Event details

Welcome to Ctrl + Manage, your monthly shortcut to what's happening in Windows management.

Each month, we'll break down what's just been released, show you what's ready to try in preview, and look ahead at where Windows management is going next. Expect a practical rundown of features, capabilities, and policies, plus demos that show what they mean for you and your organization.

And Ctrl + Manage isn't just about what we want to talk about. Your questions and comments help shape where we go deeper in future episodes. So tune in, send us your feedback, and let's make managing your Windows estate a little easier, one episode at a time.

Heather_Poulsen
Updated Sep 29, 2026

18 Comments

  • jdvorskycz's avatar
    jdvorskycz
    Copper Contributor

    It would be great if updates could be scheduled in general—meaning that quality updates could, for example, be scheduled to be postponed by 3 days, then installed manually 14 days after release, and finally enforced. Drivers are a special case—it would be great if they could be scheduled for a specific day (the release date from Microsoft, just like cumulative updates), because depending on when they’re released, there are months when they come out, say, three times a week and force you to restart. Then it would be possible to schedule them similarly to quality updates. Easy as that!

  • John_Marcum's avatar
    John_Marcum
    Copper Contributor

    I think the issue with WSUS deprecation is... what is the recommended path for updating any server going forward? Not just air gapped. If Azure Arc is the answer, how do we handle 3rd-party updates that we currently publish through WSUS?

    • AriaUpdated's avatar
      AriaUpdated
      Icon for Microsoft rankMicrosoft

      Great question! What would you like to see as the path going forward? Do you want the ability to update servers via Intune as well as Azure Update Manager? For 3rd party updates, are you mostly concerned about apps?

  • Can we get support for assignment filters for these policies? I'd like to auto-approve QMR for autopilot devices, but leave it manual for non-Autopilot devices and we can't do that now :(

  • Are there any plans to include these quality update policy settings in Autopatch Group policies instead of us having to balance using both to manage updates for our autopatch devices since these policies trump autopatch for approval and deferral periods?

    • JeffGilbert's avatar
      JeffGilbert
      Tin Contributor

      my bad on the phrasing--i don't mean GPOs, I mean the quality update policies we have set in our Autopatch Groups :)

      • AriaUpdated's avatar
        AriaUpdated
        Icon for Microsoft rankMicrosoft

        Oh! I am so sorry, I didn't realize you were talking about groups! So we are definitely looking at how to better rationalize groups. I'm guessing you'd want the same manual approval and scheduling available in groups?

  • KamS's avatar
    KamS
    Copper Contributor

    Will the live session 'Ctrl + Manage: Episode 1 - Update management' be uploaded to youtube? 

  • Thanks for joining us for our first episode of Ctrl + Manage! Your questions are encouraged - post them here at any time during the live stream. 🙂

    If your organization's policies prevent you from watching the event here, you can also tune in on LinkedIn.

    • KamS's avatar
      KamS
      Copper Contributor

      Will the live session 'Ctrl + Manage: Episode 1 - Update management' be uploaded to youtube? 

  • cmendes's avatar
    cmendes
    Tin Contributor

    https://support.microsoft.com/en-us/servicing/os/windows/docs/2026/09/windows-deployment-services-deprecation-in-the-next-windows-server-release

    • Karl-WE's avatar
      Karl-WE
      MVP

      Good question! At the moment I would pursue the PSWindowsUpdate PowerShell module which works pretty well inside air-gapped, consider Delivery Optimization within these networks and try to keep your OS and App installbase consistent. 

      • LeonBrag's avatar
        LeonBrag
        Copper Contributor

        It appears that this module is  a wrapper around the Windows Update Agent, so it can't fetch updates for machines that don’t have access to Windows Update or WSUS. Therefor is seems it value on air-gapped machines is detection and orchestration, not delivery.

         

        Hence my question about long term strategy. 

        thanks 

  • Here are some suggestions for Windows Management topics, I would find interesting to hear from Microsoft see openly discussed with the community in future episodes AriaUpdated​.

    • Quick Machine Reboot:
      This technology should prevent another Crowdstrike-like impact at pre-OS boot - But how do we get there fast and at scale on existing devices?

      System requirements:
      • WinRE Partition exists
      • WinRE Partition has a size of 2 GB
      • QMR Feature activated in Settings / Policy
      • reagentc.exe points to a valid WinRE partition and is enabled.

        Caveat: enabling QMR feature in settings or via policy does NOT ensure that all requirements mentioned before are met. 
      • What is required to improve adoption of QMR on Windows Clients and Windows Server?
        • Identified blockers: 
          • WinRE Parition on OEM devices, VMs and other installations
            • WinRE partition too small
            • removed by customers (reasons them deleding it and remediations)
            • how avoiding two WinRE partitions after in-place upgrades
            • considering adoption improvements for existing VMs and devices:
              Removing diskpart limitations vs 3rd party tools (moving partitions / flexible expanding existing partitions, currently only supports extend ( | >>) but not expand ( << |  - shrink previous volume shrink and move data to left)
            • all seems set / enabled but reagentc is not correctly configured


    • HVCI adoption and adoption blockers, as mentioned here: 

       

    • new NVMe driver
      • released and doing good for Windows Server 2025. Tests with Windows 11 24H2 indicate great improvements.
      • roadmap, migration and adoption in Windows 11
      • migration guidance or automation for devices that unfortunately using Intel RST / VMD

    • ReFS OS boot
      • available in Windows Server vNext
      • roadmap, migration and adoption in Windows 11
      • benefits vs risks
      • interoperability with Bitlocker
        • considering adoption improvement for existing VMs and devices:
          NTFS to ReFS converter - we had that for FAT to FAT32 and FAT32 to NTFS.

    • Bitlocker / Bitlocker HW accelerated encryption
      • Discussing new Bitlocker feature
        • considering adoption improvement for existing VMs and devices:
          XTS AES 256 is still not the default for OS and data volumes. Is Windows 7 compatibility still required?
        • migration and day two experiences / tools
      • Bitlocker Security in times of AI / Post-Quantum

    • Windows version
      • get-computerinfo: reports Windows 10
        • 3rd party tools often get irritated
        • A change worth the risk in 2026+?

    • Missing PowerShell commands, modules or switches
      • Which frequent management or troubleshooting tasks and scenarios require you to fallback to commandline tools in your scripts or at the command-line/ Microsoft Terminal. see also 

    • 32bit apps - can we let them go, yet?
      • Discussing an optional removal of SYSWOW64
        • chances and benefits for
        • Discussing the risks:
          • is Microsoft ready in terms of their own processes and tools
          • Installer landscape
          • Discussing and Identifying 32 bit apps and processes at scale.
          • Getting in touch with vendors / developers identifying low hanging fruits