3.3 Configuring & Monitoring Software Updates
Key Takeaways
- The Microsoft 365 admin center Software updates area surfaces Windows updates and Microsoft 365 Apps updates for enrolled devices; it is a monitoring and policy-light configuration surface, not a replacement for full Intune or Configuration Manager management
- Update rings govern when Windows feature and quality updates are offered to enrolled devices, controlling deferral periods and pausing; in the admin center they are surfaced as a high-level view, with full ring authoring in Intune (MD-102 scope)
- Microsoft 365 Apps update channels control cadence: Current Channel receives feature updates roughly monthly, Monthly Enterprise Channel receives a validated monthly build on a predictable schedule, and Semi-Annual Enterprise Channel receives feature updates twice per year (January and July)
- Semi-Annual Enterprise Channel is the recommended channel for organizations that need maximum predictability and validation time before feature updates reach users, with feature updates on a January/July cadence and Patch Tuesday quality updates
- Channel choice affects feature update cadence but not security update cadence — security and quality updates are delivered on the same Patch Tuesday schedule regardless of channel, though channel determines how far behind feature-wise a build is
Quick Answer: The Microsoft 365 admin center's Software updates area surfaces Windows update status for enrolled devices and Microsoft 365 Apps update configuration. Update rings control when Windows feature and quality updates are offered, while Microsoft 365 Apps update channels (Current, Monthly Enterprise, Semi-Annual Enterprise) control how often feature updates arrive. This view complements — it does not replace — Intune and Configuration Manager.
Microsoft 365 administrators are frequently asked to keep end-user devices current without becoming the full Intune administrator. The Software updates area of the Microsoft 365 admin center provides a single-pane monitoring and light-configuration surface for both Windows updates and Microsoft 365 Apps updates, drawing data from Intune-managed and co-managed devices.
Where to Find It
In the Microsoft 365 admin center, navigate to Health → Software updates (the navigation label may also appear under Reports → Software updates depending on tenant SKU and admin center version). The page presents two main pillars: Windows updates for enrolled devices, and Microsoft 365 Apps updates for the Office suite installed on user devices.
Windows Updates in the Admin Center
For Windows devices enrolled in Intune (or co-managed with Configuration Manager), the Software updates area shows:
- Windows updates summary — counts of devices that are up to date, need updates, or have failed updates.
- Devices needing updates — a list of devices missing quality or feature updates, with the update title and severity.
- Update compliance — an aggregate view of how compliant enrolled devices are with assigned update policies.
- Failed updates — devices where an update installation attempt has failed, with error codes that support further investigation in Intune.
This view is read-mostly. Authoring the actual update policies — defining which devices get which updates and when — is done in Intune under Devices → Windows → Update rings for Windows 10+. The admin center surfaces the result, so the M365 administrator can report on fleet health without leaving the M365 portal.
Update Rings Concept
An update ring is an Intune policy object that controls how and when Windows feature and quality updates are offered to a group of enrolled devices. Key settings on an update ring include:
- Feature update deferral — how many days after a feature update is released before it is offered (0–365 days).
- Quality update deferral — how many days after a quality update is released before it is offered (0–30 days).
- Pause feature / quality updates — a temporary hold while an issue is investigated. Feature and quality updates are paused independently, each for up to 35 days; when the 35 days expire the pause lifts automatically and the device scans again. Selecting Extend resets the pause period back to 35 days.
- Automatic update behavior — restart controls, active hours, deadline and grace period.
- Delivery optimization — peer-to-peer download mode to reduce internet bandwidth.
The admin center shows the rings assigned to enrolled devices at a high level; full ring authoring, assignment, and granular policy editing belong to Intune (covered in MD-102). MS-102 candidates should recognize the concept, the deferral/pause controls, and the fact that update rings apply to Windows 10/11 devices enrolled and managed by Intune.
Microsoft 365 Apps Updates
Microsoft 365 Apps (the Office suite: Word, Excel, PowerPoint, Outlook, and the rest) receives both feature updates (new capabilities) and quality/security updates (fixes). The cadence of feature updates is controlled by the update channel assigned to the device or user. The admin center lets the administrator view update status across the fleet and configure some org-wide update settings.
