Files
windows-itpro-docs/windows/deployment/windows-autopatch/references/windows-autopatch-changes-to-tenant.md
2024-02-05 14:10:02 -08:00

15 KiB
Raw Blame History

title, description, ms.date, ms.service, ms.subservice, ms.topic, ms.localizationpriority, author, ms.author, manager, ms.reviewer, ms.collection
title description ms.date ms.service ms.subservice ms.topic ms.localizationpriority author ms.author manager ms.reviewer ms.collection
Changes made at tenant enrollment This reference article details the changes made to your tenant when enrolling into Windows Autopatch 12/13/2023 windows-client itpro-updates reference medium tiaraquan tiaraquan aaroncz hathind
highpri
tier1

Changes made at tenant enrollment

The following configuration details explain the changes made to your tenant when enrolling into the Windows Autopatch service.

Important

The service manages and maintains the following configuration items. Don't change, edit, add to, or remove any of the configurations. Doing so might cause unintended configuration conflicts and impact the Windows Autopatch service.

Windows Autopatch enterprise applications

Enterprise applications are applications (software) that a business uses to do its work.

Windows Autopatch creates an enterprise application in your tenant. This enterprise application is used to run the Windows Autopatch service.

Enterprise application name Usage Permissions
Modern Workplace Management The Modern Workplace Management application:
  • Manages the service
  • Publishes baseline configuration updates
  • Maintains overall service health
  • DeviceManagementApps.ReadWrite.All
  • DeviceManagementConfiguration.ReadWrite.All
  • DeviceManagementManagedDevices.PriviligedOperation.All
  • DeviceManagementManagedDevices.ReadWrite.All
  • DeviceManagementRBAC.ReadWrite.All
  • DeviceManagementServiceConfig.ReadWrite.All
  • Directory.Read.All
  • Group.Create
  • Policy.Read.All
  • WindowsUpdates.ReadWrite.All

Microsoft Entra groups

Windows Autopatch will create the required Microsoft Entra groups to operate the service.

The following groups target Windows Autopatch configurations to devices and management of the service by our first party enterprise applications.

Group name Description
Modern Workplace-All AllModernWorkplaceusers
Modern Workplace - Windows 11 Pre-Release Test Devices DevicegroupforWindows11Pre-Releasetesting.
Modern Workplace Devices-All AllAutopatchdevices
Modern Workplace Devices-Virtual Machine All Autopatch virtual devices
Modern Workplace Devices-Windows Autopatch-Test Deployment ring for testing update deployments prior production rollout
Modern Workplace Devices-Windows Autopatch-First First production deployment ring for early adopters
Modern Workplace Devices-Windows Autopatch-Fast Fast deployment ring for quick rollout and adoption
ModernWorkplaceDevices-WindowsAutopatch-Broad Final deployment ring for broad rollout into the organization
Modern Workplace Roles - Service Administrator AllusersgrantedaccesstoModernWorkplaceServiceAdministratorRole
Modern Workplace Roles - Service Reader AllusersgrantedaccesstoModernWorkplaceServiceReaderRole
Windows Autopatch Device Registration Group for automaticdeviceregistrationforWindowsAutopatch

Device configuration policies

  • Windows Autopatch - Set MDM to Win Over GPO
  • Windows Autopatch - Data Collection
Policy name Policy description Properties Value
Windows Autopatch-SetMDMtoWinOverGPO Setsmobile device management (MDM)towinoverGPO

Assigned to:

  • ModernWorkplaceDevices-WindowsAutopatch-Test
  • Modern Workplace Devices-Windows Autopatch-First
  • Modern Workplace Devices-Windows Autopatch-Fast
  • Modern Workplace Devices-Windows Autopatch-Broad
MDM Wins Over GP
  • MDM policy is used
  • GP policy is blocked
Windows Autopatch-DataCollection Windows Autopatch and Telemetry settings processes diagnosticdatafromtheWindows device.

Assigned to:

  • ModernWorkplaceDevices-WindowsAutopatch-Test
  • Modern Workplace Devices-Windows Autopatch-First
  • Modern Workplace Devices-Windows Autopatch-Fast
  • Modern Workplace Devices-Windows Autopatch-Broad
  1. Allow Telemetry
  2. Limit Enhanced Diagnostic Data Windows Analytics
  3. Limit Dump Collection
  4. Limit Diagnostic Log Collection
  1. Full
  2. Enabled
  3. Enabled
  4. Enabled

Deployment rings for Windows 10 and later

  • Modern Workplace Update Policy [Test]-[Windows Autopatch]
  • Modern Workplace Update Policy [First]-[Windows Autopatch]
  • Modern Workplace Update Policy [Fast]-[Windows Autopatch]
  • Modern Workplace Update Policy [Broad]-[Windows Autopatch]
Policy name Policy description OMA Value
ModernWorkplaceUpdatePolicy[Test]-[WindowsAutopatch WindowsUpdateforBusinessConfigurationfortheTestRing

