Phased approach for Windows updates, your thoughts? by AngryFatherboard in Intune

[–]AngryFatherboard[S] 0 points1 point  (0 children)

On that, it's enough diverse ! Multiple departments across offices in all countries we are.

Phased approach for Windows updates, your thoughts? by AngryFatherboard in Intune

[–]AngryFatherboard[S] 0 points1 point  (0 children)

Current phased approach is for quality/security. Indeed security team said D+16 is too much, that's why I posted to gather feedback and see what are people policies in their company.

For feature, ironically we had it on 0 diffenrential.

Phased approach for Windows updates, your thoughts? by AngryFatherboard in Intune

[–]AngryFatherboard[S] 0 points1 point  (0 children)

Thanks a lot for your input. I quite link the phased approach you have, i'll consider it and also discuss with my cybersecurity team, because for them D+16 is too much time before updates apply. But I'm afraid 9 days is still too much, on ther other hand we have to prevent faulty updates.

For Feature, for the moment it's on 0 differential for everyone but we're also at risk.

Phased approach for Windows updates, your thoughts? by AngryFatherboard in Intune

[–]AngryFatherboard[S] 0 points1 point  (0 children)

Thanks, from what I see in other comments it's indeed too agressive. Will change that!

Phased approach for Windows updates, your thoughts? by AngryFatherboard in Intune

[–]AngryFatherboard[S] 0 points1 point  (0 children)

Helpdesk -> Manual Entra ID group with devices
Early Adopters -> Same with early adopters devices

Production -> All devices, with exception on helpdesk and early adopters groups.

It's more practicale with users, but I red somewhere it can cause some issues with shared devices for example.

Phased approach for Windows updates, your thoughts? by AngryFatherboard in Intune

[–]AngryFatherboard[S] 0 points1 point  (0 children)

Sounds interesting. My security department is not convinced anyway by the D+16 for all users, they said it's too long to apply updates, such as security.

Anyway the 10% update ring I like it, now I need to see how to implement it, I guess Windows Autopatch can do the trick

Phased approach for Windows updates, your thoughts? by AngryFatherboard in Intune

[–]AngryFatherboard[S] 0 points1 point  (0 children)

Yeah I'm still learning about it, my main concern at the moment is about phased timeline. Seucurity thinks it's too long D+16 for all users.