L1BIO 12.06.02ISO A.12.6.1CIS Windows - Feature update deferral
Intune: Defer Windows Feature Updates (180 Days)
π 2025-10-30
β’
β±οΈ 4 minuten lezen
β’
π’ Should-Have
πΌ Management Samenvatting
Defer Windows feature updates 180 days - testing period voor major OS updates (stability over bleeding-edge).
Aanbeveling
IMPLEMENT
Risico zonder
Low
Risk Score
3/10
Implementatie
13u (tech: 3u)
Van toepassing op:
β Windows 10 β Windows 11
Feature updates = major changes: Feature update: Semi-annual (22H2, 23H1) - new features, UI changes, driver updates, Risks: Breaking changes (app compatibility, driver issues), Early adopter problems (bugs in new features), Business impact: Productivity loss (broken apps, user retraining). Deferral benefits: Microsoft testing: 180 days β millions of early adopters find bugs β Microsoft patches, Enterprise testing: Pilot group tests deferred update β app compatibility verification β production rollout. CIS recommendation: 180+ days deferral (balance: stability vs security).
PowerShell Modules Vereist
Primary API: Microsoft Graph API Connection:Connect-MgGraph Required Modules: Microsoft.Graph.DeviceManagement
Implementatie
Defer feature updates: 180 days: Production devices receive feature updates 6 months after release, Quality updates: NOT deferred (security patches immediate), Pilot group: 0-30 days deferral (early testing), Production: 180 days (stability), Deployment rings: Pilot (IT - 0 days) β Early adopters (30 days) β Production (180 days).
Vereisten
Intune subscription
Windows 10/11
Deployment rings: Pilot + Production groups
App compatibility testing process
Implementatie
Intune: Devices β Windows Updates β Update rings β Create ring 'Production' β Feature update deferral: 180 days, Quality update deferral: 0 days (immediate security patches). Assign to: Production devices. Pilot ring: 0-30 days deferral (IT team).
Compliance
CIS Windows Benchmark (180 days), BIO 12.06 (Change management), ISO 27001 A.12.6.1.
Monitoring
Gebruik PowerShell-script windows-update-defer-feature.ps1 (functie Invoke-Monitoring) β Controleren.
Remediatie
Gebruik PowerShell-script windows-update-defer-feature.ps1 (functie Invoke-Remediation) β Herstellen.
Compliance & Frameworks
CIS M365: Control Windows - Feature update deferral (L1) -
BIO: 12.06.02 -
ISO 27001:2022: A.12.6.1 -
Automation
Gebruik het onderstaande PowerShell script om deze security control te monitoren en te implementeren. Het script bevat functies voor zowel monitoring (-Monitoring) als remediation (-Remediation).