Microsoft MD-102: Windows Lifecycle and Update Management — Study Guide

Part of the Microsoft Endpoint Administrator Associate MD-102 — Study Guide. Practice with verified answers in the Microsoft exam hub, or take timed practice tests on ExamRoll.io.

Overview

Windows lifecycle and update management in Microsoft Endpoint Manager (Intune) centers on Windows Update for Business (WUfB), the Windows Update for Business deployment service, and optional automation with Windows Autopatch. The goal is predictable, ring-based rollouts of quality and feature updates with minimal disruption, while maintaining real-time visibility and control. In Intune, you configure update rings, feature and driver update policies, and expedited quality updates. Compliance and readiness insights come from Windows Update for Business reports in Azure Monitor and Endpoint analytics. For moving to Windows 11 and recovering devices, use the correct upgrade or reset method based on business intent.

Windows Update for Business rings, feature targeting, and drivers

Update rings define the baseline experience for offering and installing updates. In Intune, create a Windows 10 and later update ring and assign it to Azure AD groups representing your deployment rings (for example: Pilot, Early, Broad). Configure:

Feature update policies target and hold devices on a specific Windows version, independently of ring deferrals. In Intune, use Feature updates for Windows 10 and later to select a product (Windows 10 or 11) and target version (for example, Windows 11, version 23H2). The policy uses the Windows Update for Business deployment service to pin the device to that version until you change policy or the version reaches end of service. Safeguard holds—temporary blocks Microsoft places to protect devices with known compatibility issues—apply by default. Only disable safeguards for feature updates if you have validated the issue does not affect your environment; bypassing safeguards forces the offer on next scan and can introduce risk.

Driver update management is best handled with the Windows driver update management policies in Intune. At scale, set Allow driver updates = No in your update rings for broad rings, and use the driver update management workflow to:

Expedited updates and Windows Autopatch automation

Expedited quality updates let you deploy critical security fixes outside normal deferral windows. In Intune, create an Expedite quality updates policy to deliver the latest security update (or a specific KB when supported) with an aggressive installation deadline and short restart grace period measured in hours or a small number of days. Expedite policies override deferrals and pauses. Requirements include devices managed by Intune, receiving updates directly from Windows Update (not WSUS), and having Windows Update Health Tools present. Expedite applies to quality (security) updates, not feature updates, and is intended for urgent remediation of active threats or zero-day vulnerabilities.

Windows Autopatch provides end-to-end automation for Windows updates, Microsoft 365 Apps for enterprise, Edge, and optionally drivers/firmware, using service-driven rings and policy orchestration. After onboarding eligible devices (Windows Enterprise E3/E5 or Microsoft 365 E3/E5; Intune MDM; Azure AD join or hybrid Azure AD join), Autopatch assigns devices to service rings—Test, First, Fast, Broad—by default proportions and manages:

Compliance reporting, Windows 11 readiness, and upgrade/reset paths

Windows Update for Business reports in Azure Monitor replace the legacy Update Compliance solution and provide near-real-time insights using Azure Monitor workbooks and Kusto queries. To enable:

  1. Create a Log Analytics workspace in Azure and the Windows Update for Business reports resource, linking it to the workspace.
  2. In Intune, deploy Windows Health Monitoring profiles to enable Windows updates event data, and set diagnostic data to Required (the minimum) so devices can send the needed telemetry.
  3. Assign the connection profile so Azure AD–joined devices authenticate to the reporting pipeline. You can then monitor update offering/installation states, safeguard hold reasons, feature and quality update compliance, expedite progress, and deployment health by ring or device group, and build alerts using Azure Monitor.

Assess Windows 11 readiness by validating hardware and compatibility. Minimum requirements include a compatible 64-bit CPU (for example, Intel 8th Gen/AMD Zen 2 or newer on supported lists), 4 GB RAM, 64 GB storage, UEFI with Secure Boot, TPM 2.0, DirectX 12–capable graphics with WDDM 2.0, and appropriate display/resolution. Use:

Choose the correct OS transition method based on the outcome you need:

Practical Problem Scenario

Adobe must move 45,000 Windows endpoints worldwide to a predictable monthly patch rhythm, pilot Windows 11 adoption, and reduce driver-related regressions that previously caused helpdesk spikes after Patch Tuesday.

  1. Define Azure AD device groups for rings: Pilot (2%), Early (8%), Broad (90%). Why: Clear scoping enables progressive exposure and targeted pauses without reshaping assignments each cycle.
  2. Create Intune Windows Update rings: Pilot with 0-day deferrals, 3-day quality deadlines, 1-day grace; Early with 7-day quality deferral, 7-day deadline, 2-day grace; Broad with 14-day quality deferral, 7-day deadline, 2-day grace. Set Allow driver updates = No for Early/Broad. Why: Tight Pilot accelerates signal; staged deferrals reduce blast radius; disabling drivers in larger rings minimizes hardware regressions.
  3. Implement Feature updates for Windows 10 and later to target Windows 11, version 23H2 for Pilot only; keep Early/Broad on their current versions. Respect safeguards. Why: Locks devices to a tested feature release, aligns with ring validation, and avoids accidental upgrades via rings alone.
  4. Enable Windows driver update management. Approve vendor-recommended drivers to Pilot monthly; promote to Early/Broad after one week of clean telemetry. Why: Central approval control decouples drivers from quality updates and provides rollback leverage.
  5. Configure Windows Update for Business reports with a dedicated Log Analytics workspace and Windows Health Monitoring profiles. Build workbooks and alerts by ring for install success, safeguard holds, and rollback triggers. Why: Azure Monitor offers live compliance views and alerting for issues like install failures crossing a threshold.
  6. Use Endpoint analytics Windows 11 readiness to identify CPU/TPM/Secure Boot blockers and remediate via firmware updates or replacement plans. Why: At-scale readiness inventory prevents failed upgrades and informs hardware refresh.
  7. Onboard eligible devices to Windows Autopatch for ongoing automation of Windows quality updates and Microsoft 365 Apps releases, keeping Pilot devices out of Autopatch initially to retain tighter experimental control. Why: Autopatch reduces operational overhead while preserving a curated pilot lane for change control.
  8. Prepare an Expedite quality updates policy with a 2-day deadline and 8-hour restart grace for zero-day scenarios; test on Pilot now. Why: Prevalidated expedite settings enable rapid, safe response to urgent security threats without reconfiguring rings during an incident.
  9. Establish recovery playbooks: use Autopilot Reset for re-provisioning failed devices with ESP enforcement; reserve Fresh Start for OEM de-bloat and remediation on select models. Why: Correct reset paths speed recovery and ensure required apps/policies reapply before user access.

This design blends service-driven automation (Autopatch) with Intune policy control and Azure Monitor insights to deliver safe, observable, and rapid Windows servicing at enterprise scale.


Co-management and Hybrid Environments · All domains · Remote Management and Monitoring

Practice these questions → · Timed practice on ExamRoll.io →

Pass the whole exam — not just this question

You found this answer. Get every verified question and explanation in one place, and save hours of prep. Free to start.

Pass your exam →

Browse Microsoft →

Related guides

All-in-one access

One subscription. Every exam.

Every plan unlocks unlimited answer search, practice tests, AI explanations, and the full resource library — in 20+ languages.

Monthly
24.87
Just €0.83/day
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

Best value
12 months
179.87
Just €0.49/daySave 40%
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

✓ Free plan included · ✓ Cancel anytime · ✓ All plans unlock the full product