Are you an early adaptor of Intune? Intune custom policies configured using CSPs are very helpful in most of the scenarios. But, you can get into trouble with some of the custom CSPs if you don’t update it promptly. In this post, we will see “FIX CBB Ring Devices are Getting CB Updates Intune Windows 10 Update Rings.”
What is Intune Windows 10 Update Ring Policies?
Windows 10 update ring policies are to define the Windows 10 software update behaviour of Intune managed devices. You can create different policies to define CBB (Semi-Annual) and CB (Semi-Annual Targeted) channels for Windows 10 machines. You can also use Windows 10 update ring policy to set quality updates and Delivery Optimization (DO) behaviours of Windows 10 machine.
When you set one machine into CB/SAT ring then, that machine will get Windows 10 upgrade notification whenever Microsoft releases a new version of Windows 10. I have a post and video tutorial which talks about Windows 10 update ring policies. More details available “How to Setup Windows 10 Software Update Policy Rings in Intune Azure Portal“.
CB = Semi-Annual Targeted (SAT) CBB = Semi-Annual (SA)
The machines which are supposed to get Windows 10 1709 update/upgrade through Current Branch for Business (CBB/SA) channel are getting the update as part of Current Branch channel (CB/SAT).
For example, when you have two custom policies in Intune environment to define Windows 10 update rings. These policies are there to define the Windows 10 feature update behaviour for machines.
Why Windows 10 CBB machine are getting CB Updates?
The CSPs used in the custom policies are NOT supported for Windows 10 1607 and later versions. More details available here in the Microsoft documentation here.
./Vendor/MSFT/Policy/Config/Update/RequireDeferUpgrade 1 (CBB/SA) ./Vendor/MSFT/Policy/Config/Update/RequireDeferUpgrade 0 (CB/SAT)
How to Fix the Windows 10 Update Ring Issue for Intune Managed Devices?
You should create new policies to define Windows 10 update rings. This can be done using Intune console – Software updates – Windows 10 Update Rings. One policy is for Windows 10 Current Branch/Semi-Annual Targeted channel. And the another policy is for Windows 10 Current Branch for Business/Semi-Annual channel.
For Windows 10 CB/Semi-Annual Channel Targeted (SAT) channel, you need to define a new policy in Intune console. Software updates – Windows 10 Update Rings – Semi-Annual Channel Targeted (SAT).
For Windows 10 CBB/Semi-Annual Channel (SA) channel, you need to define a new policy in Intune console. Software updates – Windows 10 Update Rings – Semi-Annual Channel (SA).
Once newly created Windows 10 Update ring policies are deployed to respective Azure AD Device groups then, remove or delete the Intune custom policies.