Windows Update for Business began as a limited, cloud-based Windows Update management tool, utilizing the Windows Update service that today manages the updates for hundreds of millions of devices. With more commercial organizations turning to cloud-based update management and deployment solutions, we are enhancing and expanding the capabilities of Windows Update for Business to make the move to the cloud even easier. From simplified branch readiness options to better control over deadlines and reboots, there are several enhancements available in Windows Update for Business with the release of Windows 10, version 1903.
Let’s take a look at the changes.
Because Windows 10 releases on a single Semi-Annual Channel (SAC), beginning in Windows 10, version 1903, we have simplified deployment ring creation with a single common start date for phased deployments across an organization. With a common start date, you can more easily use Windows Update for Business to implement a customized deployment plan (using deferral rings) to manage the validation and deployment of Windows quality and feature updates.
Windows Update for Business will feature a new UI and behavior to reflect this change, eliminating the dual offset milestone dates for SAC and SAC-T, and reinforcing a single SAC release date as the basis for beginning targeted deployment and working toward broad deployment. As noted in my previous blog post, Windows Update for Business and the retirement of SAC-T, we will handle this one-time transition in the following manner:
Once your devices have been updated to Windows 10, version 1903, please modify your Windows Update for Business deferral values if you wish to proceed with designating an additional delay between your targeted phase and broad deployment phase for the next Windows 10 feature update.
Compliance deadlines in Windows Update for Business help you manage how quickly devices in your organization receive and apply an update, often referred to as the update velocity. They provide you with the ability to define separate reboot experiences for Windows 10 feature and quality updates, and offer a proactive reboot escalation path as a device approaches the deadline.
With Windows 10, version 1903, we are bringing the following improvements to the deadline experience in Windows Update for Business:
With these improvements, it will be easier for you to consistently ensure update compliance for your organization, including your mobile workforce. With previous releases, enforcement of a configured deadline began only after a device installed the update and was pending a reboot (to apply the update). Beginning with Windows 10, version 1903, deadline enforcement begins the day an update is offered to a device, after any configured deferral has expired. IT administrators can leverage compliance deadlines to control deadline behavior for feature updates, quality updates, and non-OS updates. For example:
In this example, the first two configurations specify the number of days the device being targeted for that class of updates will have before a mandatory reboot takes place. The third configuration will be new to Windows Update for Business, and enables you to configure a grace period, i.e. the minimum amount of time an end user has to commit to a restart. This provides a less rigid update experience for scenarios such as business travel and vacations. Using grace periods, an end user who returns from vacation would have additional days before needing to complete the reboot on her device.
Update Compliance is a service that enables you to utilize Windows Update for Business to monitor the update status of devices within your organization. Starting with Windows 10, version 1903, those utilizing Update Compliance can now determine which of their managed devices are not receiving a feature update due to a hardware or software compatibility issue identified by Microsoft. See the Update Compliance documentation for more details on identifying which devices are held back from updating due to known issues. To see the current upgrade compatibility holds in place, visit the Windows release health dashboard.
Beginning with Windows 10, version 1903, Windows Update for Business no longer requires a diagnostic data level of Basic or higher to enforce configured policies. Instead, privacy-sensitive organizations can utilize Windows Update for Business policies, regardless of the diagnostic data level chosen, for any devices running Windows 10, version 1607 or later.
Please note; however, that Microsoft analytics tools such as Windows Analytics still require a higher diagnostic data level in order to surface deployment insights.
I am excited to share with you the improvements coming to Windows Update for Business in Windows 10, version 1903, and encourage you to continue using Feedback Hub to share your thoughts and suggestions on additional features and functionality that would help you leverage it in your organization. Additionally, if you’re not already using it in your organization, I recommend Update Compliance to gain better insights into the update status of devices in your organization and any update blockers. To learn more, see the following resources:
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.