DEV Community

AdminPackStudio
AdminPackStudio

Posted on

Expedite a Windows quality update in Intune - prerequisites, the real timeline, and why "expedite" sometimes does nothing

Expedite a Windows quality update in Intune: prerequisites, timeline, and why it sometimes does nothing

Your update rings defer quality updates by a few days on purpose. Then a security update ships for something that's being actively exploited, and leadership asks how fast every device can have it. That's what expedited quality updates are for: they let you push a specific security update to devices ahead of their ring deferrals, with a short restart deadline.

Expedite works well when the prerequisites are in place, and it does almost nothing visible when they aren't. This post covers how it works, what it depends on, how to check a device without changing it, and a short runbook for patch-now days. Portal paths, prerequisites, and licensing change over time, so check current Microsoft docs.


1. What expedite actually does

In the Intune admin center, under Devices > Windows > Quality updates for Windows 10 and later (sometimes shown under a "Windows updates" menu), you create an expedite profile. The key setting reads roughly:

Expedite installation of quality updates if device OS version is less than: [a recent security update release]

You pick a recent security release from the list. Devices below that build are told to install it now, ignoring the ring's quality deferral. You also set Number of days to wait before restart is enforced (a short range, 0 to 2 days at the time of writing).

Important details:

  • It's a minimum, not a pin. Devices already at or above that build are left alone.
  • It's for quality (security) updates only. It doesn't expedite feature updates or drivers.
  • You choose from the list Intune offers. You can't type an arbitrary KB number.
  • It doesn't replace rings. After the expedite, devices go back to normal ring behavior.
  • The profile is one-shot in practice. Once the target release is old, the profile has nothing left to do. Retire it so it doesn't confuse the next admin.

2. The prerequisites that break it silently

Expedite runs through Microsoft's cloud update service, not just through local policy. That's why a device can have the profile assigned and still do nothing. Check each of these:

Prerequisite Why it matters What failure looks like
Supported Windows edition and licensing The service is licensed (check current docs for your plan) Profile creates fine; devices never report
Device is Microsoft Entra joined or hybrid joined and Intune-managed The service targets devices by their Entra identity Device missing from the report
Windows diagnostic data at Required or higher, and the tenant setting that lets Intune use it The service needs device data to target and report "Not enough data" or no status
Device can reach Windows Update cloud endpoints Proxies or firewalls can block the service Download never starts
Updates actually managed by Intune / Windows Update for Business Devices on WSUS or a co-management workload still on Configuration Manager won't follow Profile assigned, nothing happens
The update health components the service relies on are present These help the device act on expedite requests Older devices lag or never act
Device is powered on and online Expedite can't wake a sleeping laptop Long tail of "pending"

The co-management one catches a lot of hybrid shops. If the Windows Update policies workload still points at Configuration Manager, Intune's expedite profile doesn't control those devices.


3. Read-only device checks

On a device that isn't picking up the expedite, start with what it thinks its state is. Nothing here changes settings.

# Build and latest installed update
Get-ComputerInfo -Property OsName, OSDisplayVersion, OsBuildNumber
Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 5 HotFixID, Description, InstalledOn

# Exact build including revision (UBR); compare with the release you expedited
$cv = Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion'
"{0}.{1}" -f $cv.CurrentBuild, $cv.UBR

# Is the device pointed at WSUS? (policy values, if set)
Get-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate' -ErrorAction SilentlyContinue |
  Select-Object WUServer, WUStatusServer
Get-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU' -ErrorAction SilentlyContinue |
  Select-Object UseWUServer

# Diagnostic data policy value (if set)
Get-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\DataCollection' -ErrorAction SilentlyContinue |
  Select-Object AllowTelemetry

# Entra join state
dsregcmd /status | Select-String 'AzureAdJoined|DomainJoined|DeviceId|TenantName'
Enter fullscreen mode Exit fullscreen mode

How to read it:

  • UseWUServer = 1 with a WUServer value means the device is pointed at WSUS. Expedite through Intune won't behave the way you expect until that's fixed.
  • AllowTelemetry = 0 (Security / off) blocks the service. Required is 1.
  • AzureAdJoined : NO and not hybrid joined means the service can't target the device.
  • The UBR (the number after the build) tells you the exact cumulative update level. That's what you compare with the release you picked in the profile.

Get-HotFix doesn't always list every cumulative update cleanly. Treat the build and UBR as the source of truth.


4. The realistic timeline

Expedite is fast compared with waiting out a 7-day deferral, but it isn't instant:

  1. Profile assigned. The service has to process it and notify devices.
  2. Online devices check in, download, and install.
  3. The restart deadline you set starts counting. Users get restart prompts.
  4. The device reports back, and the Intune report updates.

Plan in hours to a couple of days, not minutes. Laptops that are off, on a bad network, or asleep make up the long tail. That's normal. Your job is to measure the tail and chase it, not to expect 100 percent by lunch.

Use the expedited quality updates report in Intune (under Reports > Windows updates) and export it at fixed points, for example +4 hours, +24 hours, and +48 hours. Those three exports become your evidence that the patch was handled.


5. A short "patch now" runbook

1. Confirm the update addresses the issue (Microsoft release notes / security guidance).
2. Open a change ticket marked emergency. Name the approver.
3. Assign the expedite profile to the pilot or IT group first. Watch for 1-2 hours.
4. If nothing breaks, assign to all targeted devices. Restart deadline 1-2 days.
5. Send user comms: "Restart when prompted. Save your work first."
6. Export the report at +4h, +24h, +48h. Chase the offline tail.
7. Check the WSUS / co-management / diagnostic-data exceptions from section 2.
8. Retire the profile once the release is behind the normal ring.
9. Write two lines in the ticket: what was done, what's still outstanding.
Enter fullscreen mode Exit fullscreen mode

Step 3 matters even on emergency days. A pilot group that breaks in one hour is much better than a fleet that breaks in one hour.


6. Common mistakes

Mistake What happens Fix
Expecting expedite to work on WSUS-pointed devices Nothing happens on those devices Fix the source of updates first
Assigning to all devices with no pilot A bad update hits everyone Pilot group first, even for an hour
Restart deadline of 0 days with no comms Users lose unsaved work Warn users; pick 1 day if you can
Leaving old expedite profiles assigned Confusing reports later Retire after the release is normal
Measuring success by "profile assigned" False confidence Measure by build/UBR in the report
Ignoring the offline tail Unpatched laptops sit there for weeks Export, list, chase via helpdesk

Want the patch process written down?

The Windows Update Rings & Patch Ops Pack ($25) from Admin Pack Studio covers ring topology, promotion gates with line-of-business smoke tests, a weekly Patch Tuesday runbook with comms templates, pause and rollback habits with reopen criteria, and five patch break/fix cards. It's mostly docs, plus one read-only local snapshot script (similar in spirit to the checks above). It doesn't expedite, approve, or install anything for you.

Get the pack: https://cashflow4375.gumroad.com/l/windows-update-rings-patch-ops-pack?utm_source=devto&utm_medium=article&utm_campaign=expedite_quality

Need help with the offline tail on the helpdesk side? The IT Helpdesk Tier-1 Break/Fix Runbook Pack has triage cards and an escalation matrix: https://cashflow4375.gumroad.com/l/tezla


Admin Pack Studio. Not affiliated with Microsoft. Windows, Intune, Configuration Manager, and Microsoft Entra ID are Microsoft products. Operational guidance for admins authorized to manage their tenant. Settings, prerequisites, and licensing change, so check current Microsoft documentation. Examples use placeholder names.

Top comments (0)