Event banner
Windows Office Hours: September 28, 2023
Event details
Please note this Windows Office Hours date has been changed to September 28, 2023.
Get answers to your questions about adopting Windows 11 and managing the Windows devices used by remote, onsite, and hybrid workers across your organization. Get tips on keeping devices up to date effectively! Learn how to cloud attach your on-premises workloads!
Windows Office Hours is our continuing series of live Q&A for IT professionals here on Tech Community.
How does it work?
We will have a broad group of product experts, servicing experts, and engineers representing Windows, Microsoft Intune, Configuration Manager, Windows 365, Windows Autopilot, security, public sector, FastTrack, and more. They will be standing by here -- in chat -- to provide guidance, discuss strategies and tactics, and, of course, answer any specific questions you may have.
Post your questions in the Comments early and throughout the one-hour event.
Note: This is a chat-based event. There is no video or live meeting component. Questions and answers will appear in the Comments section below. |
129 Comments
- Heather_Poulsen
Community Manager
That concludes Windows Office Hours for today. We appreciate you joining us and we'll continue to work to answer your questions below. RSVP for next month and add it to your calendar: https://techcommunity.microsoft.com/t5/windows-events/windows-office-hours-october-19-2023/ev-p/3871718
- RyanSpoonerJCBIron ContributorDamn, I just missed it. Guess I'll have to wait until October to ask my question 🙂
- ThomasTrombley
Microsoft
We're lurkers Ryan. Feel free to post your question! Best, Thomas
- LorisC80Copper ContributorWe have an issue acquiring digital licenses from O365 tenants. It happens on several workstations - for no apparent reason - that sometimes Windows loses the acquisition of the Win10 Enterprise license related to the E3/E5 license and Windows returns to the Pro version by taking the product key from the UEFI. We have made dozens of attempts to solve the problem, but without success. Sometimes a reboot is enough, sometimes you need to disconnect the O365 account and reconnect it. The problem has been appearing about 4 months ago without any change in our configurations. Do you have any suggestions to give us? What can we investigate? This is a big problem because most people work on the move and, when the version is upgraded to Pro, the Always On VPN no longer connects automatically A thousand thanks
- LorisC80Copper ContributorThanks a lot I undestand that it's a complex problem. We spent a lot of time looking for a solution.....we are able to mitigate the problem, but not to solve it. Thanks in advance for your and your colleagues help
- ThomasTrombley
Microsoft
Good Morning/Afternoon/Evening Loris, I am working on an answer for you. This is a bit out of the scope of our Windows Office Hours crew, so I am working on finding an expert to help! Best, Thomas
- ChrisAtMafSteel ContributorSince configuring 'Specify source service for specific classes of Windows Updates' to point Windows 11 to install quality updates from WSUS (disabling Dual Scan), computers pointing to a WSUS server get a 0x800f0950 error when trying to install any Features on Demand (e.g. NET Framework 3.5, or Server Core App Compatibility https://learn.microsoft.com/en-us/windows-server/get-started/server-core-app-compatibility-feature-on-demand). The only fix appears to be to temporarily change the SetPolicyDrivenUpdateSourceForQualityUpdates registry key. https://learn.microsoft.com/en-us/answers/questions/703064/specify-source-service-for-specific-classes-of-win Is this a known issue within Microsoft and when will you be resolving it?
- Sudhagar Thirumoolan
Microsoft
Features On Demand Support in WSUS is only available starting with Windows 11 22H2. You can find more about this in the blog post here - https://techcommunity.microsoft.com/t5/windows-it-pro-blog/get-ready-for-the-first-uup-on-premises-updates-coming-in-march/ba-p/3738461. Alternatively, you can configure a policy to only download FODs from the internet but continue to get your feature \ quality updates from WSUS. More details here. https://learn.microsoft.com/en-us/windows-hardware/manufacture/desktop/configure-a-windows-repair-source?view=windows-11#use-windowsupdate-to-restore-optional-features-and-repair-windows-images Please let me know if that helps.- ChrisAtMafSteel Contributor
Hey, if you have a look at the forum post I mentioned you'll see that we already tried setting 'Specify settings for optional component installation and component repair' which is mentioned in your article. Even if this is set, FoD installations throw the error I mentioned when SetPolicyDrivenUpdateSourceForQualityUpdates is set to pick things up from WSUS. What else can we do? We want WSUS to be used for feature / quality updates with dual scan, and FoD to be retrieved from Windows Update, without errors.
- AkGayamCopper ContributorIs Windows Autopatch same as Windows Update rings but with more granular control and software update management? Will Windows Autopatch replace Update rings in the future? We currently have Microsoft 365 A5 licenses, is there a possibility the service to be extended to A5 subscription in the future?
- David_Guyer
Microsoft
Hi Akshay, I think of Autopatch as a layer on top of the basic update policies in Intune that provides tools for organizing your Autoptach groups and rings, and creating policies, like update Rings policies for you and helping with best practices and recommended settings. Over time, both layers will evolve together, including Update Rings. HTH.
- Rich_OlsonCopper ContributorWould an Intune Windows Update Ring for devices that are domain joined automatically enroll devices into Windows Insider Program - we are seeing this happen without any user interaction?
- David_Guyer
Microsoft
Not unless you configure Enable Preview Builds.- Rich_OlsonCopper ContributorWell we were new to Update Rings in Intune and did not understand all the settings. We adjusted the hours for the update ring and then machines starting getting Windows 11 insider preview that were not able to even get Windows 11. I posted about that in another thread.
