What you need to know
What must be verified before changing a Windows feature-update deferral to zero?
Potentially affected
Use this sequence when replacing ring-based feature deferrals with an Intune feature-update policy. Record the desired Windows version and the full affected population, including devices that have not yet reported readiness.
DSE recommendation
Make observed service processing the release gate for the deferral change.
Source facts
If a device scans after its feature-update deferral is removed but before Windows Update processes the replacement feature policy, it can receive an unintended version offer. Microsoft’s transition sequence assigns the target-version policy first, verifies OfferReady for all targeted devices, and only then sets the ring’s feature deferral to zero. Microsoft Learn.
Applicability
Use this sequence when replacing ring-based feature deferrals with an Intune feature-update policy. Record the desired Windows version and the full affected population, including devices that have not yet reported readiness.
DSE recommendation
Make observed service processing the release gate for the deferral change. Keep the old control in place until the replacement is verified, rather than relying on a fixed waiting period or successful policy creation. Have the update owner explain missing devices before approving the next step.
Verification
Generate the policy report and reconcile the targeted devices against the approved inventory. Preserve their OfferReady evidence and the subsequent deferral change. On representative clients, check the offered version after scanning and confirm it matches the intended policy. Investigate an unexpected offer before expanding the transition; do not equate policy presence in Intune with completed processing by Windows Update.
Official references
Review the official source
Configure Windows Feature Update Policies - Microsoft Intune | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE