6.3 Update Rings, Feature Updates, Platform Updates, and Delivery Optimization
Key Takeaways
- Update rings manage ongoing Windows Update behavior such as deferrals, restart experience, deadlines, active hours, user notifications, and staged rollout groups.
- Feature update policies target or hold a specific Windows release and are the preferred answer when the scenario requires version control rather than general update timing.
- Expedited quality update policies are for urgent supported Windows quality or security updates and do not replace the normal monthly servicing strategy.
- Apple update management uses Intune update policies and declarative device management concepts, while Android Enterprise updates use device restriction profiles or FOTA for supported OEMs.
- Delivery Optimization reduces bandwidth impact through peer, cache, and bandwidth settings; update monitoring verifies deployment status, failures, and whether devices actually reached the intended version.
The update objective decides the policy
The MD-102 Protect devices domain includes update planning, update rings, update policies for iOS/iPadOS and macOS, Android updates through configuration profiles or firmware-over-the-air (FOTA) deployments, Delivery Optimization, and update monitoring. Do not collapse every update requirement into update rings; the exam separates timing, version targeting, urgency, platform, bandwidth, and reporting into distinct controls.
A ring controls the regular Windows Update experience. A feature update policy controls which Windows feature release is offered or held. An expedited quality update policy accelerates an urgent supported update. Platform-specific policies handle the Apple and Android update models. Delivery Optimization changes how content is downloaded; it is not a compliance or version-targeting policy.
Windows update decision table
| Requirement | Best control | Why |
|---|---|---|
| Create pilot, broad, and production stages for regular monthly Windows servicing | Update rings | Rings control deferrals, restart settings, deadlines, active hours, and user experience by group |
| Keep devices on a specific Windows release until app validation is complete | Feature updates for Windows 10 and later | Feature update policies target a version and hold it until changed or removed |
| Move devices to a newer Windows feature version in a managed rollout | Feature update policy with rollout planning | The policy controls the target version; rings still affect restart and client experience |
| Deploy a critical security update faster than normal deferrals allow | Expedited quality update policy | Expedite policies temporarily bypass normal timing for a selected supported update |
| Control download source, peer caching, cache size, or bandwidth impact | Delivery Optimization profile or settings catalog | Delivery Optimization optimizes content delivery, not update approval or version |
| Verify offer, install, failure, and device status | Windows update reports | Reporting shows where devices are stuck and which events or failures need remediation |
Rings versus feature update policies
This pairing is heavily tested. Update rings answer "when and how do monthly updates and restarts happen for this group?" with deferral days, deadlines, grace periods, active hours, and restart notifications. Feature update policies answer "which Windows feature version should this group be on?" by targeting a specific release (for example, holding devices on Windows 11 24H2) and enforcing it. A scenario that says "hold devices at a version until an app is validated" is a feature update answer even though rings are configured too; rings alone cannot pin a feature version.
Platform update controls
| Platform | Intune update approach | Exam cue |
|---|---|---|
| Windows | Update rings, feature update policies, quality update policies, driver update policies, expedited quality updates | Deferrals, deadlines, restart behavior, target Windows version, urgent patches |
| iOS/iPadOS and macOS | Apple software update policies using declarative device management where supported | Target a specific OS version, enforce the latest version, set deadlines, reduce disruption |
| Android Enterprise corporate devices | Device restriction profiles for OTA behavior, or FOTA deployments for supported manufacturers such as Samsung or Zebra | Corporate-owned Android update scheduling, freeze periods, OEM firmware control |
| Mixed fleet | Separate platform-specific assignments and reports | A Windows update ring does not manage iOS, macOS, or Android update behavior |
The most testable platform rule: a Windows update ring manages only Windows. iOS/iPadOS, macOS, and Android each require their own Intune update controls, so any answer that uses a Windows ring to update Apple or Android devices is wrong.
Delivery Optimization in plain terms
Delivery Optimization helps Windows devices get Microsoft content more efficiently. It can use download modes (such as HTTP with peering, group peering, or Microsoft Connected Cache), peer selection, bandwidth limits, and cache size rules. On MD-102, choose it when the organization wants to reduce WAN usage or improve download efficiency for updates and apps without changing the update schedule. Do not choose it to force a feature version, mark a device compliant, or onboard Defender for Endpoint.
Monitoring and remediation
Update management is incomplete without reporting. For Windows, review update ring reports, feature update reports, quality update reports, driver update reports, and device-level failures. For Apple, remember that a policy reporting success can mean the configuration arrived, not that the OS version already changed; monitor software update reports and the actual device OS version. For Android, verify the device type, OEM support, FOTA deployment status, and device restriction behavior.
When troubleshooting an update scenario, ask four questions:
- Is the device eligible for the update policy and platform?
- Is the device receiving the intended policy assignment?
- Is another policy delaying or conflicting with the update, such as ring deferrals affecting feature-update timing?
- Does reporting show offer, download, install, restart, or failure state?
High-value exam contrasts
Use update rings for ongoing servicing behavior. Use feature update policies to target or hold a Windows version. Use expedited quality updates for urgent, time-bound patch response. Use Delivery Optimization for content-delivery efficiency. Use platform-specific Apple and Android update controls for non-Windows devices.
Update ring settings worth knowing
Within an update ring, the settings most likely to appear in a scenario are the quality update deferral (0 to 30 days), the feature update deferral (0 to 365 days, though feature targeting is better handled by a feature update policy), the deadline for installs and restarts with an associated grace period, active hours that protect the user from restarts during the workday, and user experience controls such as whether users can pause updates or access Windows Update settings.
A scenario that says "updates must install within X days but never restart during business hours" maps to a deadline plus active hours, both configured in the ring.
Be deliberate about the relationship between rings and feature update policies. When a feature update policy is assigned to pin a version, the ring's feature update deferral should generally be left at 0 so the two controls do not fight; the feature update policy becomes the authority on which version is offered. This is a frequent source of "the device will not move to the new version" troubleshooting and a strong distractor on the exam.
Driver and quality update specifics
Intune also offers Windows driver update policies, which let you approve or decline specific driver and firmware updates (manual approval) or allow automatic approval, giving control over a category that historically caused fleet instability. Quality update policies (distinct from the ring's deferrals) let you target a specific monthly quality update, and expedited quality updates push an urgent security fix outside normal deferral timing, optionally forcing a restart within a set number of hours.
If a stem describes a zero-day that must be patched across the fleet today, expedited quality updates are the answer, not editing every ring's deferral. Keep these Windows-specific tools mentally separated from the Apple declarative update policies and the Android FOTA / device-restriction approach so a mixed-platform question does not push you toward a Windows-only control.
A company must keep Windows devices on Windows 11 version 24H2 until a finance application is validated on a newer release. Which Intune policy is the best match?
Which policy choices correctly match the update requirement? Select all that apply.
Select all that apply
A branch office has slow WAN links, and Windows update downloads are saturating bandwidth. The organization still wants the same update schedule but more efficient content delivery. Which control should be reviewed?