{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-343-wait-for-feature-policy-processing-before-removing-windows-update-deferrals/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-343-wait-for-feature-policy-processing-before-removing-windows-update-deferrals/",
        "slug": "dse-20260909-343-wait-for-feature-policy-processing-before-removing-windows-update-deferrals",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-343-wait-for-feature-policy-processing-before-removing-windows-update-deferrals/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-343-wait-for-feature-policy-processing-before-removing-windows-update-deferrals.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-343-wait-for-feature-policy-processing-before-removing-windows-update-deferrals/"
        },
        "title": "Wait for feature-policy processing before removing Windows update deferrals",
        "summary": "What must be verified before changing a Windows feature-update deferral to zero?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "managed-it",
            "label": "Managed IT operations",
            "alt": "A controlled technology lifecycle progressing from assessment to approved production.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/managed-it-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/managed-it-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:26:13+00:00",
        "modified_at": "2026-09-10T01:40:03+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 1,
        "word_count": 203,
        "potentially_affected": "Use this sequence when replacing ring-based feature deferrals with an Intune feature-update policy. Record the desired Windows version and the full affected population, including devices that have not yet reported readiness.",
        "dse_recommendation": "Make observed service processing the release gate for the deferral change.",
        "primary_source": {
            "name": "Configure Windows Feature Update Policies - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/device-updates/windows/configure-feature-update-policy",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>If a device scans after its feature-update deferral is removed but before Windows Update processes the replacement feature policy, it can receive an unintended version offer. Microsoft&#8217;s transition sequence assigns the target-version policy first, verifies OfferReady for all targeted devices, and only then sets the ring&#8217;s feature deferral to zero. <a href=\"https://learn.microsoft.com/en-us/intune/device-updates/windows/configure-feature-update-policy\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this sequence when replacing ring-based feature deferrals with an Intune feature-update policy. Record the desired Windows version and the full affected population, including devices that have not yet reported readiness.</p>\n<h2>DSE recommendation</h2>\n<p>Make observed service processing the release gate for the deferral change. Keep the old control in place until the replacement is verified, rather than relying on a fixed waiting period or successful policy creation. Have the update owner explain missing devices before approving the next step.</p>\n<h2>Verification</h2>\n<p>Generate the policy report and reconcile the targeted devices against the approved inventory. Preserve their OfferReady evidence and the subsequent deferral change. On representative clients, check the offered version after scanning and confirm it matches the intended policy. Investigate an unexpected offer before expanding the transition; do not equate policy presence in Intune with completed processing by Windows Update.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/device-updates/windows/configure-feature-update-policy\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Configure Windows Feature Update Policies</a>.</p>",
        "content_text": "Source facts\nIf a device scans after its feature-update deferral is removed but before Windows Update processes the replacement feature policy, it can receive an unintended version offer. Microsoft’s transition sequence assigns the target-version policy first, verifies OfferReady for all targeted devices, and only then sets the ring’s feature deferral to zero. Microsoft Learn.\nApplicability\nUse this sequence when replacing ring-based feature deferrals with an Intune feature-update policy. Record the desired Windows version and the full affected population, including devices that have not yet reported readiness.\nDSE recommendation\nMake observed service processing the release gate for the deferral change. Keep the old control in place until the replacement is verified, rather than relying on a fixed waiting period or successful policy creation. Have the update owner explain missing devices before approving the next step.\nVerification\nGenerate the policy report and reconcile the targeted devices against the approved inventory. Preserve their OfferReady evidence and the subsequent deferral change. On representative clients, check the offered version after scanning and confirm it matches the intended policy. Investigate an unexpected offer before expanding the transition; do not equate policy presence in Intune with completed processing by Windows Update.\nOfficial references\nMicrosoft Learn: Configure Windows Feature Update Policies.",
        "content_markdown": "## Source facts\n\nIf a device scans after its feature-update deferral is removed but before Windows Update processes the replacement feature policy, it can receive an unintended version offer. Microsoft’s transition sequence assigns the target-version policy first, verifies OfferReady for all targeted devices, and only then sets the ring’s feature deferral to zero. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-updates/windows/configure-feature-update-policy).\n\n## Applicability\n\nUse this sequence when replacing ring-based feature deferrals with an Intune feature-update policy. Record the desired Windows version and the full affected population, including devices that have not yet reported readiness.\n\n## DSE recommendation\n\nMake observed service processing the release gate for the deferral change. Keep the old control in place until the replacement is verified, rather than relying on a fixed waiting period or successful policy creation. Have the update owner explain missing devices before approving the next step.\n\n## Verification\n\nGenerate the policy report and reconcile the targeted devices against the approved inventory. Preserve their OfferReady evidence and the subsequent deferral change. On representative clients, check the offered version after scanning and confirm it matches the intended policy. Investigate an unexpected offer before expanding the transition; do not equate policy presence in Intune with completed processing by Windows Update.\n\n## Official references\n\n[Microsoft Learn: Configure Windows Feature Update Policies](https://learn.microsoft.com/en-us/intune/device-updates/windows/configure-feature-update-policy)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-343-wait-for-feature-policy-processing-before-removing-windows-update-deferrals/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-343-wait-for-feature-policy-processing-before-removing-windows-update-deferrals/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-343-wait-for-feature-policy-processing-before-removing-windows-update-deferrals/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Wait for feature-policy processing before removing Windows update deferrals",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-343-wait-for-feature-policy-processing-before-removing-windows-update-deferrals/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-343-wait-for-feature-policy-processing-before-removing-windows-update-deferrals/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-343-wait-for-feature-policy-processing-before-removing-windows-update-deferrals/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-343-wait-for-feature-policy-processing-before-removing-windows-update-deferrals/",
                "headline": "Wait for feature-policy processing before removing Windows update deferrals",
                "description": "What must be verified before changing a Windows feature-update deferral to zero?",
                "abstract": "What must be verified before changing a Windows feature-update deferral to zero?",
                "articleBody": "Source facts\nIf a device scans after its feature-update deferral is removed but before Windows Update processes the replacement feature policy, it can receive an unintended version offer. Microsoft’s transition sequence assigns the target-version policy first, verifies OfferReady for all targeted devices, and only then sets the ring’s feature deferral to zero. Microsoft Learn.\nApplicability\nUse this sequence when replacing ring-based feature deferrals with an Intune feature-update policy. Record the desired Windows version and the full affected population, including devices that have not yet reported readiness.\nDSE recommendation\nMake observed service processing the release gate for the deferral change. Keep the old control in place until the replacement is verified, rather than relying on a fixed waiting period or successful policy creation. Have the update owner explain missing devices before approving the next step.\nVerification\nGenerate the policy report and reconcile the targeted devices against the approved inventory. Preserve their OfferReady evidence and the subsequent deferral change. On representative clients, check the offered version after scanning and confirm it matches the intended policy. Investigate an unexpected offer before expanding the transition; do not equate policy presence in Intune with completed processing by Windows Update.\nOfficial references\nMicrosoft Learn: Configure Windows Feature Update Policies.",
                "datePublished": "2026-09-10T00:26:13+00:00",
                "dateModified": "2026-09-10T01:40:03+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-343-wait-for-feature-policy-processing-before-removing-windows-update-deferrals/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-343-wait-for-feature-policy-processing-before-removing-windows-update-deferrals/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Wait for feature-policy processing before removing Windows update deferrals"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 203,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Configure Windows Feature Update Policies - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/device-updates/windows/configure-feature-update-policy"
                }
            }
        ]
    }
}