Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesTo control when supported Windows quality updates are approved and offered to managed devices, create a Windows quality update policy in the Intune admin center at Devices > Manage updates > Windows updates > Quality updates. Select approval behavior for security, non-security, and out-of-band updates, configure a delay for automatic approvals if needed, and assign the policy to eligible devices. Use update rings for installation and restart experience; use an expedite policy when one eligible update needs faster deployment.
What a quality update approval policy controls
A Windows quality update policy is the cloud orchestration and approval surface for supported quality update content. It covers monthly security updates, monthly non-security preview updates, and out-of-band security and non-security updates. In documented scenarios, supported .NET Framework updates use the same approval settings, with exceptions described below. See Microsoft’s Windows quality updates and .NET Framework updates guidance.
Approval is distinct from the device’s installation and restart experience. Update rings configure client-side deferrals, deadlines, restart behavior, active hours, and notifications. A quality update policy’s automatic-approval delay is not the same as a ring’s quality-update deferral.
Check device eligibility first
Quality update policies use the Windows Autopatch backend. Before assigning one, verify the relevant devices meet Microsoft’s policy requirements, which include:
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
- MICROSOFT WINDOWS 11 PRO (INGLES) FPP 64-BIT ENG INTL USB FLASH DRIVE
- Enrollment in Intune.
- Microsoft Entra joined or hybrid joined state. Entra-registered devices are not supported for policy types using this backend, including quality update policies.
- A Windows license that includes the required Autopatch entitlement.
- Connectivity to Microsoft update endpoints.
Eligibility differs across update-management features, so consult the Windows Update Management overview and the policy-specific documentation before rollout. For unsupported Entra-registered devices, management remains limited to Windows Update client policies and update rings.
Choose an approval mode
Microsoft documents automatic approval for monthly security updates and manual approval for other update types as the defaults. The appropriate setting depends on how quickly updates should become available and how much change control your organization requires.
Rank #2
- STREAMLIMED AND INTUITIVE UI | Intelligent desktop | Personalize your experience for simpler efficiency | Powerful security built-in and enabled.
- JOIN YOUR BUSINESS OR SCHOOL DOMAIN for easy access to network files, servers, and printers.
- OEM IS TO BE INSTALLED ON A NEW PC WITH NO PRIOR VERSION of Windows installed and cannot be transferred to another machine.
- OEM DOES NOT PROVIDE PRODUCT SUPPORT | To acquire product with Microsoft support, obtain the full packaged “Retail” version.
| Mode | How it works | When it fits |
|---|---|---|
| Automatic approval | Updates are approved automatically. You can set Make updates available after to add a delay in days before availability. | Normal security servicing where timely deployment matters. Microsoft recommends automatic approval for security updates. |
| Manual approval | An administrator must explicitly approve an update before it is deployed. | Optional or non-security releases that need strict change control or additional testing. Delaying critical updates can harm security compliance. |
Microsoft’s guidance states: “Windows Autopatch recommends automatic approvals for security updates and manual approvals for optional updates.” Choose settings deliberately: manual approval introduces an administrative decision point, while automatic approval with a delay allows a staged availability window.
Create and assign the quality update policy
- Open the policy area: In the Intune admin center, go to Devices > Manage updates > Windows updates > Quality updates, select Create, then select Windows quality update policy. Admin center navigation can change, so verify the labels shown in your tenant.
- Name the policy: Use a recognizable name that identifies its update category or rollout purpose.
- Set approval behavior: Under Settings, select the approval configuration for security, non-security, and out-of-band updates.
- Set the delay if using automatic approval: Configure Make updates available after for the desired number of days. With manual approval, updates wait for explicit administrator approval.
- Configure scope and assignments: Continue through scope tags and assign the policy to the intended device groups. Use deployment groups and a validation sequence suited to your organization’s risk tolerance.
- Configure device experience separately: Create or review update rings for deferrals, deadlines, restart controls, active hours, and notifications. Microsoft documents a quality-update deferral range of 0–30 days in a ring; this is separate from the policy’s automatic-approval delay. See the update ring policy settings.
Keep update rings and approval policies distinct
Use the quality update policy to determine approval and cloud orchestration for supported update content. Use an update ring to shape Windows Update client behavior, including when a device defers an update and how installation and restarts are presented. Rings can be assigned in stages such as test, pilot, and production; see Microsoft’s update ring policy guidance.
Recommended Free Tools
Rank #3
- Less chaos, more calm. The refreshed design of Windows 11 enables you to do what you want effortlessly.
- Biometric logins. Encrypted authentication. And, of course, advanced antivirus defenses. Everything you need, plus more, to protect you against the latest cyberthreats.
- Make the most of your screen space with snap layouts, desktops, and seamless redocking.
- Widgets makes staying up-to-date with the content you love and the news you care about, simple.
- Stay in touch with friends and family with Microsoft Teams, which can be seamlessly integrated into your taskbar. (1)
Review overlapping assignments and settings against the intended deployment process. For devices managed by Autopatch, Microsoft may create and maintain rings; administrators typically should not assign custom rings to those devices.
Use expedite only for a specific urgent update
An expedite policy is for a selected eligible update that needs faster deployment than the normal approval and timing path provides. It does not replace the ongoing quality update approval policy or define how future monthly updates are handled.
Rank #4
- Instantly productive. Simpler, more intuitive UI and effortless navigation. New features like snap layouts help you manage multiple tasks with ease.
- Smarter collaboration. Have effective online meetings. Share content and mute/unmute right from the taskbar (1) Stay focused with intelligent noise cancelling and background blur.(2)
- Reassuringly consistent. Have confidence that your applications will work. Familiar deployment and update tools. Accelerate adoption with expanded deployment policies.
- Powerful security. Safeguard data and access anywhere with hardware-based isolation, encryption, and malware protection built in.
Create an expedite policy for the selected release and assign it to the devices that need it. One expedite policy selects one update. Applicable quality update deferrals are overridden for that update, but installation is not instantaneous or guaranteed: devices must connect, scan, and communicate with the service, and start time depends on connectivity and service processing. Microsoft also documents supported Windows editions and in-support builds, direct Windows Update delivery, Update Health Tools, and other configuration requirements; preview builds are not supported for expedited updates. Check the current expedite update requirements and workflow before relying on it.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Understand update coverage and exceptions
Quality update approval settings can cover supported monthly OS security updates, monthly non-security preview updates, and out-of-band security and non-security updates. Supported .NET Framework updates follow the same settings in documented scenarios, but two exceptions matter:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
- Video Link to instructions and Free support VIA Amazon
- 24/7 Tech Support!
- key code included
- Windows 10 devices enrolled in Extended Security Updates (ESU) continue to receive .NET Framework updates through Windows Update based on client-side settings.
- .NET Framework 3.5 updates are not managed through this quality policy workflow.
For implementation details and the current exceptions, consult Microsoft’s quality updates and .NET Framework documentation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

