MD-102 Update Management 2 — Questions and Answers
Question 1: An administrator needs to immediately deploy a critical security update to all Windows devices without waiting for the configured deferral period. Which Intune feature should they use?
- Update ring override
- Expedite update (Correct answer)
- Emergency deployment
- Force sync
Correct answer: Expedite update
Expedite updates in Intune allow administrators to push a specific quality update to devices immediately, bypassing any configured deferral periods for urgent security patches.
Question 2: In an Intune update ring, what does the 'Active hours' setting control?
- When devices can download updates from Microsoft servers
- The time window during which Windows will not restart devices to apply updates (Correct answer)
- The hours during which Delivery Optimization peer sharing is active
- When Intune syncs update policies to devices
Correct answer: The time window during which Windows will not restart devices to apply updates
Active hours defines the time window when Windows will not restart a device to complete update installation, ensuring users are not interrupted during their working hours.
Question 3: Which Windows Autopatch feature automatically manages update rings and deployment schedules without requiring manual administrator configuration?
- Intune update rings
- Windows Update for Business
- Autopatch groups (Correct answer)
- Windows Insider rings
Correct answer: Autopatch groups
Autopatch groups in Windows Autopatch automatically manage device grouping and phased update deployment, reducing the administrative overhead of manually configuring update rings.
Question 4: A company wants to keep 50 devices on Windows 10 21H2 indefinitely while the rest upgrade. Which Long-Term Servicing Channel version supports this scenario for non-specialized devices?
- Windows 10 LTSC 2019
- Windows 10 LTSC 2021 (Correct answer)
- Windows 11 LTSC 2024
- Windows 10 Enterprise LTSB
Correct answer: Windows 10 LTSC 2021
Windows 10 LTSC 2021 is the appropriate Long-Term Servicing Channel release for devices that require a stable, unchanging OS version, with 5 years of mainstream support.
Question 5: What is the recommended approach for managing Microsoft 365 Apps update channels within Microsoft Intune?
- Use Windows Update for Business policies
- Configure update rings for Office
- Use the Microsoft 365 Apps Update channel policy under App configuration (Correct answer)
- Manually deploy Office updates via Win32 apps
Correct answer: Use the Microsoft 365 Apps Update channel policy under App configuration
Microsoft 365 Apps update channels are managed through App configuration policies in Intune, which control which update channel (Monthly Enterprise, Current, etc.) is used for Office apps.
Question 6: An update ring in Intune is set to 'Pause quality updates.' How long can quality updates be paused before the pause automatically expires?
- 7 days
- 14 days
- 21 days
- 35 days (Correct answer)
Correct answer: 35 days
Quality update pauses in Intune update rings automatically expire after 35 days, after which the device will resume receiving quality updates.
Question 7: Which Intune policy type should be used to enforce that devices install all pending updates within a specific number of days, even if the user postpones the restart?
- Update ring deadline settings (Correct answer)
- Compliance policy grace period
- Device configuration restart policy
- Windows Update ring restart deadline
Correct answer: Update ring deadline settings
Update ring deadline settings in Intune include options to set a deadline by which devices must install quality and feature updates and restart, overriding user postponements.
An administrator needs to immediately deploy a critical security update to all Windows devices without waiting for the configured deferral period.
Which Intune feature should they use?