Intune Update Ring for Phased Security Updates

Answer Correct answer: D — Create an update ring in the Microsoft Intune admin center to phase security updates between test and production groups.

You have a Microsoft 365 subscription. The subscription contains 500 computers that run Windows 11 and are enrolled in Microsoft Intune. You need to manage the deployment of monthly security updates. The solution must meet the following requirements: • Updates must be deployed to a group of test computers for quality assurance. • Updates must be deployed automatically 15 days after the quality assurance testing. What should you create in the Microsoft Intune admin center?

  1. a device configuration profile
  2. a feature update policy
  3. a security baseline
  4. an update ring Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests knowledge of Intune update rings as the mechanism for phased rollout, avoiding the trap of using device configuration profiles for scheduling.

Learn how to use Intune update rings to phase Windows security updates between QA and production groups. This page confirms that an update ring is the correct configuration for staged deployments.

Many candidates choose Device Configuration Profile (A), confusing general settings with the specific update deployment and scheduling capabilities of update rings.

Community Discussion (8 comments)

Moot2 👍 2 Selected: D
Do update ring
RomanV 👍 1 Selected: D
If you worked with Intune, you know it's D: Update ring.
Merrybob 👍 3 Selected: D
D. an update ring Taking a ring approach will ensure that testing is performed in the company's Dev/QA environment(s), and final release will be made to the Production environment after 15 days after QA testing wraps up. .
Krayzr 👍 1 Selected: D
Windows Copilot says: To manage the deployment of monthly security updates for your 500 computers running Windows 11 and enrolled in Microsoft Intune, you should create an update ring in the Microsoft Intune admin center 1. An update ring is a collection of devices that receive updates at the same time. You can use update rings to manage the deployment of monthly quality updates, feature updates, and other updates to devices in your organization 1. To meet the requirements of deploying updates to a group of test computers for quality assurance and deploying updates automatically 15 days after the quality assurance testing, you can use Quality updates for Windows 10 and Later policy 1. With this policy, you can expedite the installation of the most recent Windows 10/11 security updates on devices you manage with Microsoft Intune 1. Deployment of expedited updates is done without the need to pause or edit your existing monthly update policies 1. You can also configure quality updates deferrals by using Intune Windows update rings and the setting for Quality update deferral period 1. Therefore, the correct answer is D. an update ring.
mertak 👍 1 Selected: D
ChatGPT: To meet the specified requirements for managing the deployment of monthly security updates in Microsoft Intune, you can follow these general steps: Create Device Groups: In the Microsoft Intune admin center, navigate to "Groups." Create a device group for the test computers where you will perform quality assurance testing. Create Update Ring: In the Microsoft Intune admin center, navigate to "Endpoint security" > "Update policies." Create an update ring for the group of test computers. Configure the update ring settings, including the deployment schedule.
NoursBear 👍 2
Whichever way you want to do it, 2 actions or more will be required, either you create 2 rings and dont assign the all users one yet or you create one ring which is assined to the pilot group first then you change the assignment or one ring assigned to all and use filtering, then again the filtering then has to be removed. Not a great question
mp34 👍 1
not sure about this one, as far as i can see the update ring and config profile both offer similar settings as far as i can make out, you would need 2 configurations for this, one for testing and the other for the main updates....
krzysiek321 👍 1
D - update ring

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

An update ring in Microsoft Intune is specifically designed to manage the deployment of Windows updates by defining when different groups of devices receive them. By creating two update rings—one for the test group with a shorter delay and one for the production group with a 15-day delay—you can enforce the required phased rollout automatically. This aligns perfectly with the requirement to deploy updates to a QA group first and then automatically to others after a set period.

Why the Other Options Are Wrong

Device configuration profiles (A) are used to apply settings like Wi-Fi or email configurations, not to schedule update deployments. Feature update policies (B) manage major version upgrades, not monthly security patches. Security baselines (C) provide recommended settings for compliance but do not handle the timing or phasing of update delivery.

Community Comment Notes

Community consensus strongly supports option D, with users noting that update rings are the standard tool for this scenario. One user highlighted that taking a 'ring approach' ensures QA testing before final release. Another noted that while filtering could be used, update rings are the native feature for managing these timelines effectively.

Official Reference

Exam Strategy

When asked about phased updates or staging windows in Intune, immediately think of Update Rings. They are the only object type that allows you to define specific delay days for quality and feature updates across different device groups.

Frequently Asked Questions

Why not use a device configuration profile?

Device configuration profiles apply settings like certificates or Wi-Fi, but they cannot schedule or phase the deployment of Windows updates.

Can I use one update ring for both groups?

No, you need separate update rings assigned to different device groups to apply different delay timelines for QA versus production.

Related Analysis

Practice All MD-102 Questions

Access 92 questions with complete answers and detailed explanations.

View Full MD-102 Practice Test →

← Back to MD-102 Study Guide