Endpoint Manager Feature Updates not working

Copper Contributor



We used WSUS in the past and want now to migrate to WUfB and feature update profiles. The feature update policy shows "not scanned yet". All devices are hybrid joined. The WSUS GPOs are turned off.


Update ring settings for the pilot ring:

Update settings
Microsoft product updates
Windows drivers
Quality update deferral period (days)
Feature update deferral period (days)
Upgrade Windows 10 devices to Latest Windows 11 release
Set feature update uninstall period (2 - 60 days)
Servicing channel
Retail channel
User experience settings
Automatic update behavior
Auto install at maintenance time
Active hours start
8 AM
Active hours end
5 PM
Restart checks
Option to pause Windows updates
Option to check for Windows updates
Change notification update level
Use the default Windows Update notifications
Use deadline settings
Deadline for feature updates
Deadline for quality updates
Grace period
Auto reboot before deadline
Telemetry is set to optional and Control Policy Conflict  is set to MDM Wins Over GP. The
MDM Diag Report:wufbsv.jpg
6 Replies
best response confirmed by johnsmith85 (Copper Contributor)
Hi Rudy_Ooms, I think everything is configured properly. We use Microsoft 365 Business Premium, could this be a licensing problem? I found this on the blog regarding quality updates:
Make sure you are licensed to use it: Windows 10 Enterprise E3 or E5/Windows 10 Education A3 or A5/Windows 10 Virtual Desktop Access
Feature updates should work with business premium as stated here

Did you happen to deploy a windows health monitoring report configuration profile?

@Rudy_Ooms_MVP Yes, windows health monitoring is configured. The feature update profile shows still "no scanned yet".

Hi johnsmith85, Did you ever get a resolution. I am having the exact same issue. Everything is configured correctly, but 90% of devices never update in the reports beyond offering, regardless if they have actually updated yet. It has been a week and the reports don't update once the offer is made. Many of the devices did update, but no update in reports.

I also have a tenant with lots of "Not scanned"errors.  Nearly  all are related to Hybrid Join errors. In Microsoft Entra - Devices the join status on these devices is often "Pending" or there are duplicate entries - Hybrid Joinn and Azure AD Registered.  There are articles here on how to fix the join errors . Mostly need to use the dsregcmd /leave command , make sure the group policy for autoenrollment is switched on then reboot.  Sometimes I have to delete the device in Entra then rejoin to fix these issues. 
Some errors also occur because the device has been switched off for a while

1 best response

Accepted Solutions
best response confirmed by johnsmith85 (Copper Contributor)