Skip to content

Windows Updates

Windows update rings let operators approve specific Microsoft software, driver, and firmware updates for defined groups of Windows endpoints.

Open Operations > Windows Updates to manage rings and approvals.

An update ring combines three things:

  • one or more direct assignments that determine the ring's endpoint scope
  • an approval decision for each discovered Microsoft update revision

Approving an update does not install it immediately. Installation starts only when a job containing the Install approved Windows updates task runs against an endpoint.

Requirements and limitations

Windows update rings apply to Windows endpoints and use Microsoft Update as the update provider.

The following limitations apply:

  • WSUS is not supported for ring-managed endpoints.
  • Only updates offered through Windows Update are supported. Vendor tools and other update channels are outside the ring workflow.
  • The endpoint must report update inventory before its missing updates can appear in a ring.
  • A ring must be enabled and effective before an installation task can apply.

Use Update Inventory when you need a fleet-wide view that is not scoped to one ring.

Organize rings

The tree on the left side of the Windows Updates page contains update-ring folders and rings.

Use the Actions menu to:

  • add a folder
  • create an update ring
  • create nested folders inside an existing ring folder
  • rename or delete a ring folder

Ring folders only organize the Windows Updates tree. They do not assign the contained rings to endpoints.

An Endpoint folder assignment refers to a folder from the Endpoints area and includes endpoints in that folder and its descendant folders.

Create a ring

To create a ring:

  1. Open Operations > Windows Updates.
  2. Select Actions > New update ring.
  3. Enter a name and optional description.
  4. Select the ring folder or leave the ring at the root.
  5. Enter the automatic approval delay in whole days. The default is 0 days.
  6. Keep Ring enabled selected when the ring should be eligible to control endpoints and install approved updates.
  7. Save the ring.

A disabled ring remains available for review, but it does not install approved updates on endpoints.

Ring detail tabs

Each ring has four tabs.

Overview

The Overview tab contains the update approval table.

It shows Microsoft updates reported as missing in the ring, revisions scheduled for automatic approval, and recorded decision history. The table includes:

  • update title and KB article IDs
  • classification
  • update type (Software, Driver, or Firmware)
  • automatic or optional driver offer type
  • Microsoft revision number
  • number of effective endpoints reporting the update as missing
  • availability (Current, Installed, or Expired)
  • decision state
  • last-seen time

Use the table controls to search, sort, and filter by decision state, availability, update type, and driver offer type. Current and installed revisions are shown by default. Select Expired in the availability filter to include decision history for revisions that no effective endpoint currently reports as missing or installed.

Assignments

The Assignments tab lists the tenant, endpoint-folder, endpoint-group, and endpoint scopes assigned directly to the ring. Each target links to its corresponding page.

Select Actions > Assign from the ring header to add an assignment. Select assignments with their row checkboxes, then right-click the selection to open targets or remove one or more assignments.

Rules

The Rules tab lists the reusable automatic approval rules assigned to the ring. Every assigned rule uses the ring's automatic approval delay.

Select Assign on the right side of the tab row to assign rules. To unassign rules, select them with the table checkboxes, then right-click the selection and select Unassign rule or Unassign selected. Ctrl and Shift selection are supported. Assigning a rule evaluates updates that Ordyn has already discovered as well as future update revisions.

Endpoints

The Endpoints tab lists the endpoints for which the ring is effective.

The table shows:

  • endpoint and hostname
  • tenant
  • operating system
  • ring membership status and ring assignment conflicts
  • the assignment that selected the ring
  • last reconciliation time

Open an endpoint row to inspect that endpoint in the Endpoints area.

Endpoints with an equal-precedence ring conflict appear under every candidate ring with a Conflict status, but they are excluded from the ring's update catalog and cannot run the approved-update installation task.

Set up an update ring workflow

The complete setup uses a Windows Update Policy profile, direct ring assignments, update inventory collection, and an installation job:

  1. Open Library > Configuration Profiles and create a Windows Update Policy profile.
  2. Set Automatic updates mode to Disabled.
  3. Set Update source to Microsoft Update / Windows Update.
  4. Set Windows Update user access to Blocked when users must not manually scan for, download, or install updates. This also blocks interactive access for administrators.
  5. Configure any optional schedule or restart settings required by your organization. Ring installation itself does not restart endpoints.
  6. Assign the policy to the required tenant, endpoint folder, endpoint group, or endpoint scope.
  7. Use Remediate behavior when Ordyn should apply the policy. Use Audit only when GPO or MDM applies the settings and Ordyn should check them.
  8. Run or automate the Windows Update Policy as required for your environment.
  9. Create or edit a job with Collect Windows update inventory. Select Microsoft Update and the required classifications. Select Drivers when the ring should discover automatic, optional, and firmware offers from Windows Update.
  10. Run or schedule update inventory collection for the intended endpoint scope. Driver and firmware updates cannot appear in the ring until an applicable endpoint reports them.
  11. Open Operations > Windows Updates, create the ring, and configure its automatic approval delay and rules.
  12. Open the ring's Actions menu, select Assign, and choose the required tenant, endpoint folder, endpoint group, or endpoint.
  13. Review the ring's Assignments and Endpoints tabs.
  14. Create a job containing Install approved Windows updates and run or schedule it for the intended endpoint scope. Each endpoint uses its own effective ring.

The Windows Update Policy and ring assignment scopes can differ. Ring membership does not inspect or enforce the Windows Update Policy.

Assign a ring

To assign a ring:

  1. Open Operations > Windows Updates and select the ring.
  2. Select Actions > Assign.
  3. Select Tenant, Folder, Group, or Endpoint as the destination type.
  4. Search for and select the destination.
  5. Select Assign.

Ring assignments are declarative. They change ring membership and do not change Windows Update settings on an endpoint.

An endpoint can match several ring assignments. Ordyn selects the highest-precedence assignment using this order:

  1. endpoint
  2. endpoint group
  3. deepest matching endpoint folder
  4. tenant

An assignment at a more specific level overrides matching assignments below it. Multiple assignments at the same highest precedence can select the same ring without creating a conflict.

If assignments for different rings match at the same highest precedence, no ring becomes effective and a ring installation job fails until the conflict is resolved. A common example is an endpoint that belongs to two groups assigned to different rings.

Each tenant, folder, group, or endpoint can be assigned directly to only one ring. Assigning the same target to another ring reports a conflict; remove its existing direct assignment first.

Deleting an assigned tenant, endpoint folder, endpoint group, or endpoint also removes its direct ring assignment. Removing an assignment or deleting its target does not change Windows Update settings.

Configure Windows Update policy

Ordyn recommends an effective, compliant Windows Update Policy that:

  • sets automatic updates to Disabled
  • sets Update source to Microsoft Update / Windows Update

The policy can use Remediate behavior so Ordyn applies the settings, or Audit only behavior when GPO or MDM supplies the effective values.

Ordyn's ring installation job never changes Windows Update policy. Automatic reboot orchestration is disabled by default and can be enabled explicitly in the job step.

The ring workflow installs approved updates only when its job task runs. Set Windows Update user access to Blocked in the effective Windows Update Policy when interactive users must not start Windows Update outside Ordyn. The setting applies to administrators as well as standard users.

Use Windows Update notifications in the same policy to keep the default Windows notifications, show restart warnings only, or turn off all Windows Update notifications. This setting controls notification visibility and does not change installation or restart timing.

Removing a ring assignment changes ring membership only. Manage the Windows Update Policy assignment separately when its endpoint configuration should also change.

Update grouping

Ordyn groups discoveries from different endpoints by the Microsoft Update ID and revision number. The update type remains part of each exact installation request.

This means:

  • the same revision discovered on many endpoints appears once in the ring table
  • the missing count shows how many non-conflicted intended endpoints currently report that revision as missing
  • one approval applies that exact revision to all eligible endpoints in the ring
  • a newly discovered revision requires its own decision

This prevents endpoint-specific inventory records from creating duplicate approval rows while keeping Microsoft revisions distinct.

Approve or reject updates

Each update has one of these ring-specific decision states:

  • Eligible: no decision has been recorded
  • Approved: the ring installation job may install this exact revision
  • Rejected: the ring installation job excludes this revision

Use the decision filter in the table header to include approved or rejected updates. Eligible updates include revisions currently missing from ring endpoints and revisions scheduled by an assigned automatic approval rule. An approved or rejected revision is marked Expired when no effective endpoint currently reports it as missing or installed. Expired decisions are hidden by default and remain available through the availability filter.

