wufb
28 TopicsForce Update scan with WUFB managed by Intune
Hi, is there a way to force a WUFB scan on a machine or we have to wait every 22h for the scan to be done? Also, when in the Windows 10 UI, you click on check for Updates, does it check what you have set in your WUFB policies (feature updates included) or will it ignore them and behave like a regular home pc and install everything that is available? Thks9.8KViews0likes6CommentsQuality update uninstall with WUFB and Intune
Hi, I wanted to know what happens when we click on 'Uninstall' for quality updates with WUFB managed via Intune. When I go in the ring summary I can see that Quality updates say : Uninstalled and Paused (Days remaining: 35) but the updates are not getting uninstalled on the devices assigned to this ring. How long should it take for the uninstall to start and where could I look to see why it's not? Thks in advance and don't hesitate if you have any questions.4KViews0likes2CommentsSCCM to WufB
Hello We are co-managed and are in the process of testing out WUfB workloads. We have a leftover GPO that is setting the "Configure Automatic Updates" policy to Disabled and few others. Configure Automatic Updates - Set as Disabled from Domain GPO Do not allow update deferral policies to cause scans against Windows Update - Set as Disabled from Local GPO (from SCCM) Do not connect to any Windows Update Internet locations - Set as Enabled from Domain GPO Specify intranet Microsoft update service location - Set as Enabled from Local GPO (from SCCM) To manage from Intune we are planning to do the following 1. Add the device to Co-management workloads 2. Modify the following GPO's Configure Automatic Updates - Delete the Registry Entry and set as Not Configured in GPO 3. Create a new profile under "Windows 10 update rings" in Intune with the required settings and assign to the devices But still devices does not scan. Will that help us to move towards to WuFB or do we need to do anything else ?3.7KViews0likes3CommentsWindows 10 Report Feature Update failures
Hi I work in a co-managed enviroment where we have switched WUFB workload to Intune. The feature updates are working well but the reporting does not. We have 70% errors in the Windows 10 and later feature update report, all failures are: "Device Registration Invalid Azure AD Device Id". Now, the devices are Hybrid-AzureAD Joined and as mentioned Co-Managed with WUFB as Intune-managed workload. For what it's worth, I can see the Azure Device ID present in AzureAD. Anyone have any suggestions regarding how to solve this so we get that fancy piechart-report working? ๐3.6KViews0likes1CommentWUfB - Update Baseline / Best Practise
We use WUfb about more than one year. Now we want to work with "Deadline" But there are a lot (?) of unknow unsure... We found this "https://www.microsoft.com/en-us/download/details.aspx?id=101056" with a lot of settings (Update from: 16.09.2020) and the article from AriaUpdated --> here What we want: - Do not Auto-restart during the Work hours (08:00 - 17:00) - a lot of User Notification (annoy the user to restart his device) - do not Auto-restart without inform the user in the attachmend is our Policy (censored) What is the "best practise" for our use case? Thank for your Help! ๐Solved2.9KViews0likes7CommentsWUFB Deadlines
Hi, I wanted to know the real definition/behavior for quality update deadlines. Let's say we set it to 2days. For already WUFB managed, I understand it means the devices will reboot two days after the end of the deferal But lets say I add an existing sccm managed device into co-management for WUFB, 10days after patch Tuesday, if there's no grace period set, will the device start to see the update right away, since it's past the 2 days deadline or will it still wait for the 2 days (meaning the deadline starts when the device sees that it has an update to install? Thank you in advance and don't hesitate if you have any questions.2.5KViews0likes3CommentsWufB Delivery Optimization Report Broken
Since some days, we have a problem with our Delivery-Optimization-Report in WufB-Workbook. We only see the following error in all Sections Query could not be parsed at 'datetime()' on line [2,21] Token: 'datetime()' Line: 2 Postion: 21 Is this a global Issue? Is anybode else faceing this problem. The Report used to work fine for several Weeks - no changes made.Solved2.1KViews0likes7CommentsBehind the scenes: access and region control in Windows Update for Business reports
