Configuring Automatic Security Updates on Windows Endpoints
Security & antivirus
automatic updates
Windows Update
patch
security
By Kerry · Updated 03/05/26 07:53 AM
Automatic security updates ensure Windows machines receive critical patches promptly without requiring manual intervention. For unmanaged devices, enable automatic updates: Settings > Windows Update > Advanced options > Automatic updates set to On. Set Active hours (the period Windows avoids restarting for updates) to match the user's work schedule.
For managed environments with Intune: create a Windows Update for Business ring policy (Intune > Devices > Windows > Update rings). Configure deferral periods: 0 days deferral for Security updates ensures patches apply promptly. Set the 'Restart deadline' (e.g., 3 days after update download) so updates don't sit pending indefinitely. Feature updates can be deferred longer (30-90 days) to allow testing.
Monitor update compliance in Intune > Reports > Windows updates. Identify devices that are behind on patches. For devices that consistently fail to update, check disk space (insufficient space blocks updates), Windows Update service health, and network connectivity to Windows Update endpoints. Critical security patches (tagged as CVSS 9.0+) should be deployed as quickly as possible — consider an expedited ring with 0 deferral for critical severity patches.