Expedite security updates in Microsoft Endpoint Manager admin center

Published Mar 02 2021 08:00 AM 14.2K Views
Microsoft

Update May 15, 2021: The public preview for this feature is now available in Microsoft Endpoint Manager. For more information, see Expedite Windows 10 quality updates in Microsoft Intune.


The ability to expedite Windows 10 security updates within the Microsoft Endpoint Manager admin center is coming soon as a public preview, so keep an eye on this blog for updates.

Expediting security updates can help you deploy updates faster than normal across your organization, for example, for an important security fix or a fix that solves a problem with a critical line of business application. For these faster-than-normal scenarios, especially in quality updates, expedite will help you step on the gas and go faster than your steady state configuration.

With this new capability, you can create a profile in the Microsoft Endpoint Manager admin center that will expedite Windows 10 security updates. In testing, we have seen more than 90% of expedited devices reach a ready-to-restart stage within two days. This is two to three times more devices updated successfully in the first week of a deployment compared to devices configured with common update settings.

One benefit of expediting an update is that you won’t need to modify existing quality update settings of your Windows 10 update rings. An expedite profile will temporarily override the necessary settings to ensure the expedited update is installed as quickly as possible. The settings will be automatically restored to their original state after the update successfully installs. In addition, expedited updates can be targeted to your whole organization or limited to a specific subset of users or devices.

Once you create an expedite policy, the service will contact devices to start the update deployment without waiting for the next scan for updates.

Profile settings will give you some control over the familiar restart behavior which builds on the Windows Update Compliance Deadline (you can learn more about enforcing compliance deadlines for updates). The restart experience will allow end users to manage when the restart occurs by scheduling the restart, restarting right away, or asking to be reminded later. When the restart deadline is reached, the restart will be enforced. Users will get two warning dialogs before their device automatically restarts. The enforced restart does not wait until outside of active hours to provide reliable update compliance.

Due to the short window of restart control for end users, organizations should only want to use expedited updates when they have a special need to go faster than normal. For fast, steady state patch compliance, we encourage you to use the compliance deadline with a 3-day deadline and a 2-day grace period. If you need to go even faster, use the expedite profile.

Reports to monitor expedited updates will also be entering Public Preview. The summary report will show device states, including Success, In Progress, and Errors. The error report will provide insight into errors to enable you to fix devices that need help.

Support for expediting updates in the Microsoft Endpoint Manager admin center will be available to all Windows 10 devices on builds that have not yet reached end of service (see the Microsoft Lifecycle Policy for dates and details). In addition, devices must be Azure Active Directory joined. (Note that workplace joined devices are not supported.)

 

How does it work?

The demo below shows you how to create a new expedited quality update in Intune and gives you an overview of the available settings. It also shows the restart experience and mockups of the summary and error reports.

 

To learn more

Once the expedite profile is released in Microsoft Endpoint Manager admin center, see the online Microsoft Intune documentation for more details, or watch the below video for further in-depth information:

 

 

