Primary API: Microsoft Graph API Connection:Connect-MgGraph Required Modules: Microsoft.Graph.DeviceManagement
Implementatie
0-day quality deferral: Policy: Defer quality updates: 0 days, Effect: Security patches deploy ASAP (next check-in - typically hours), No delay: Critical CVE β patch released Tuesday β deployed Tuesday/Wednesday, Pilot testing: SKIP for quality (too urgent - deploy immediately).
Vereisten
Intune subscription
Windows 10/11
Auto-updates enabled
Active hours: Non-disruptive restart times
Implementatie
Intune: Windows Update ring β Quality update deferral: 0 days (immediate). Feature deferral: 180 days (testing OK). Active hours: 9 AM - 5 PM.
Compliance
CIS Windows Benchmark L1 (0 days), Microsoft Security Baseline, BIO 12.06, NIS2 Art. 21, NIST SI-2.
Monitoring
Gebruik PowerShell-script windows-update-defer-quality.ps1 (functie Invoke-Monitoring) β Controleren.
Remediatie
Gebruik PowerShell-script windows-update-defer-quality.ps1 (functie Invoke-Remediation) β Herstellen.
Compliance & Frameworks
CIS M365: Control Windows - Quality deferral (L1) -
BIO: 12.06.01 -
NIS2: Artikel -
Automation
Gebruik het onderstaande PowerShell script om deze security control te monitoren en te implementeren. Het script bevat functies voor zowel monitoring (-Monitoring) als remediation (-Remediation).