To update decisions:

  1. Select one or more rows with the checkboxes.
  2. Right-click the selection.
  3. Select Approve, Reject, or Clear decision from the context menu.

You can also use the row context menu. Standard table selection is supported:

  • Ctrl or Command adds or removes individual rows from the selection.
  • Shift selects a range from the selection anchor.
  • The header checkbox selects or clears the loaded rows.

Clearing a decision returns the update to Eligible.

If an active automatic approval rule still matches the update, clearing its decision schedules it again. An overdue update can be approved again during the next automatic approval evaluation. Reject the update to suppress automatic approval for that ring and revision.

Decisions belong to one ring. Approving an update in one ring does not approve it in another ring.

Configure automatic approval rules

Select Automatic approvals above the update-ring tree to manage reusable matching rules.

To create a rule:

  1. Select Actions > New automatic approval rule.
  2. Enter a name and optional description.
  3. Select at least one classification. Select Drivers for Windows Update driver and firmware offers.
  4. Optionally select products or enter an Update name contains value.
  5. For driver rules, optionally select providers, manufacturers, driver classes, device models, or hardware IDs.
  6. Keep the rule enabled and save it.
  7. Open a ring's Rules tab and assign the rule.

To preview a saved rule, right-click that rule and select Preview. The preview opens separately and lists the most recently discovered Microsoft update revisions that currently match the rule.

Classification is required. Product, classification, and driver values are selected from metadata already reported by endpoints. Matching is case-insensitive:

  • an update may match any selected product
  • an update may match any selected classification
  • every populated matcher group must match
  • values within one matcher group use OR matching
  • Update name contains performs simple substring matching and does not support regular expressions
  • driver provider, manufacturer, class, model, and hardware ID values use exact matching

Driver applicability can differ between endpoints even when Microsoft gives the update the same ID and revision. A driver rule matches the shared update when at least one effective endpoint in the ring has one applicability record that satisfies every populated driver matcher group. The resulting approval applies that exact Microsoft update identity to all endpoints in the ring where Windows reports it as applicable.

Firmware delivered through the Windows Update driver channel is shown as Firmware. Approving it authorizes installation in the same way as any other driver. Review vendor release information and test firmware approvals in an appropriate ring before wider deployment.

The approval date is calculated from the time Ordyn first discovered the Microsoft Update ID and revision:

First discovered + ring delay = automatic approval date

For example, the same rule assigned to rings with delays of 0, 3, and 5 days schedules the exact revision immediately for the first ring, after three days for the second ring, and after five days for the third ring. Discovery on any endpoint starts the shared delay calculation. A rule is scheduled for a ring only while at least one effective endpoint in that ring reports the update as missing and satisfies its applicability matchers.

The update table shows scheduled automatic approvals with the rule name and approval date. Disabled rings show their schedules as paused. When a ring is enabled, an overdue update becomes approved during the next evaluation.

Before approval, a scheduled entry is removed when no effective endpoint in the ring reports the revision as missing or when the assigned rules do not match it. An Approved decision remains recorded until an operator changes or clears it.

Manual decisions take precedence. A manual rejection prevents a matching rule from approving that ring and revision. Editing, disabling, unassigning, or deleting a rule does not revoke approvals already created by the rule.

Automatic approval only changes the ring decision. It does not start an installation job or reboot an endpoint.

Install approved updates with a job

Use the dedicated job task for ring installations:

  1. Open Operations > Jobs.
  2. Create or edit a job.
  3. Add the Install approved Windows updates task.
  4. Optionally select classifications or products to limit this job to a subset of the ring's approved updates.
  5. Save the job.
  6. Run the job manually or configure a time automation.

When an endpoint reaches the task, Ordyn checks that:

  • the endpoint has an effective ring
  • the effective ring is enabled
  • the endpoint has no equal-precedence ring conflict

The task then requests installation of the exact Microsoft Update IDs, revisions, and update types currently approved for that endpoint's effective ring and matching the job filters. Rejected, eligible, and nonmatching approved updates are not included. Windows performs its normal applicability checks before installing software, drivers, or firmware.

