Intune Driver Firmware Update Policies | Review Approve Schedule Suspend Options | Endpoint Manager

Let’s have a quick review of Intune Driver Firmware Update policies. Also, have a look into the following options to control the driver updates with Intune policies.

  • Approve
  • Schedule
  • Suspend

This blog post is based on the Ignite 2021 session by Thad Martin and Bryan Keller. You can refer to the session video Driver and firmware servicing in the enterprise – Microsoft Tech Community.

NOTE! – This feature is not available in Intune at this point in time. When the Driver Update Policies will be available in Intune? Fall 2021! The private Preview Program is getting started this Spring.

Patch My PC

Current Driver Update Architecture

The following is the diagram showed in the Ignite session to explain the current architecture flow of Windows 10 Driver updates using Windows Update for Business. There are no selection and approval capabilities with the current driver update policies in Intune.

  1. Intune Admin configure and set the Windows 10 Update policy for managed devices.
  2. Devices Scan against Software Update in the cloud.
  3. All the available drivers are offered for those devices.
Intune Driver Firmware Update Policies | Review Approve Schedule Suspend Options - Pic Credits to Microsoft
Intune Driver Firmware Update Policies | Review Approve Schedule Suspend Options – Pic Credits to Microsoft

New Driver & Firmware Servicing Architecture

Now, let’s look at the architecture diagram provided by Microsoft to understand the new driver & firmware update flow.

  1. Intune Admin creates a new Windows 10 Driver Update policy.
    • Intune Admin browse and select particular driver updates.
    • Deploy to Azure AD device group.
  2. Devices scan against Software Update cloud service based on Windows 10 Driver update policy.
  3. Software Update cloud service sends the Scan results back to Intune.
  4. Intune populates available driver updates for those devices based on the data from the software update service.
  5. Intune Admin approves the selected driver updates and saves the Windows 10 Driver Update Policy.
  6. Devices scan against software update services based on new approval (updated) policy.
  7. Only the approved Driver updates are offered to the devices by the Software Update service.
Intune Driver Firmware Update Policies | Review Approve Schedule Suspend Options - Pic Credits to Microsoft
Intune Driver Firmware Update Policies | Review Approve Schedule Suspend Options – Pic Credits to Microsoft

Intune Driver Firmware Updates

You can create new Windows 10 Driver Update policy from the Devices node as you can see in the below screen capture.

1E Nomad
  • Login to Endpoint.Microsoft.com.
  • Navigate to Devices node.
  • Scroll down to Policy section.
  • Click on Windows 10 Driver Update policies blade to create a new Driver update policy.
Intune Driver Firmware Update Policies | Review Approve Schedule Suspend Options - Pic Credits to Microsoft
Intune Driver Firmware Update Policies | Review Approve Schedule Suspend Options – Pic Credits to Microsoft

There are two options when you create Intune Driver update policy for controlling Windows Update for Business driver updates.

  • Automatically Deploy all applicable updates from Windows Update
    • You have an option to Delay the Driver Update deployment to devices
      • Deploy after (0 to 14 days)
  • Deploy Only approved updates (Manual process)
    • There is an option to notify me when new recommended updates become available
Intune Driver Firmware Update Policies | Review Approve Schedule Suspend Options - Pic Credits to Microsoft
Intune Driver Firmware Update Policies | Review Approve Schedule Suspend Options – Pic Credits to Microsoft

NOTE! – Microsoft recommends creating Azure AD groups with a similar model so that it will easy to manage driver updates for those group devices.

Review – Approve – Schedule Driver Updates from Intune

Follow the steps to review, select, approve, and schedule driver updates from Intune.

  • Click on New Updates (3) available under the New Updates column from Windows 10 Driver Update Policies blade.
Intune Driver Firmware Update Policies | Review Approve Schedule Suspend Options - Pic Credits to Microsoft
Intune Driver Firmware Update Policies | Review Approve Schedule Suspend Options – Pic Credits to Microsoft
  • This will take you to the available list of driver updates details page for this group of devices.
  • You also have the following options to manage the Driver Update policy.
    • Suspend the policy – If you hit some issue with the driver updates. To pause the deployment of Driver updates.
    • Delete the Policy
  • There are three sections on this page:
    • Properties
    • Recommended Updates
    • Previously Approved Updates
  • You will have the following details for each driver update.
    • Driver Name
    • Version Number of Driver update
    • Driver Date
    • Manufactor – Intel/Realtek/DisplayLink
    • Driver Class – Video/Sound/Networking
    • Status – Appproved or Available
    • Devices Applicable
    • Devices Installed
Intune Driver Firmware Update Policies | Review Approve Schedule Suspend Options - Pic Credits to Microsoft
Intune Driver Firmware Update Policies | Review Approve Schedule Suspend Options – Pic Credits to Microsoft
  • Click on the Driver name where status is Available.
  • On the right side of the Endpoint Manager portal, you can see the Manage Deployment blade.
  • Click on the drop-down menu from the Action section and select Approve to approve this driver update deployment.
Intune Driver Firmware Update Policies | Review Approve Schedule Suspend Options - Pic Credits to Microsoft
Intune Driver Firmware Update Policies | Review Approve Schedule Suspend Options – Pic Credits to Microsoft
  • Now, let’s schedule the Windows 10 driver update from Intune.
  • Under the Deploy section, you have an option to select a date.
    • From this particular date whenever the client scans Windows Updates, this particular DisplayLink update will get offered to those 991 devices as you see in the below screenshot.
  • Click on Save to continue.
Intune Driver Firmware Update Policies | Review Approve Schedule Suspend Options - Pic Credits to Microsoft
Intune Driver Firmware Update Policies | Review Approve Schedule Suspend Options – Pic Credits to Microsoft

Suspend Driver Updates on Intune Managed Windows 10 Devices

Now, let’s understand what are the options to suspend Windows 10 Driver update policy because of known issues with the driver updates. You can do this suspension from the same page mentioned in the above section.

  • Click on the Driver Name that you want to suspend.
  • Click on the drop-down menu from the Action section on the Manage Deployment blade.
  • Select the action option called Suspend.
  • Click the Save button to suspend the further deployment of that particular driver update.
Intune Driver Firmware Update Policies | Review Approve Schedule Suspend Options - Pic Credits to Microsoft
Intune Driver Firmware Update Policies | Review Approve Schedule Suspend Options – Pic Credits to Microsoft
  • Now you can see that particular Driver status is changed to suspended.
Intune Driver Firmware Update Policies | Review Approve Schedule Suspend Options - Pic Credits to Microsoft
Intune Driver Firmware Update Policies | Review Approve Schedule Suspend Options – Pic Credits to Microsoft

Results

Let’s quickly check the resultant Windows 10 Driver update policy from Endpoint Manager portal. The following are the details that you can see in the policy blade.

  • Update Policy Name – Name of the policy.
  • Type of Policy – Manual or Automatic.
  • Devices Assigned – Devices assigned to this policy.
  • Devices Reporting – Number of devices scans & start reporting to Software Update (for Business) services with inventory details.
  • New Updates – Once the scan is completed the new updates will start appearing.
Intune Driver Firmware Update Policies | Review Approve Schedule Suspend Options - Pic Credits to Microsoft
Intune Driver Firmware Update Policies | Review Approve Schedule Suspend Options – Pic Credits to Microsoft

Resources

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.