{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-234-do-not-treat-the-tunnel-upgrade-window-end-as-a-completion-deadline/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-234-do-not-treat-the-tunnel-upgrade-window-end-as-a-completion-deadline/",
        "slug": "dse-20260909-234-do-not-treat-the-tunnel-upgrade-window-end-as-a-completion-deadline",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-234-do-not-treat-the-tunnel-upgrade-window-end-as-a-completion-deadline/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-234-do-not-treat-the-tunnel-upgrade-window-end-as-a-completion-deadline.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-234-do-not-treat-the-tunnel-upgrade-window-end-as-a-completion-deadline/"
        },
        "title": "Do not treat the Tunnel upgrade-window end as a completion deadline",
        "summary": "Can a Microsoft Tunnel server upgrade continue after its configured maintenance window ends?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:28:02+00:00",
        "modified_at": "2026-09-10T01:20:46+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 228,
        "potentially_affected": "Use this interpretation when scheduling Tunnel Gateway server upgrades for a site. Identify the effective site settings and time zone before promising a business restoration time.",
        "dse_recommendation": "Plan staffing and service observation beyond the latest permitted upgrade start.",
        "primary_source": {
            "name": "Install the Microsoft Tunnel VPN for Microsoft Intune - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/install",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>A Microsoft Tunnel site&#8217;s maintenance window limits when an upgrade cycle may start. A cycle begun before the end can continue and finish afterward. The selected site time zone applies to every server there, regardless of individual server time zones. Automatic upgrade and administrator approval are separate site choices. The configured maintenance window must span at least one hour. <a href=\"https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/install\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this interpretation when scheduling Tunnel Gateway server upgrades for a site. Identify the effective site settings and time zone before promising a business restoration time.</p>\n<h2>DSE recommendation</h2>\n<p>Plan staffing and service observation beyond the latest permitted upgrade start. Have the Tunnel owner distinguish approval time, allowed start interval, actual start, and observed completion in the maintenance record. Confirm who responds if a late-starting cycle is still active at the window&#8217;s end. Do not shorten the operating plan by assuming the configured end time forcibly stops work, and do not assume a window grants manual approval.</p>\n<h2>Verification</h2>\n<p>For an approved upgrade, record the site time zone and actual cycle timestamps alongside server version and health afterward. Validate an intended client connection and internal resource access. If completion extends beyond the window, compare it with the documented start-time rule before declaring a scheduling defect. Preserve the evidence for planning the next maintenance period.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/install\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Install the Microsoft Tunnel VPN for Microsoft Intune</a>.</p>",
        "content_text": "Source facts\nA Microsoft Tunnel site’s maintenance window limits when an upgrade cycle may start. A cycle begun before the end can continue and finish afterward. The selected site time zone applies to every server there, regardless of individual server time zones. Automatic upgrade and administrator approval are separate site choices. The configured maintenance window must span at least one hour. Microsoft Learn.\nApplicability\nUse this interpretation when scheduling Tunnel Gateway server upgrades for a site. Identify the effective site settings and time zone before promising a business restoration time.\nDSE recommendation\nPlan staffing and service observation beyond the latest permitted upgrade start. Have the Tunnel owner distinguish approval time, allowed start interval, actual start, and observed completion in the maintenance record. Confirm who responds if a late-starting cycle is still active at the window’s end. Do not shorten the operating plan by assuming the configured end time forcibly stops work, and do not assume a window grants manual approval.\nVerification\nFor an approved upgrade, record the site time zone and actual cycle timestamps alongside server version and health afterward. Validate an intended client connection and internal resource access. If completion extends beyond the window, compare it with the documented start-time rule before declaring a scheduling defect. Preserve the evidence for planning the next maintenance period.\nOfficial references\nMicrosoft Learn: Install the Microsoft Tunnel VPN for Microsoft Intune.",
