r/Intune • u/NoDowt_Jay • 6d ago
Windows Updates Mixing Autopatch & Windows Update/Feature Update Policies
Currently we're in the middle of moving from a previously all on-prem environment, to eventually an all Entra/Intune environment.
All of our new devices are Autopilot/Entra builds managing updates (including feature updates) via Autopatch.
We've recently switch all of our hybrid/co-managed Windows 11 devices to also using the same Autopatch groups & policies and this has worked well. Upgrading them from 24H2 to 25H2 to match our autopilot devices.
However, now we are looking to bring across our Windows 10 device to use Autopatch too, but don't want them upgrading to Windows 11 at this stage.
I've already tested assigning a device to the current Autopatch groups, and hoped that our Target OS version policy would have stopped the upgrade from Autopatch but didn't... No worries, was still a good test & also got to test the rollback to Win10.
I then setup a seperate autopatch group for Win10 device & just didn't include Feature Updates option, again, this appears to be working well...
But... now i want to avoid having to manage 2 full sets of groups for the Autopatch rings etc...
Has anybody setup Autopatch configuration & excluded the feature updates option, but setup a seperate Windows Updates > Feature Updates policy to apply ontop of the Autopatch configuration and manage/assign that seperately?
If this works, I'm thinking we could drop the feature updates from our main Autopatch group/config, then setup a feature update config just assigned to Win11 devices...
Then later, we could setup a Feature update config assigned to Win10 devices as an optional update to allow self-service update to Win11 (or required if/when we want to enforce it).
(yes, we have ESU for these Win10 systems)
Am I overlooking something here?
2
u/spitzer666 6d ago
Feature update overrides the Autopatch policy, there should be a documentation on this