4 Comments
%3CLINGO-SUB%20id%3D%22lingo-sub-2340939%22%20slang%3D%22en-US%22%3ERe%3A%20Expedite%20security%20updates%20in%20Microsoft%20Endpoint%20Manager%20admin%20center%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2340939%22%20slang%3D%22en-US%22%3E%3CP%3EThis%20is%20a%20very%20useful%20feature%20that%20can%20be%20used%20to%20expedite%20critical%20security%20updates%20to%20specific%20groups.%20Way%20to%20go%20Intune%20Dev%20Team.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2177116%22%20slang%3D%22en-US%22%3EExpedite%20security%20updates%20in%20Microsoft%20Endpoint%20Manager%20admin%20center%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2177116%22%20slang%3D%22en-US%22%3E%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3E%3CEM%3E%3CSTRONG%3EUpdate%20May%2015%2C%202021%3A%3C%2FSTRONG%3E%26nbsp%3BThe%20public%20preview%20for%20this%20feature%20is%20now%20available%20in%20Microsoft%20Endpoint%20Manager.%20For%20more%20information%2C%20see%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fmem%2Fintune%2Fprotect%2Fwindows-10-expedite-updates%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EExpedite%20Windows%2010%20quality%20updates%20in%20Microsoft%20Intune%3C%2FA%3E.%3C%2FEM%3E%3C%2FP%3E%0A%3CHR%20%2F%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3EThe%20ability%20to%20expedite%20Windows%2010%20security%20updates%20within%20the%20Microsoft%20Endpoint%20Manager%20admin%20center%20is%20coming%20soon%20as%20a%20public%20preview%2C%20so%20keep%20an%20eye%20on%20this%20blog%20for%20updates.%3C%2FP%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3EExpediting%20security%20updates%20can%20help%20you%20deploy%20updates%20faster%20than%20normal%20across%20your%20organization%2C%20for%20example%2C%20for%20an%20important%20security%20fix%20or%20a%20fix%20that%20solves%20a%20problem%20with%20a%20critical%20line%20of%20business%20application.%20For%20these%20faster-than-normal%20scenarios%2C%20especially%20in%20quality%20updates%2C%20expedite%20will%20help%20you%20step%20on%20the%20gas%20and%20go%20faster%20than%20your%20steady%20state%20configuration.%3C%2FP%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3EWith%20this%20new%20capability%2C%20you%20can%20create%20a%20profile%20in%20the%20Microsoft%20Endpoint%20Manager%20admin%20center%20that%20will%20expedite%20Windows%2010%20security%20updates.%20In%20testing%2C%20we%20have%20seen%20more%20than%2090%25%20of%20expedited%20devices%20reach%20a%20ready-to-restart%20stage%20within%20two%20days.%20This%20is%20two%20to%20three%20times%20more%20devices%20updated%20successfully%20in%20the%20first%20week%20of%20a%20deployment%20compared%20to%20devices%20configured%20with%20common%20update%20settings.%3C%2FP%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3EOne%20benefit%20of%20expediting%20an%20update%20is%20that%20you%20won%E2%80%99t%20need%20to%20modify%20existing%20quality%20update%20settings%20of%20your%20Windows%2010%20update%20rings.%20An%20expedite%20profile%20will%20temporarily%20override%20the%20necessary%20settings%20to%20ensure%20the%20expedited%20update%20is%20installed%20as%20quickly%20as%20possible.%20The%20settings%20will%20be%20automatically%20restored%20to%20their%20original%20state%20after%20the%20update%20successfully%20installs.%20In%20addition%2C%20expedited%20updates%20can%20be%20targeted%20to%20your%20whole%20organization%20or%20limited%20to%20a%20specific%20subset%20of%20users%20or%20devices.%3C%2FP%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3EOnce%20you%20create%20an%20expedite%20policy%2C%20the%20service%20will%20contact%20devices%20to%20start%20the%20update%20deployment%20without%20waiting%20for%20the%20next%20scan%20for%20updates.%3C%2FP%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3EProfile%20settings%20will%20give%20you%20some%20control%20over%20the%20familiar%20restart%20behavior%20which%20builds%20on%20the%20Windows%20Update%20Compliance%20Deadline%20(you%20can%20learn%20more%20about%20%3CA%20href%3D%22http%3A%2F%2Faka.ms%2FWUfBComplianceDeadline%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Eenforcing%20compliance%20deadlines%20for%20updates%3C%2FA%3E).