Interested in using Windows Update for Business reports for richer access and region control? As we've announced on the Windows IT Pro Blog today, you now have more power and flexibility to route data and to control access to your data with Windows Update for Business reports, as well as to host it in an expanded set of regions. While you can find out how in the blog article linked below, let's get behind the scenes of the new capability: The architecture Pricing structure A few current limitations Additional information The architecture When you run the Ansible solution to control access and region, your automated script deploys the following resources to your tenant. This solution automatically creates the following resources. Azure resources: Azure Function triggered on an interval to perform periodic data export Log Analytics resources: Log Analytics workspace for each scope Azure Monitor resources: Data collection endpoint for ingesting data Data collection rule for each scoped workspace to direct data routing You can easily manage these resources through the Azure Portal. The diagram below shows the key workflows, resources, and interactions for the Contoso/Fabrikam deployment example. If you're an Azure administrator, you may find it helpful for understanding the created resources and how data is routed throughout the solution. Pricing structure Since you'll be routing data for Azure AD device groups to different Log Analytics workspaces, let's see if anything changes in your billing based on your existing infrastructure. Data is stored in Log Analytics workspaces with the same schema as your already existing Windows Update for Business reports workspace, and so billing remains the sameโwhich is to say there is no data charge at the default 30-day retention period. See Log Analytics pricing tiers for more information. The Azure Function that copies data to scoped workspaces will incur standard Azure Function compute and consumption costs, and this is dependent upon the scale of your scopes and devices. You can use the calculator to estimate costs after running a test with your lab configuration to determine how many scopes and devices are processed over what time frame. A few limitations of the Ansible solution for access control Since this is a preview of the Ansible solutions, you might encounter a few limitations with access control capabilities: All scoped workspaces in the tenant are shown in the drop-down menu. We'll be filtering that list to just those each user has access to in a future update. Aggregated delivery optimization status is not computed. Aggregated status is tenant-wide in the primary workspace. Therefore, scoped workspaces would need to compute the aggregate for their device set separately. The Azure Function doesn't yet perform that process. No support for nested Azure AD groups. Only direct group members are considered at present. Nested support could be added by modifying the Azure Function. The solution assumes a single subscription and target resource group. This may or may not be relevant for your tenant. Tenants that need greater control can extend the solution by modifying the Ansible project. Additional information Not sure how easy it is for you to implement our new access control solution? You won't need anything other than your familiar Azure Portal and general understanding of resource management and Azure security fundamentals. Just follow these 7 easy steps to route the tenant's primary workspace into separate secured workspaces for each access control scope: Define scopes. Create Azure Active Directory groups. Group resources and restrict tag access. Download the Ansible solution. Configure your deployment. Deploy the Ansible solution to Azure. Use the Ansible solution. Find precise guidance and answers to your questions in Windows Update for Business reports: access and region control. Get in on the conversation This space is excellent for discussion with your peers and with our team members, so feel free to leave a comment below! If you have any feedback or questions regarding the Ansible solution on GitHub, please feel free to open project issues for support or reach out through our other Windows Update for Business reports support options.2KViews0likes3CommentsWSUS plugin in WAC
Are there any plans to bring the WSUS console into WAC as a plugin, reflecting most of the features, including the ability to import updates? Most of the actions in the WSUS console should be underlying PowerShell commands, which would be the qualifying thing for this task, imho. There are still a lot of customers that rely on WSUS and do not leverage ConfigMgr (due overhead, licensing, TCO) or WuFB (cloud use restriction policies), missing ability of WuFB of managing Windows Server. I am not aware if WuFB can now also manage Windows Server 2012 and newer and gather the update status in a dashboard, as it does for Windows 10. If this is a limitation it should be considered to offer a single pane for free* of modern management as a whole pendant to WSUS. *eventually charging log analytics workspace1.9KViews0likes1CommentDevices don't show up in Update Compliance
Hi, where can we start the troubleshooting if I don't see any devices showing up in my Update Compliance workspace. I've ran the deployment script after editing the Commercial ID, and the devices don't show up. https://docs.microsoft.com/en-us/windows/deployment/update/update-compliance-configuration-script#broad-deployment I've also tried with the GPO settings, like explained here: https://docs.microsoft.com/en-us/windows/deployment/update/update-compliance-configuration-manual#group-policies but nothing is showing up. Thank you in advance and don't hesitate if you have any questions.1.8KViews0likes5Comments