        "content_markdown": "## Source facts\n\nA Microsoft Tunnel site’s maintenance window limits when an upgrade cycle may start. A cycle begun before the end can continue and finish afterward. The selected site time zone applies to every server there, regardless of individual server time zones. Automatic upgrade and administrator approval are separate site choices. The configured maintenance window must span at least one hour. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/install).\n\n## Applicability\n\nUse this interpretation when scheduling Tunnel Gateway server upgrades for a site. Identify the effective site settings and time zone before promising a business restoration time.\n\n## DSE recommendation\n\nPlan staffing and service observation beyond the latest permitted upgrade start. Have the Tunnel owner distinguish approval time, allowed start interval, actual start, and observed completion in the maintenance record. Confirm who responds if a late-starting cycle is still active at the window’s end. Do not shorten the operating plan by assuming the configured end time forcibly stops work, and do not assume a window grants manual approval.\n\n## Verification\n\nFor an approved upgrade, record the site time zone and actual cycle timestamps alongside server version and health afterward. Validate an intended client connection and internal resource access. If completion extends beyond the window, compare it with the documented start-time rule before declaring a scheduling defect. Preserve the evidence for planning the next maintenance period.\n\n## Official references\n\n[Microsoft Learn: Install the Microsoft Tunnel VPN for Microsoft Intune](https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/install)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-234-do-not-treat-the-tunnel-upgrade-window-end-as-a-completion-deadline/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-234-do-not-treat-the-tunnel-upgrade-window-end-as-a-completion-deadline/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-234-do-not-treat-the-tunnel-upgrade-window-end-as-a-completion-deadline/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Do not treat the Tunnel upgrade-window end as a completion deadline",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-234-do-not-treat-the-tunnel-upgrade-window-end-as-a-completion-deadline/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-234-do-not-treat-the-tunnel-upgrade-window-end-as-a-completion-deadline/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-234-do-not-treat-the-tunnel-upgrade-window-end-as-a-completion-deadline/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-234-do-not-treat-the-tunnel-upgrade-window-end-as-a-completion-deadline/",
                "headline": "Do not treat the Tunnel upgrade-window end as a completion deadline",
                "description": "Can a Microsoft Tunnel server upgrade continue after its configured maintenance window ends?",
                "abstract": "Can a Microsoft Tunnel server upgrade continue after its configured maintenance window ends?",
                "articleBody": "Source facts\nA Microsoft Tunnel site’s maintenance window limits when an upgrade cycle may start. A cycle begun before the end can continue and finish afterward. The selected site time zone applies to every server there, regardless of individual server time zones. Automatic upgrade and administrator approval are separate site choices. The configured maintenance window must span at least one hour. Microsoft Learn.\nApplicability\nUse this interpretation when scheduling Tunnel Gateway server upgrades for a site. Identify the effective site settings and time zone before promising a business restoration time.\nDSE recommendation\nPlan staffing and service observation beyond the latest permitted upgrade start. Have the Tunnel owner distinguish approval time, allowed start interval, actual start, and observed completion in the maintenance record. Confirm who responds if a late-starting cycle is still active at the window’s end. Do not shorten the operating plan by assuming the configured end time forcibly stops work, and do not assume a window grants manual approval.\nVerification\nFor an approved upgrade, record the site time zone and actual cycle timestamps alongside server version and health afterward. Validate an intended client connection and internal resource access. If completion extends beyond the window, compare it with the documented start-time rule before declaring a scheduling defect. Preserve the evidence for planning the next maintenance period.\nOfficial references\nMicrosoft Learn: Install the Microsoft Tunnel VPN for Microsoft Intune.",
                "datePublished": "2026-09-10T00:28:02+00:00",
                "dateModified": "2026-09-10T01:20:46+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-234-do-not-treat-the-tunnel-upgrade-window-end-as-a-completion-deadline/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-234-do-not-treat-the-tunnel-upgrade-window-end-as-a-completion-deadline/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Do not treat the Tunnel upgrade-window end as a completion deadline"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 228,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Install the Microsoft Tunnel VPN for Microsoft Intune - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/install"
                }
            }
        ]
    }
}