Intune Update Ring for Phased Security Updates
You have a Microsoft 365 subscription. The subscription contains 500 computers that run Windows 11 and are enrolled in Microsoft Intune. You need to manage the deployment of monthly security updates. The solution must meet the following requirements: • Updates must be deployed to a group of test computers for quality assurance. • Updates must be deployed automatically 15 days after the quality assurance testing. What should you create in the Microsoft Intune admin center?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests knowledge of Intune update rings as the mechanism for phased rollout, avoiding the trap of using device configuration profiles for scheduling.
Learn how to use Intune update rings to phase Windows security updates between QA and production groups. This page confirms that an update ring is the correct configuration for staged deployments.
Many candidates choose Device Configuration Profile (A), confusing general settings with the specific update deployment and scheduling capabilities of update rings.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
An update ring in Microsoft Intune is specifically designed to manage the deployment of Windows updates by defining when different groups of devices receive them. By creating two update rings—one for the test group with a shorter delay and one for the production group with a 15-day delay—you can enforce the required phased rollout automatically. This aligns perfectly with the requirement to deploy updates to a QA group first and then automatically to others after a set period.Why the Other Options Are Wrong
Device configuration profiles (A) are used to apply settings like Wi-Fi or email configurations, not to schedule update deployments. Feature update policies (B) manage major version upgrades, not monthly security patches. Security baselines (C) provide recommended settings for compliance but do not handle the timing or phasing of update delivery.Community Comment Notes
Community consensus strongly supports option D, with users noting that update rings are the standard tool for this scenario. One user highlighted that taking a 'ring approach' ensures QA testing before final release. Another noted that while filtering could be used, update rings are the native feature for managing these timelines effectively.Official Reference
Exam Strategy
When asked about phased updates or staging windows in Intune, immediately think of Update Rings. They are the only object type that allows you to define specific delay days for quality and feature updates across different device groups.
Frequently Asked Questions
Why not use a device configuration profile?
Device configuration profiles apply settings like certificates or Wi-Fi, but they cannot schedule or phase the deployment of Windows updates.
Can I use one update ring for both groups?
No, you need separate update rings assigned to different device groups to apply different delay timelines for QA versus production.
Related Analysis
Practice All MD-102 Questions
Access 92 questions with complete answers and detailed explanations.
View Full MD-102 Practice Test →