%20The%20restart%20experience%20will%20allow%20end%20users%20to%20manage%20when%20the%20restart%20occurs%20by%20scheduling%20the%20restart%2C%20restarting%20right%20away%2C%20or%20asking%20to%20be%20reminded%20later.%20When%20the%20restart%20deadline%20is%20reached%2C%20the%20restart%20will%20be%20enforced.%20Users%20will%20get%20two%20warning%20dialogs%20before%20their%20device%20automatically%20restarts.%20The%20enforced%20restart%20does%20not%20wait%20until%20outside%20of%20active%20hours%20to%20provide%20reliable%20update%20compliance.%3C%2FP%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3EDue%20to%20the%20short%20window%20of%20restart%20control%20for%20end%20users%2C%20organizations%20should%20only%20want%20to%20use%20expedited%20updates%20when%20they%20have%20a%20special%20need%20to%20go%20faster%20than%20normal.%20For%20fast%2C%20steady%20state%20patch%20compliance%2C%20we%20encourage%20you%20to%20use%20the%20compliance%20deadline%20with%20a%203-day%20deadline%20and%20a%202-day%20grace%20period.%20If%20you%20need%20to%20go%20even%20faster%2C%20use%20the%20expedite%20profile.%3C%2FP%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3EReports%20to%20monitor%20expedited%20updates%20will%20also%20be%20entering%20Public%20Preview.%20The%20summary%20report%20will%20show%20device%20states%2C%20including%20%3CSTRONG%3ESuccess%3C%2FSTRONG%3E%2C%20%3CSTRONG%3EIn%20Progress%3C%2FSTRONG%3E%2C%20and%20%3CSTRONG%3EErrors%3C%2FSTRONG%3E.%20The%20error%20report%20will%20provide%20insight%20into%20errors%20to%20enable%20you%20to%20fix%20devices%20that%20need%20help.%3C%2FP%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3ESupport%20for%20expediting%20updates%20in%20the%20Microsoft%20Endpoint%20Manager%20admin%20center%20will%20be%20available%20to%20all%20Windows%2010%20devices%20on%20builds%20that%20have%20not%20yet%20reached%20end%20of%20service%20(see%20the%20%3CA%20href%3D%22http%3A%2F%2Fdocs.microsoft.com%2Flifecycle%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMicrosoft%20Lifecycle%20Policy%3C%2FA%3E%20for%20dates%20and%20details).%20In%20addition%2C%20devices%20must%20be%20Azure%20Active%20Directory%20joined.%20(Note%20that%20workplace%20joined%20devices%20are%20not%20supported.)%3C%2FP%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId--522252744%22%20id%3D%22toc-hId--522253829%22%20id%3D%22toc-hId--522253829%22%20id%3D%22toc-hId--522253829%22%20id%3D%22toc-hId--522253829%22%3EHow%20does%20it%20work%3F%3C%2FH2%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3EThe%20demo%20below%20shows%20you%20how%20to%20create%20a%20new%20expedited%20quality%20update%20in%20Intune%20and%20gives%20you%20an%20overview%20of%20the%20available%20settings.%20It%20also%20shows%20the%20restart%20experience%20and%20mockups%20of%20the%20summary%20and%20error%20reports.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CDIV%20style%3D%22position%3A%20relative%3B%20padding-bottom%3A%2056.25%25%3B%20padding-top%3A%2030px%3B%20height%3A%200%3B%20overflow%3A%20hidden%3B%20min-width%3A%20320px%3B%22%3E%3CIFRAME%20src%3D%22https%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fvideoplayer%2Fembed%2FRWyOPL%3Fautoplay%3Dfalse%22%20frameborder%3D%220%22%20allowfullscreen%3D%22allowfullscreen%22%20style%3D%22position%3A%20absolute%3B%20top%3A%200%3B%20left%3A%200%3B%20width%3A%20100%25%3B%20height%3A%20100%25%3B%22%20class%3D%22video-iframe%22%20your%3D%22%22%20video%3D%22%22%20title%3D%22%E2%80%9Dput%22%20here%3D%22%22%3E%3C%2FIFRAME%3E%3C%2FDIV%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-1965260089%22%20id%3D%22toc-hId-1965259004%22%20id%3D%22toc-hId-1965259004%22%20id%3D%22toc-hId-1965259004%22%20id%3D%22toc-hId-1965259004%22%3ETo%20learn%20more%3C%2FH2%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3EOnce%20the%20expedite%20profile%20is%20released%20in%20Microsoft%20Endpoint%20Manager%20admin%20center%2C%20see%20the%20online%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMicrosoft%20Intune%20documentation%3C%2FA%3E%20for%20more%20details%2C%20or%20watch%20the%20below%20video%20for%20further