- mikey365Brass ContributorPlease add an Intune policy to silently sign in users to Entra ID Global Secure Access. End users aren't going to know what that is for and will just close the pop up dialog box to sign in.
- Heather_Poulsen
Community Manager
Noted! Please also file this feedback at https://aka.ms/intunefeedback or upvote it if it exists already.
- RussJ70Copper ContributorWe have blocked the MS Store using an Intune Policy using Settings Catalog which works fine and we push apps from the Company Portal...however in order to allow users to try the Teams preview we have had to reverse that setting but we have got app installation restrictions in place. Is that the only way to achieve the Teams Preview installation? And is there any documentation regarding this anywhere?
- Heather_Poulsen
Community Manager
The public preview of Teams is enabled on a per-user basis, and the option to turn on public preview is controlled in an admin policy. Please see Public preview in Microsoft Teams for more details.
- RussJ70Copper ContributorYes we have that set in the Teams Admin center so the slide bar appears in Teams for then user, but when they select it the download is blocked unless we open up the Store via the Intune policy...
- Daniel_BargeCopper ContributorIn Intune, is there anything like Monitoring > Deployments in SCCM? Any way to monitor deployments and their percentage of completion, as well as other filters like Date created, deployment start time, etc.?
- David_Guyer
Microsoft
Hi Daniel, if you are using Feature update, or Driver update policies, or the Expedited Quality update policies then there are reports showing exactly that under Reports, Windows Updates, and even more detail in the reports on the Reports tab there. We are hoping to add more tools and reports for Quality updates in the future. HTH.- Daniel_BargeCopper ContributorSorry if I was unclear. I'm more concerned with having this information for win32 app deployments. Is that feature available or coming in the future?
- rcclark333Copper ContributorAre there any plans to allow folders in new Outlook to be arranged by Folder. I, among others, use the Unread Mail sorted by folder. With numerous rules moving emails to certain folder, it is difficult to triage unread emails when I can't arrange by folder.
- ThomasTrombley
Microsoft
Let me know if any of these help: 1. Click on the mail folder you would like to organize. Go to the View tab in Outlook, then click the Arrange By dropdown menu. Click on the Unread option and you’ll see all of your unread messages move to the top of the inbox. 2. Go to 'View|Current View|Customize Current View', click the "filter" button, go too the "More Choices" tab, add a checkmark to "Only items that are" checkbox, and select "Unread. You can also just 'View|Current View|Unread mail in this folder". 3. Right-click Search folders > New Search Folder > Custom > Create a custom search folder > Choose. Type a Name and select Criteria > More Choices > Only items that are "Unread". Now select Browse, untick the top-level folder (for your email account), and select your "MyAdmin" folder and check "Search subfolders". 4. In Mail, select the folder you want to filter for unread messages. Near the upper right corner of the message list, select Filter > Unread. 5. Sort emails by unread then date in searching folder of Unread Mails 1 (1) Click to select the Unread mail in the Select a Search Folder box; 2 (2) Click the Search mail in box and specify the email account whose unread emails you will collect; 3 (3) Click the OK button. - Heather_Poulsen
Community Manager
We don't have anyone "in the office" today that specializes in Outlook, but we're on the hunt for the right person. Stay tuned!
- erickmichaelCopper ContributorWe have a large number of devices that haven't processed their Windows Updates and are still on an older version of Windows and don't understand why. Can you provide some guidelines for what we should be checking on the devices or in Intune to see why the updates aren't processing? When we talked to Microsoft support they suggested that we set our Maintenance time on the devices to 7pm instead of the default of 12am and we made that change over a week ago, but that doesn't seem to have changed anything. The devices show that the Update Ring policy "Succeeded", Windows Health Monitoring is "Enabled", Reporting and Telemetry are set to "Required", the Telemetry proxy server has been left as <blank>, the devices are checking in to Intune, the devices are marked as company owned, and you can see our policy settings below. Microsoft product updates Allow Windows drivers Allow Quality update deferral period (days) 2 Feature update deferral period (days) 2 Upgrade Windows 10 devices to Latest Windows 11 release No Set feature update uninstall period (2 - 60 days) 15 Servicing channel General Availability channel User experience settings Automatic update behavior Auto install at maintenance time Active hours start 7 AM Active hours end 6 PM Restart checks Allow Option to pause Windows updates Disable Option to check for Windows updates Enable Change notification update level Turn off all notifications, excluding restart warnings Use deadline settings Allow Deadline for feature updates 4 Deadline for quality updates 4 Grace period 7 Auto reboot before deadline Yes
- David_Guyer
Microsoft
Erick, on first glance there are no settings you've configured here that would prevent devices from getting updated. I mostly recommend starting with https://support.microsoft.com/en-us/windows/troubleshoot-problems-updating-windows-188c2b0f-10a7-d72f-65b8-32d177eb136c and then reaching out to support so that we can work with you to collect and analyze logs, and truly troubleshoot. There are a few basic things that I can share that may help you get started... check if clicking the Check for Updates successfully gets any updates, to ensure the device is generally update healthy, and getting through firewalls etc... If that's working manually, but not working automatically, then you can check if devices are being turned off outside of active hours, or other issues. Hope something in there helps!