Update Channels
| Channel | Feature update cadence | Typical audience | Validation |
|---|---|---|---|
| Current Channel | Roughly monthly — new features as soon as they are ready | Insiders, pilot users, early adopters | Minimal pre-release validation; features ship when ready |
| Monthly Enterprise Channel | One validated build per month, released on a predictable schedule (second Tuesday) | Broad enterprise default | Microsoft validates the build for a month before release; predictable rollout |
| Semi-Annual Enterprise Channel | Twice per year — feature updates on the January and July Patch Tuesday schedule | Regulated, change-controlled environments | Maximum validation time; features mature for months before reaching this channel |
A fourth channel, Current Channel (Preview), gives early adopters a sneak peek of the next monthly build; it is not used for broad production fleets.
Channel Choice Trade-offs
- Current Channel delivers features fastest but with the least validation and the highest change-management overhead. Suitable for power users and IT pilots.
- Monthly Enterprise Channel is the recommended default for most enterprises — one predictable, Microsoft-validated build per month, released on Patch Tuesday.
- Semi-Annual Enterprise Channel is the right choice for regulated industries and organizations that need long validation windows and minimal feature churn. Feature updates land twice a year, giving IT months to test.
Security and Quality Updates
Regardless of channel, security and quality updates are delivered on the same Patch Tuesday (second Tuesday of the month) schedule. The channel controls how feature-rich a build is, not how quickly security patches arrive. This is a frequent exam point: switching a user from Current Channel to Semi-Annual Enterprise Channel delays new features but does not delay security fixes.
Configuring Microsoft 365 Apps Update Settings
Org-wide Microsoft 365 Apps update settings are configured under Settings → Org settings → Microsoft 365 installation options (and related software update policy settings). Available configuration includes:
- Default update channel for new Microsoft 365 Apps installations.
- Office update endpoint control — the source from which devices pull updates (CDN by default; a local on-premises distribution point can be configured for disconnected networks).
- Automatic updates enabled/disabled — whether installed Microsoft 365 Apps self-update.
- Update deadline and grace period — how long after an update is available before it is forced.
For per-device or per-group channel assignment, use the Office Deployment XML or Intune's Microsoft 365 Apps deployment profile. The admin center provides the org-wide default and the monitoring view; granular targeting belongs to Intune.
Viewing Update Status and Failures
The Software updates page surfaces:
- Microsoft 365 Apps update status — how many devices are on each channel, and how many are behind on updates.
- Failed Microsoft 365 Apps updates — devices where an update could not install, with the failure reason.
- Windows update failures — devices with failed Windows update installations, with the relevant error code.
For root-cause analysis on a specific failure, the administrator typically pivots to Intune or Configuration Manager, where the device's update log and policy assignment can be inspected. The admin center's value is the consolidated fleet view across both pillars.
How the Admin Center View Complements Intune and Configuration Manager
The MS-102 exam is careful to scope this area to what the admin center surfaces. Full endpoint management — authoring update rings, deploying feature updates, managing co-management, configuring Windows Update for Business policies at depth — is MD-102 (Endpoint Administrator) territory. The M365 Administrator's role is to:
- Monitor fleet update health in a single pane.
- Configure org-wide Microsoft 365 Apps update defaults.
- Recognize when to escalate to the Intune administrator for policy authoring or device-level remediation.
- Communicate update status to stakeholders using the consolidated view.
Understanding the boundary is itself testable: a question may ask which tool to use to author an update ring (Intune), versus which tool surfaces the consolidated update compliance view (Microsoft 365 admin center).
An organization uses Microsoft 365 Apps in a regulated industry that requires the longest possible validation window before new features reach users. Which update channel should they assign, and how often will feature updates arrive?
A user is moved from Current Channel to Semi-Annual Enterprise Channel. Which statement about the effect on this user's Microsoft 365 Apps updates is correct?
An M365 administrator needs to author a policy that defers Windows feature updates by 90 days for a pilot group of Windows 11 devices. Where should this policy be created, and what is the admin center's role?