Intune: Windows Update Scheduled Install - Every Day
๐ 2025-10-30
โข
โฑ๏ธ 2 minuten lezen
โข
๐ข Should-Have
๐ผ Management Samenvatting
Windows Update scheduled install: Every day - allows daily update installation window (fastest patch deployment).
Aanbeveling
IMPLEMENT
Risico zonder
Medium
Risk Score
5/10
Implementatie
2u (tech: 1u)
Van toepassing op:
โ Windows 10 โ Windows 11
Update schedule options: Specific day (Tuesday only): Updates install ONLY on Tuesdays โ if device offline Tuesday: waits until NEXT Tuesday (7-day delay), Every day (RECOMMENDED): Updates install ANY day device is online โ fastest deployment. Security: Critical patch released โ Every day: Installs within 24 hours, Specific day: May wait 7 days (unacceptable for critical vulnerabilities). CIS: Every day schedule (fastest patch compliance).
PowerShell Modules Vereist
Primary API: Microsoft Graph API Connection:Connect-MgGraph Required Modules: Microsoft.Graph.DeviceManagement
Implementatie
Every day schedule: Policy: Scheduled install day: 0 (Every day), Effect: Windows checks for updates daily โ installs when available, Active hours respected: Updates install outside 9 AM - 5 PM (non-disruptive), Fastest patching: Device online ANY day โ updates install (no weekly wait).
Vereisten
Intune subscription
Windows 10/11
Active hours configured (9 AM - 5 PM)
Auto-updates enabled
Implementatie
Intune: Windows Update ring โ Scheduled install day: Every day (0). Active hours: 9 AM - 5 PM. Effect: Updates install daily (outside active hours).
Compliance
CIS Windows Benchmark L1, BIO 12.06, NIST SI-2.
Monitoring
Gebruik PowerShell-script scheduled-install-day-is-set-to-every-day.ps1 (functie Invoke-Monitoring) โ Controleren.
Remediatie
Gebruik PowerShell-script scheduled-install-day-is-set-to-every-day.ps1 (functie Invoke-Remediation) โ Herstellen.
Compliance & Frameworks
CIS M365: Control Windows - Update schedule (L1) -
BIO: 12.06.01 -
Automation
Gebruik het onderstaande PowerShell script om deze security control te monitoren en te implementeren. Het script bevat functies voor zowel monitoring (-Monitoring) als remediation (-Remediation).