatch Update policy per ring, there is a setting "Option to check for Windows updates" - check out the official setting documentation here Windows Update settings you can manage with Intune Update Ring policies for Windows 10/11 devices. | Microsoft Learn
- jackfordCopper Contributor
Hi,
What is the recommended best practice for updating Lenovo drivers and bios automatically. How do we get driver updates applied as part of Autopilot pre-provision.
thank you
- EricMoe
Microsoft
Let's split your ask into two separate asks - Lenovo drivers being one ask, BIOS/UEFI updates as another. In terms of driver management, in Autopatch you can configure your driver approvals to be Automatic for one or more rings. https://learn.microsoft.com/en-us/windows/deployment/windows-autopatch/manage/windows-autopatch-manage-driver-and-firmware-updates covers the details about how to set Automatic approval for a ring. If all of your devices are from Lenovo, this is pretty easy - all of your rings would have Automatic driver approval. If you have a mix of Lenovo and other devices, and only want to Automatically approve your Lenovo drivers, then you would need to do some ring construction to keep Lenovo devices across one set of rings with automatic driver approval, and then your other devices in a different set of rings with manual driver approval. Now, when it comes to BIOS/UEFI, these types of driver updates are always going to require manual approval. These drivers show up in the "Other drivers" tab of your list of drivers to approve. You will need to decide which BIOS/UEFI drivers you want to install and then approve them.
- ofortunBrass Contributor
Now, when it comes to BIOS/UEFI, these types of driver updates are always going to require manual approval.
Edited...
I was under the impression that these would be automatically approved and added to the Recommended list. We see this for most devices.
Looking at our driver update policies, I see what you mean. Is this documented somewhere that we'll need to perform a review? Are there other classes or manufacturers that also require review?
- txtechsquadCopper Contributor
One of the biggest questions we are facing is a big issue with the Feature update from 23H2 to 24H2. How to solve it? And the company uses Autopatch.
- EricMoe
Microsoft
There is a feature update failures (Operational) report Use Windows Update for Business reports for Windows Updates in Microsoft Intune - Microsoft Intune | Microsoft Learn that you can dive into and individual device errors should have an alert message coupled with full details including how to remediate the issue. Hope this helps.
- HeyHey16KIron Contributor
In Intune how can we pause a single Windows Update? At the moment it seems we can only pause ALL updates or NONE?
- Pearl-Angeles
Community Manager
Thanks for your participation! The panelists covered your question at 9:58.
- HeyHey16KIron Contributor
Thank you 🙂
- ArshadJ685Copper Contributor
How do we patch devices that are on all day everyday but can only be patched and restarted during the weekends? And if it misses the update&restart during that weekend, to try again the next weekend. Basically, not patch and restart during week days at all. Is that even possible with WUfB/Autopatch?
- Pearl-Angeles
Community Manager
Thanks for your question! The panelists covered this topic at 1:48 in today's live session.
- Thomas RedmerBrass Contributor
We are blocked from using driver management, because video/audio/network/Bluetooth driver background installs interrupt the users. Screen flickering, audio or network dropping, BT mouse/keyboard disconnected. During presentations or online meetings.
How to prevent that? I'm referring to Autopatch default/recommended settings for single user devices:
"Automatically install". Which is a great setting to roll out CUs fast, because they don't cause interruption. But it applies the same for drivers, which is problematic.
"Schedule Install" is not nice for that use case either, because drivers will still install automatically outside then-fixed active hours. Or if devices are powered down, will be delayed till deadline.- Katie_Yao
Microsoft
Schedule Install is the best practice we recommend and the driver policies should land on devices. Please share your logs and screenshots via Feedback Hub for further investigation-->Send feedback to Microsoft with the Feedback Hub app - Microsoft Support
- dkallertCopper Contributor
Im interested in that too. WUfB is such a nice Feature, but the described experience is killing the good impression.
- reastman1966Brass Contributor
I am looking for the best practice on how to have Intune offer the latest drivers for our Lenovo devices and what Intune will not offer to the devices? I noticed that bios updates are not offered by Intune and had to use the Lenovo Vantage application to get it to install. Our parent company uses Dell devices and they don't seem to have to use anything other than Intune for updates.
- Jason_Sandys
Microsoft
Which OEM specific updates including drivers and firmware that are offered are ultimately up to the OEM and not Microsoft. If there is a driver or firmware version missing for devices in your organization, you should contact your OEM as they are in complete control of publishing.
- ON2000Brass Contributor
My recent Lenovo X1 Carbon for example had its BIOS updated few days ago, with a 3 months old BIOS version, and it was deployed through Intune/WUfB. A newer from mid-June is already available on Lenovo website, but if you ask me as a simple user : I am happy to know it works already so good.