3.3 Windows 11 Upgrades and Windows 365 Cloud PCs

Key Takeaways

  • Feature update policies in Intune specify the Windows version devices are eligible to install and keep that target version enforced until the policy changes or is removed.
  • Feature update policies do not downgrade devices that are already on a newer Windows release.
  • Update rings still matter because they control monthly quality update deferrals, restart behavior, deadlines, and active hours.
  • Windows 365 Cloud PCs are provisioned from user-group assignments, licensing, a provisioning policy, a network choice, and a gallery or custom image.
  • Changing a Windows 365 provisioning policy generally affects newly provisioned or reprovisioned Cloud PCs, not already provisioned Cloud PCs.
Last updated: June 2026

Windows 11 upgrade planning with Intune

For MD-102, Windows upgrade management is mostly about policy intent. Feature update policies select the Windows release you want devices to install or remain on. Update rings control ongoing quality update behavior such as deferrals, deadlines, restarts, and active hours. Knowing which of those two policy types answers a question is the single most-tested distinction in this objective.

NeedIntune policy or capabilityExam clue
Move eligible Windows 10 devices to Windows 11Feature update policy targeting a Windows 11 releaseUpgrade to a selected Windows 11 version
Keep Windows 11 devices on version 23H2 or 24H2Feature update policyStay on a release until the admin changes policy
Control monthly quality update cadenceUpdate ring for WindowsDeferrals, active hours, restart deadlines
Install a critical quality update faster than normal cadenceExpedite quality update policyZero-day or urgent security update
Validate device readinessReports, device inventory, compatibility pilotsPilot ring, staged rollout, blocker remediation

Feature update policies keep applying until changed or removed. They also do not downgrade a device. If a device already runs a newer Windows version than the target, the policy is not used to force it backward; the device simply stays where it is.

Because Windows 10 reached end of support on October 14, 2025, 2026 endpoint plans should treat Windows 11 upgrade readiness as an operational priority. Intune may still show enrolled Windows 10 devices, and some management features may still work, but ongoing quality and feature update support is no longer guaranteed for Windows 10. Organizations can purchase Extended Security Updates (ESU) for Windows 10 in some scenarios, but the exam expects you to treat Windows 11 migration as the strategic direction.

A practical Windows 11 deployment pattern

A safe upgrade plan usually starts with readiness and scope:

  1. Identify hardware, app, driver, VPN, and security-agent blockers, including TPM and CPU compatibility for Windows 11.
  2. Create pilot user and device groups for IT, early adopters, and critical departments.
  3. Use assignment filters where group membership is too broad, such as excluding unsupported models or including a specific OS version range.
  4. Assign a feature update policy to the pilot group and monitor installation status.
  5. Expand rings after help desk, app owners, and security teams confirm success.

If a question says the organization must control monthly quality update restart behavior, do not answer feature update policy by itself; that is an update ring. If the question says devices must remain on a specific Windows 11 release until the admin selects a later release, use a feature update policy.

Windows 365 Cloud PC deployment

Windows 365 provisions Cloud PCs from the Microsoft cloud and manages them through Intune. A provisioning policy is the central object. It tells Windows 365 which users get Cloud PCs and how those Cloud PCs should be created.

A Windows 365 provisioning policy includes:

  • Network - Microsoft-hosted network or Azure network connection, depending on join and networking requirements.
  • Image - Microsoft gallery image or custom image.
  • Configuration - language, region, optional device name template, and related settings.
  • Assignment - Microsoft Entra user security groups or Microsoft 365 Groups.
  • Licensing - users need the appropriate Windows 365 license before a Cloud PC is provisioned.

For Windows 365 Enterprise, if a user in an assigned group is not licensed, Windows 365 does not provision that user's Cloud PC. If a user is in scope for more than one provisioning policy for the same license type, the service uses the first assigned policy for that Cloud PC. These two licensing rules are common exam traps, so read assignment and license details carefully.

Policy changes after provisioning

A key exam trap is assuming every provisioning policy edit changes existing Cloud PCs. Many changes, such as image, network, region, or single sign-on configuration, affect newly provisioned or reprovisioned Cloud PCs. Existing provisioned Cloud PCs usually need a specific move, apply-current-configuration, or reprovision operation depending on the setting.

Reprovisioning is destructive to the Cloud PC because it deletes and recreates it from the current provisioning policy, discarding local data. Use it when a failed or misconfigured Cloud PC must be rebuilt, not as a routine policy refresh. Advise users to save work to OneDrive or another backed-up location before a reprovision.

Cloud PCs and configuration profiles

After provisioning, Cloud PCs are Intune-managed Windows devices. You can target device configuration, security, and app policies to Cloud PC device groups just like physical Windows endpoints. For user-experience settings that follow the person, use user-group assignment carefully so a setting does not also land on the user's physical device unexpectedly.

Do not confuse Windows 365 Cloud PCs with Azure Virtual Desktop multi-session hosts. A Cloud PC is a single-user dedicated machine. Windows 11 Enterprise multi-session is managed through a more constrained Intune path, mainly the Settings catalog with Enterprise multi-session applicability filtering. That profile behavior is covered in the next section.

Update rings versus feature update policies, restated

Because this distinction is so heavily tested, restate it clearly.

A feature update policy answers "which Windows release should these devices be on, and stay on, until I change it?" An update ring answers "how should monthly quality updates roll out — what deferral, what active hours, what restart deadline, and how strict is enforcement?" An expedite quality update policy answers "how do I push one urgent security update faster than the normal ring cadence?" If a question mixes a release-version requirement with a restart-cadence requirement, you may need both a feature update policy and an update ring; do not assume one policy satisfies both intents.

Monitoring and readiness reporting

Upgrade work is not finished when a policy is assigned. Intune surfaces update and feature-update reports, and Windows Update for Business reports can show which devices are on target, pending, or blocked. Use these to confirm that a pilot ring actually moved to the target release before expanding scope. For Windows 11 migrations specifically, hardware eligibility (TPM 2.0, supported CPU, Secure Boot) is a common blocker, so plan for an inventory and remediation pass before you expect a feature update policy to take effect across the fleet.

A feature update policy will not upgrade an ineligible device; it simply waits, and the device shows as not yet upgraded in reporting until the blocker is resolved.

Test Your Knowledge

An organization wants eligible devices to stay on Windows 11 version 23H2 until administrators deliberately approve a later release. Which Intune policy should be used?

A
B
C
D
Test Your Knowledge

A Windows 11 device is already running a newer release than the version targeted by a feature update policy. What should you expect?

A
B
C
D
Test Your Knowledge

A Windows 365 Enterprise provisioning policy is assigned to a Microsoft Entra user group. One user in the group does not have a Windows 365 license. What happens for that user?

A
B
C
D
Test Your Knowledge

An administrator changes the image in a Windows 365 Enterprise provisioning policy. What is the expected effect on Cloud PCs that are already provisioned to users?

A
B
C
D