Assigned to:

  • ModernWorkplaceDevices-WindowsAutopatch-Test
  • MicrosoftProductUpdates
  • EnablePrereleasebuilds
  • UpgradetoLatestWin11
  • QualityUpdatesDeferralPeriodInDays
  • FeatureUpdatesDeferralPeriodInDays
  • FeatureUpdatesRollbackWindowInDays
  • BusinessReadyUpdatesOnly
  • AutomaticUpdateMode
  • InstallTime
  • DeadlineForFeatureUpdatesInDays
  • DeadlineForQualityUpdatesInDays
  • DeadlineGracePeriodInDays
  • PostponeRebootUntilAfterDeadline
  • DriversExcluded
  • RestartChecks
  • SetDisablePauseUXAccess
  • SetUXtoCheckforUpdates
  • Allow
  • Not Configured
  • No
  • 0
  • 0
  • 30
  • All
  • WindowsDefault
  • 3
  • 5
  • 0
  • 0
  • False
  • False
  • Allow
  • Disable
  • Enable
ModernWorkplaceUpdatePolicy[First]-[WindowsAutopatch] WindowsUpdateforBusinessConfigurationfortheFirstRing

Assigned to:

  • ModernWorkplaceDevices-WindowsAutopatch-First
  • MicrosoftProductUpdates
  • EnablePrereleasebuilds
  • UpgradetoLatestWin11
  • QualityUpdatesDeferralPeriodInDays
  • FeatureUpdatesDeferralPeriodInDays
  • FeatureUpdatesRollbackWindowInDays
  • BusinessReadyUpdatesOnly
  • AutomaticUpdateMode
  • InstallTime
  • DeadlineForFeatureUpdatesInDays
  • DeadlineForQualityUpdatesInDays
  • DeadlineGracePeriodInDays
  • PostponeRebootUntilAfterDeadline
  • DriversExcluded
  • RestartChecks
  • SetDisablePauseUXAccess
  • SetUXtoCheckforUpdates
  • Allow
  • Not Configured
  • No
  • 1
  • 0
  • 30
  • All
  • WindowsDefault
  • 3
  • 5
  • 2
  • 2
  • False
  • False
  • Allow
  • Disable
  • Enable
ModernWorkplaceUpdatePolicy[Fast]-[WindowsAutopatch] WindowsUpdateforBusinessConfigurationfortheFastRing

Assigned to:

  • ModernWorkplaceDevices-WindowsAutopatch-Fast
  • MicrosoftProductUpdates
  • EnablePrereleasebuilds
  • UpgradetoLatestWin11
  • QualityUpdatesDeferralPeriodInDays
  • FeatureUpdatesDeferralPeriodInDays
  • FeatureUpdatesRollbackWindowInDays
  • BusinessReadyUpdatesOnly
  • AutomaticUpdateMode
  • InstallTime
  • DeadlineForFeatureUpdatesInDays
  • DeadlineForQualityUpdatesInDays
  • DeadlineGracePeriodInDays
  • PostponeRebootUntilAfterDeadline
  • DriversExcluded
  • RestartChecks
  • SetDisablePauseUXAccess
  • SetUXtoCheckforUpdates
  • Allow
  • Not Configured
  • No
  • 6
  • 0
  • 30
  • All
  • WindowsDefault
  • 3
  • 5
  • 2
  • 2
  • False
  • False
  • Allow
  • Disable
  • Enable
ModernWorkplaceUpdatePolicy[Broad]-[WindowsAutopatch] WindowsUpdateforBusinessConfigurationfortheBroadRing

Assigned to:

  • ModernWorkplaceDevices-WindowsAutopatch-Broad
  • MicrosoftProductUpdates
  • EnablePrereleasebuilds
  • UpgradetoLatestWin11
  • QualityUpdatesDeferralPeriodInDays
  • FeatureUpdatesDeferralPeriodInDays
  • FeatureUpdatesRollbackWindowInDays
  • BusinessReadyUpdatesOnly
  • AutomaticUpdateMode
  • InstallTime
  • DeadlineForFeatureUpdatesInDays
  • DeadlineForQualityUpdatesInDays
  • DeadlineGracePeriodInDays
  • PostponeRebootUntilAfterDeadline
  • DriversExcluded
  • RestartChecks
  • SetDisablePauseUXAccess
  • SetUXtoCheckforUpdates
  • Allow
  • Not Configured
  • No
  • 9
  • 0
  • 30
  • All
  • WindowsDefault
  • 3
  • 5
  • 5
  • 2
  • False
  • False
  • Allow
  • Disable
  • Enable

Windows feature update policies

  • Windows Autopatch - DSS Policy [Test]
  • Windows Autopatch - DSS Policy [First]
  • Windows Autopatch - DSS Policy [Fast]
  • Windows Autopatch - DSS Policy [Broad]
  • Modern Workplace DSS Policy [Windows 11]
Policy name Policy description Value
Windows Autopatch - DSS Policy [Test] DSSpolicyforTest devicegroup Assigned to:
  • ModernWorkplaceDevices-WindowsAutopatch-Test

