Microsoft has deprecated WSUS. It still works, but it's getting no new features, and for a small business with remote workers it was never a good fit anyway. Intune's Windows Update policies (together called Windows Update for Business) give you control over when updates install, without running a server. Your devices download straight from Microsoft, wherever they are.
The four policy types
| Policy | Controls | Typical setting |
|---|---|---|
| Update rings | Quality (monthly) update deferrals, deadlines, restarts, and user experience | Staged rings: pilot, early, broad |
| Feature updates | Which Windows version a device stays on or moves to | Pin to a specific Windows 11 version |
| Quality update expedite | Pushing one urgent security update faster than the rings would | Used for zero-days only |
| Driver and firmware updates | Whether drivers come through Windows Update, and with what approval | Automatic approval for most small fleets |
Design the rings
A simple three-ring setup covers most small businesses:
- Pilot: IT and a few willing users. No deferral. They find problems first.
- Early: a cross-section of the business, a few days behind pilot.
- Broad: everyone else, a week or so behind.
For each ring, set:
- Quality update deferral (days after release)
- Deadline for install, and a grace period before a forced restart
- Active hours or automatic behavior, so restarts don't hit the middle of the workday
Feature updates
Create a feature update policy that pins devices to a specific Windows 11 version. Devices won't jump to the next version until you change the policy. That gives you time to test line-of-business apps against each new release.
Consider Windows Autopatch
Windows Autopatch automates ring management, deployment, and reporting on top of these same policies. Microsoft has extended it to more licenses, including Business Premium, so check what your tenant is entitled to before building everything by hand.
The silent blocker: leftover WSUS and GPO settings
If devices ignore your Intune update rings, the culprit is almost always old Group Policy or registry settings pointing them at WSUS:
# On an affected device
Get-ItemProperty "HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" -ErrorAction SilentlyContinue |
Select-Object WUServer, WUStatusServer, DisableDualScan, DoNotConnectToWindowsUpdateInternetLocations
Get-ItemProperty "HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" -ErrorAction SilentlyContinue |
Select-Object UseWUServer, NoAutoUpdateIf WUServer is set and UseWUServer is 1, the device is still pointed at WSUS. Remove the GPO (or unlink it from the device's OU), run gpupdate /force, and confirm the values are gone. Registry values left behind by old images or scripts need to be cleaned up directly.
Checking it's working
- Intune -> Reports -> Windows updates shows per-device status for feature and quality updates.
- On the device, Settings -> Windows Update -> Advanced options should say "Some of these settings are managed by your organization" and list the Intune policy's behavior.
Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 5confirms the latest cumulative update actually installed.
Retiring WSUS
Once every device reports through Intune for a full monthly cycle:
- Unlink and delete the WSUS GPOs.
- Stop the WSUS service and keep the server off for a month.
- Decommission it, and update your documentation so nobody rebuilds it later.