%20in-depth%20information%3A%3C%2FP%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CDIV%20style%3D%22position%3A%20relative%3B%20padding-bottom%3A%2056.25%25%3B%20padding-top%3A%2030px%3B%20height%3A%200%3B%20overflow%3A%20hidden%3B%20min-width%3A%20320px%3B%22%3E%3CIFRAME%20src%3D%22https%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fvideoplayer%2Fembed%2FRWyA8t%3Fautoplay%3Dfalse%22%20frameborder%3D%220%22%20allowfullscreen%3D%22allowfullscreen%22%20style%3D%22position%3A%20absolute%3B%20top%3A%200%3B%20left%3A%200%3B%20width%3A%20100%25%3B%20height%3A%20100%25%3B%22%20class%3D%22video-iframe%22%20your%3D%22%22%20video%3D%22%22%20title%3D%22%E2%80%9Dput%22%20here%3D%22%22%3E%3C%2FIFRAME%3E%3C%2FDIV%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-2177116%22%20slang%3D%22en-US%22%3E%3CP%3EExplore%20the%20benefits%20of%20expedited%20updates%20and%20the%20reports%20that%20will%20enable%20you%20to%20monitor%20progress.%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22expedite.PNG%22%20style%3D%22width%3A%20886px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F260331i5C8BE5A9E8375E2C%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22expedite.PNG%22%20alt%3D%22expedite.PNG%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2177116%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EDeployment%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EServicing%20and%20updates%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWindows%2010%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2364426%22%20slang%3D%22en-US%22%3ERe%3A%20Expedite%20security%20updates%20in%20Microsoft%20Endpoint%20Manager%20admin%20center%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2364426%22%20slang%3D%22en-US%22%3E%3CP%3EThis%20is%20a%20great%20new%20feature%20that%20will%20really%20help%20when%20a%20critical%20security%20update%20is%20released.%3C%2FP%3E%3CP%3EIt%20would%20be%20extremely%20beneficial%20to%20have%20a%20similar%20feature%20for%20removing%20updates.%3C%2FP%3E%3CP%3EA%20recent%20example%20would%20be%20the%20March%20updates%20that%20affected%20a%20lot%20of%20print%20drivers.%20With%20our%20onsite%20devices%20we%20could%20use%20WSUS%20to%20remove%20the%20dodgy%20update%2C%20but%20we%20could%20not%20do%20that%20with%20our%20Intune%20managed%20remote%20workers.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2379344%22%20slang%3D%22en-US%22%3ERe%3A%20Expedite%20security%20updates%20in%20Microsoft%20Endpoint%20Manager%20admin%20center%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2379344%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F437688%22%20target%3D%22_blank%22%3E%40David_Guyer%3C%2FA%3E%26nbsp%3Bthis%20would%20be%20also%20an%20awesome%20feature%20for%20Azure%20Update%20Management%20which%20is%20not%20WuFB%20%2F%20MS%20Endpoint%20admin%20center.%20At%20best%20it%20would%20be%20great%20if%20MS%20Endpoint%20admin%20center%20would%20be%20able%20to%20manage%20Windows%20Server.%20Currently%20many%20small%20businesses%20need%20to%20administer%202%20different%20things.%20In%20the%20past%20they%20had%20one%20tool%20called%20WSUS%20to%20manage%20server%20and%20clients%20OS.%20Can%20you%20elaborate%20this%20with%20the%20PGs%3F%3CBR%20%2F%3E%3CBR%20%2F%3EI%20also%20agree%20the%20idea%20of%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F117913%22%20target%3D%22_blank%22%3E%40Simon%20Ludlow%3C%2FA%3E%26nbsp%3Bis%20really%20nice.%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2178635%22%20slang%3D%22en-US%22%3ERe%3A%20Expedite%20security%20updates%20in%20Microsoft%20Endpoint%20Manager%20admin%20center%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2178635%22%20slang%3D%22en-US%22%3E%3CP%3EThis%20is%20very%20valuable%20especially%20when%20we%20are%20dealing%20with%20some%20sort%20of%200-days%20which%20impact%20our%20security%20or%20we%20are%20dealing%20with%20mass%20issue%20and%20we%20need%20to%20perform%20rapid%20deployment%20of%20updates%20and%20this%20is%20very%20handy.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Co-Authors
Version history
Last update:
‎May 14 2021 02:20 PM
Updated by: