WU for Shutdown devices

%3CLINGO-SUB%20id%3D%22lingo-sub-2470608%22%20slang%3D%22en-US%22%3EWU%20for%20Shutdown%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2470608%22%20slang%3D%22en-US%22%3E%3CP%3ENeed%20help%20in%20understanding%20the%20best%20way%20to%20handle%20the%20device%20update%20through%20Intune%20for%20a%20specific%20scenario.%20We%20have%20few%20users%20who%20shutdown%20the%20devices%20everyday%20around%206%20PM%20and%20starts%20again%20next%20day%20morning%209%20AM.%20Our%20Update%20Rings%20in%20Intune%20are%20set%20with%20the%20following%20profile%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Vinod7_0-1624381740776.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F290530iA4FEB9134972BDC6%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22Vinod7_0-1624381740776.png%22%20alt%3D%22Vinod7_0-1624381740776.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20how%20can%20we%20make%20sure%20that%20these%20devices%20gets%20update.%20Also%20we%20cannot%20find%20the%20users%20who%20are%20doing%20the%20regular%20shutdown%20as%20well.%20SCCM%20has%20the%20option%20to%20scan%20the%20device%20next%20day%20morning%20if%20it%20misses%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2473203%22%20slang%3D%22en-US%22%3ERe%3A%20WU%20for%20Shutdown%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2473203%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F180125%22%20target%3D%22_blank%22%3E%40Vinod7%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20best%20way%20to%20ensure%20devices%20update%20is%20to%20Enable%20the%20%22Use%20deadline%20settings%22%20setting%2C%20and%20set%20the%20deadline%20and%20grace%20periods.%26nbsp%3B%20We%20recommend%203%20day%20deadline%20and%202%20day%20grace%20period%20for%20quality%20updates%2C%20for%20example.%26nbsp%3B%20%26nbsp%3BThis%20will%20ensure%20the%20devices%20are%20restarted%20to%20complete%20the%20update%2C%20even%20if%20devices%20are%20shut%20down%20overnight.%26nbsp%3B%20This%20does%20mean%20the%20restart%20will%20likely%20happen%20for%20those%20users%20during%20the%20business%20day%20when%20the%20deadline%20and%20grace%20period%20expire%2C%20but%20for%20those%20users%20who%20shut%20down%20the%20devices%20during%20the%20working%20day%20the%20restarts%20have%20to%20happen%20during%20the%20day.%26nbsp%3B%20One%20of%20the%20great%20things%20about%20the%20deadline%20is%20that%20once%20the%20device%20reaches%20restart%20required%2C%20the%20users%20get%20notifications%20that%20the%20restart%20is%20required%20and%20they%20get%20the%20opportunity%20to%20restart%20right%20away%2C%20or%20to%20schedule%20a%20restart.%26nbsp%3B%20So%20those%20users%20who%20are%20automatically%20restarted%20during%20the%20day%2C%20should%20have%20received%20ample%20notification%2C%20depending%20on%20how%20many%20days%20you%20provide%20them%20with%20that%20setting.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYou%20may%20also%20try%20to%20shorten%20the%20default%20active%2Fmaintenance%20hours%20so%20that%20the%20system%20is%20enabled%20to%20try%20to%20restart%20outside%20of%20those%20hours%20if%20the%20device%20is%20not%20in%20use.%26nbsp%3B%20In%20fact%2C%20our%20recommendation%20is%20to%20set%20the%20%22Automatic%20update%20behavior%22%20setting%20to%20%22reset%20to%20defaults%22%20so%20that%20the%20end%20user%20can%20control%20active%20hours%20and%20enabling%20the%20smart%20busy%20checks%20and%20intelligent%20active%20hours%20features...%20which%20also%20work%20better%20for%20users%20who%20leave%20devices%20on%20overnight.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHope%20this%20helps%2C%3C%2FP%3E%0A%3CP%3E-David%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2508621%22%20slang%3D%22en-US%22%3ERe%3A%20WU%20for%20Shutdown%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2508621%22%20slang%3D%22en-US%22%3EHi%20David%20-%20These%20is%20very%20good%20explanation%20and%20much%20useful%20to%20understand%20how%20to%20configure%20the%20settings.%20So%20for%20the%20active%2Fmaintenance%20hours%20which%20we%20have%20set%20to%206%20AM%20to%2010%20PM%2C%20does%20it%20mean%20that%20the%20updates%20will%20not%20be%20installed%20during%20that%20time%20or%20just%20restart%20will%20not%20happen%20%3F%20We%20have%20like%20100%2B%20devices%20where%20they%20are%20not%20updating%20at%20all.%20The%20only%20way%20is%20to%20run%20the%20PSWindowsUpdate%20powershell%20module%20remotely%20to%20start%20the%20install.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2511545%22%20slang%3D%22en-US%22%3ERe%3A%20WU%20for%20Shutdown%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2511545%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F180125%22%20target%3D%22_blank%22%3E%40Vinod7%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EActive%20Hours%20affects%20the%20automatic%20restart.%26nbsp%3B%20Scan%2C%20download%2C%20and%20install%20can%20still%20happen%20during%20active%20hours%20since%20they%20are%20background%20tasks.%26nbsp%3B%20The%20system%20detect%20for%20idle%20time%20and%20other%20techniques%20to%20minimize%20user%20productivity%20impact%20during%20active%20hours.%26nbsp%3B%20More%20info%20about%20active%20hours%20is%20here%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fdeployment%2Fupdate%2Fwaas-restart%23configure-active-hours%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EManage%20device%20restarts%20after%20updates%20(Windows%2010)%20-%20Windows%20Deployment%20%7C%20Microsoft%20Docs%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThere%20may%20be%20other%20reasons%20devices%20are%20not%20scanning%20or%20updating.%26nbsp%3B%20For%20example%2C%20if%20these%20devices%20were%20previously%20managed%20by%20using%20Group%20Policies%2C%20and%20the%20policy%20is%20configured%20to%20not%20auto%20update%2C%20then%20even%20though%20you%20are%20managing%20using%20Intune%2C%20the%20Group%20Policies%20will%20still%20be%20in%20effect.%26nbsp%3B%20You%20would%20need%20to%20disable%20the%20Group%20Policies%20in%20this%20case%20to%20get%20back%20to%20normal.%26nbsp%3B%20Another%20cause%20could%20be%20the%20required%20services%20being%20disabled%20from%20running.%26nbsp%3B%20%26nbsp%3BI%20found%20this%20troubleshooting%20guide%20that%20covered%20a%20number%20of%20the%20potential%20issues%2C%20it%20would%20be%20a%20great%20place%20to%20start%3A%26nbsp%3B%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fdeployment%2Fupdate%2Fwindows-update-troubleshooting%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EWindows%20Update%20troubleshooting%20-%20Windows%20Deployment%20%7C%20Microsoft%20Docs%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHope%20this%20helps%2C%3C%2FP%3E%0A%3CP%3E-David%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

Need help in understanding the best way to handle the device update through Intune for a specific scenario. We have few users who shutdown the devices everyday around 6 PM and starts again next day morning 9 AM. Our Update Rings in Intune are set with the following profile

Vinod7_0-1624381740776.png

 

So how can we make sure that these devices gets update. Also we cannot find the users who are doing the regular shutdown as well. SCCM has the option to scan the device next day morning if it misses

3 Replies

@Vinod7 ,

 

The best way to ensure devices update is to Enable the "Use deadline settings" setting, and set the deadline and grace periods.  We recommend 3 day deadline and 2 day grace period for quality updates, for example.   This will ensure the devices are restarted to complete the update, even if devices are shut down overnight.  This does mean the restart will likely happen for those users during the business day when the deadline and grace period expire, but for those users who shut down the devices during the working day the restarts have to happen during the day.  One of the great things about the deadline is that once the device reaches restart required, the users get notifications that the restart is required and they get the opportunity to restart right away, or to schedule a restart.  So those users who are automatically restarted during the day, should have received ample notification, depending on how many days you provide them with that setting.

 

You may also try to shorten the default active/maintenance hours so that the system is enabled to try to restart outside of those hours if the device is not in use.  In fact, our recommendation is to set the "Automatic update behavior" setting to "reset to defaults" so that the end user can control active hours and enabling the smart busy checks and intelligent active hours features... which also work better for users who leave devices on overnight.

 

Hope this helps,

-David

 

Hi David - These is very good explanation and much useful to understand how to configure the settings. So for the active/maintenance hours which we have set to 6 AM to 10 PM, does it mean that the updates will not be installed during that time or just restart will not happen ? We have like 100+ devices where they are not updating at all. The only way is to run the PSWindowsUpdate powershell module remotely to start the install.

@Vinod7 

 

Active Hours affects the automatic restart.  Scan, download, and install can still happen during active hours since they are background tasks.  The system detect for idle time and other techniques to minimize user productivity impact during active hours.  More info about active hours is here: Manage device restarts after updates (Windows 10) - Windows Deployment | Microsoft Docs

 

There may be other reasons devices are not scanning or updating.  For example, if these devices were previously managed by using Group Policies, and the policy is configured to not auto update, then even though you are managing using Intune, the Group Policies will still be in effect.  You would need to disable the Group Policies in this case to get back to normal.  Another cause could be the required services being disabled from running.   I found this troubleshooting guide that covered a number of the potential issues, it would be a great place to start:  Windows Update troubleshooting - Windows Deployment | Microsoft Docs

 

Hope this helps,

-David