Exclude from:
  • ModernWorkplace-Windows11Pre-ReleaseTestDevices
Windows Autopatch -DSSPolicy[First] DSSpolicyforFirstdevice group Assigned to:
  • ModernWorkplaceDevices-WindowsAutopatch-First
  • Modern Workplace - Windows 11 Pre-Release Test Devices
Windows Autopatch -DSSPolicy[Fast] DSSpolicyforFastdevice group Assigned to:
  • Modern Workplace Devices-Windows Autopatch-Fast

Exclude from:
  • Modern Workplace - Windows 11 Pre-Release Test Devices
Windows Autopatch -Policy[Broad] DSSpolicyforBroad devicegroup Assigned to:
  • ModernWorkplaceDevices-WindowsAutopatch-Broad

Exclude from:
  • ModernWorkplace-Windows11Pre-ReleaseTestDevices
Modern WorkplaceDSSPolicy[Windows11] Windows11DSSpolicy Assigned to:
  • ModernWorkplace-Windows11Pre-ReleaseTestDevices

Microsoft Office update policies

  • Windows Autopatch - Office Configuration
  • Windows Autopatch - Office Update Configuration [Test]
  • Windows Autopatch - Office Update Configuration [First]
  • Windows Autopatch - Office Update Configuration [Fast]
  • Windows Autopatch - Office Update Configuration [Broad]
Policy name Policy description Properties Value
Windows Autopatch-OfficeConfiguration SetsOfficeUpdateChanneltotheMonthlyEnterpriseservicingbranch.

Assigned to:

  1. ModernWorkplaceDevices-WindowsAutopatch-Test
  2. Modern Workplace Devices-Windows Autopatch-First
  3. Modern Workplace Devices-Windows Autopatch-Fast
  4. Modern Workplace Devices-Windows Autopatch-Broad
  1. Enable Automatic Updates
  2. Hide option to enable or disable updates
  3. Update Channel
  4. Channel Name (Device)
  5. Hide Update Notifications
  6. Update Path
  7. Location for updates (Device)
  1. Enabled
  2. Enabled
  3. Enabled
  4. Monthly Enterprise Channel
  5. Disabled
  6. Enabled
  7. http://officecdn.microsoft.com/pr/55336b82-a18d-4dd6-b5f6-9e5095c314a6
Windows Autopatch-OfficeUpdateConfiguration[Test] Sets theOfficeupdatedeadline

Assigned to:

  1. ModernWorkplaceDevices-WindowsAutopatch-Test
  1. Delay downloading and installing updates for Office
  2. Update Deadline
  1. Enabled; Days(Device) == 0 days
  2. Enabled; Update Deadline(Device) == 7 days
Windows Autopatch-OfficeUpdateConfiguration[First] Setsthe Officeupdatedeadline

Assigned to:

  1. ModernWorkplaceDevices-WindowsAutopatch-First
  1. Delay downloading and installing updates for Office
  2. Update Deadline
  1. Enabled; Days(Device) == 0 days
  2. Enabled; Update Deadline(Device) == 7 days
Windows Autopatch-OfficeUpdateConfiguration[Fast] Setsthe Officeupdatedeadline

Assigned to:

  1. ModernWorkplaceDevices-WindowsAutopatch-Fast
  1. Delay downloading and installing updates for Office
  2. Update Deadline
  1. Enabled; Days(Device) == 3 days
  2. Enabled; Update Deadline(Device) == 7 days
Windows Autopatch-OfficeUpdateConfiguration[Broad] Setsthe Officeupdatedeadline
Assigned to:
  1. ModernWorkplaceDevices-WindowsAutopatch-Broad
  1. Delay downloading and installing updates for Office
  2. Update Deadline
  1. Enabled; Days(Device) == 7 days
  2. Enabled; Update Deadline(Device) == 7 days

Microsoft Edge update policies

  • Windows Autopatch - Edge Update Channel Stable
  • Windows Autopatch - Edge Update Channel Beta
Policy name Policy description Properties Value
Windows Autopatch-EdgeUpdateChannelStable Deploys updates via the Edge Stable Channel

Assigned to:

  1. ModernWorkplaceDevices-WindowsAutopatch-First
  2. Modern Workplace Devices-Windows Autopatch-Fast
    1. Modern Workplace Devices-Windows Autopatch-Broad
  1. Target Channel Override
  2. Target Channel (Device)
  1. Enabled
  2. Stable
Windows Autopatch - Edge Update Channel Beta Deploysupdates via the EdgeBetaChannel

Assigned to:

  1. ModernWorkplaceDevices-WindowsAutopatch-Test
  1. Target Channel Override
  2. Target Channel (Device)
  1. Enabled
  2. Beta

PowerShell scripts

Script Description
Modern Workplace - Autopatch Client Setup v1.1 Installs necessary client components for the Windows Autopatch service