Filters are inclusive. Multiple selected classifications match any selected classification, and multiple selected products match any selected product. When both filters contain values, an update must match both groups. Empty filters include all approved updates. To run a frequent Defender-only job, select Microsoft Defender Antivirus under products. Leave classifications empty to include all Defender update classifications.

While the task is running, its details list the approved updates sent to the endpoint. After Windows finishes, the details separate successfully installed updates from updates that failed to download or install. Failed entries include the Windows error code when one is available.

A successful task can report that no approved updates were applicable. This means Windows did not offer any of the requested revisions to that endpoint at execution time; it is not an installation failure. The task details show the requested, discovered, and matched update counts to make that outcome explicit.

One job can target endpoints from multiple rings. Ordyn resolves every endpoint independently, so each endpoint receives only the approvals from its own effective ring. An endpoint without an effective ring, with a disabled effective ring, or with an equal-precedence conflict fails safely without installing updates.

Approvals and jobs are independent. Changing an approval changes what a later execution can install; it does not start a job or modify an already delivered endpoint task.

See Available Tasks for the job task reference.

Reboot behavior

Automatic reboot orchestration is disabled by default. With the default setting, an update that requires a reboot remains pending until the user restarts the device or Windows completes its normal restart handling.

When automatic reboot orchestration is enabled explicitly, the job can restart after Windows reports that a reboot is required, wait for the endpoint to reconnect, check Windows Update readiness, and optionally rerun the same approved identities until clean. Enable this only for scopes where job-initiated restarts are acceptable.

Delivery Optimization and peer sharing

Windows Delivery Optimization is configured as a normal configuration profile. It is separate from update rings because it controls how Microsoft content is downloaded, not which updates are approved.

To configure peer sharing:

  1. Open Library > Configuration Profiles.
  2. Create a profile with type Windows Delivery Optimization.
  3. Select a download mode:
    • HTTP only (no peer sharing)
    • Local network peers
    • Private peer group
  4. For a private peer group, enter the peer group ID used by endpoints that may share content.
  5. Configure optional cache age, cache size, minimum cached file size, and VPN peer-sharing settings.
  6. Assign the profile to the required Windows endpoint scopes and configure remediation behavior.

Delivery Optimization profiles can be assigned independently of rings. Use the same private peer group ID on endpoints that should share content across the selected group boundary.

If Delivery Optimization is already controlled by GPO, MDM, or another provider, remediation reports an error and makes no policy changes.

See Configuration Profiles for the complete profile behavior.

Permissions

Windows Updates uses separate permissions for:

  • reading rings, assignments, endpoints, and decisions
  • managing rings
  • approving, rejecting, or clearing update decisions
  • managing reusable automatic approval rules and settings

Windows Updates: Settings manages reusable rule definitions. Windows Updates: Manage configures ring delays and rule assignments.

Creating a job also requires the normal job-design permissions. Running or scheduling the job requires the corresponding job-operation permissions for the target scope.

Creating, editing, assigning, or deleting a ring requires Windows Updates: Manage.

In the fixed-role catalog, Platform Admin has all Windows Updates management and approval permissions. A super admin bypasses normal permission checks.

Troubleshooting

The ring has no eligible updates

Check that:

  • the ring is enabled
  • the ring has intended, non-conflicted endpoints
  • those endpoints have reported update inventory
  • at least one intended endpoint reports a Microsoft update of a collected type as missing
  • or an enabled assigned automatic approval rule matches a discovered revision
  • the decision filter includes Eligible

For missing driver updates, confirm that the Collect Windows update inventory job selects the Drivers classification.

An intended endpoint is missing from the Endpoints tab

The assignment may be overridden by a more specific assignment. Equal-precedence conflicts appear under every candidate ring rather than disappearing from the tab.

Review all matching tenant, endpoint-folder, group, and endpoint ring assignments.

The job task fails because no ring is effective

The endpoint must have one enabled effective ring at execution time. Check the ring's Assignments and Endpoints tabs for a missing assignment, a disabled ring, or equal-precedence assignments to different rings.

An installed update still requires a restart

This is expected for updates that require reboot completion. Ordyn does not actively restart ring-managed endpoints.