Appearance
Windows Updates
Windows update rings let operators approve specific Microsoft software, driver, and firmware updates for defined groups of Windows endpoints.
Open Operations > Windows Updates to manage rings and approvals.
An update ring combines three things:
- one or more direct assignments that determine the ring's endpoint scope
- an approval decision for each discovered Microsoft update revision
Approving an update does not install it immediately. Installation starts only when a job containing the Install approved Windows updates task runs against an endpoint.
Requirements and limitations
Windows update rings apply to Windows endpoints and use Microsoft Update as the update provider.
The following limitations apply:
- WSUS is not supported for ring-managed endpoints.
- Only updates offered through Windows Update are supported. Vendor tools and other update channels are outside the ring workflow.
- The endpoint must report update inventory before its missing updates can appear in a ring.
- A ring must be enabled and effective before an installation task can apply.
Use Update Inventory when you need a fleet-wide view that is not scoped to one ring.
Organize rings
The tree on the left side of the Windows Updates page contains update-ring folders and rings.
Use the Actions menu to:
- add a folder
- create an update ring
- create nested folders inside an existing ring folder
- rename or delete a ring folder
Ring folders only organize the Windows Updates tree. They do not assign the contained rings to endpoints.
An Endpoint folder assignment refers to a folder from the Endpoints area and includes endpoints in that folder and its descendant folders.
Create a ring
To create a ring:
- Open
Operations>Windows Updates. - Select
Actions>New update ring. - Enter a name and optional description.
- Select the ring folder or leave the ring at the root.
- Enter the automatic approval delay in whole days. The default is
0days. - Keep
Ring enabledselected when the ring should be eligible to control endpoints and install approved updates. - Save the ring.
A disabled ring remains available for review, but it does not install approved updates on endpoints.
Ring detail tabs
Each ring has four tabs.
Overview
The Overview tab contains the update approval table.
It shows Microsoft updates reported as missing in the ring, revisions scheduled for automatic approval, and recorded decision history. The table includes:
- update title and KB article IDs
- classification
- update type (
Software,Driver, orFirmware) - automatic or optional driver offer type
- Microsoft revision number
- number of effective endpoints reporting the update as missing
- availability (
Current,Installed, orExpired) - decision state
- last-seen time
Use the table controls to search, sort, and filter by decision state, availability, update type, and driver offer type. Current and installed revisions are shown by default. Select Expired in the availability filter to include decision history for revisions that no effective endpoint currently reports as missing or installed.
Assignments
The Assignments tab lists the tenant, endpoint-folder, endpoint-group, and endpoint scopes assigned directly to the ring. Each target links to its corresponding page.
Select Actions > Assign from the ring header to add an assignment. Select assignments with their row checkboxes, then right-click the selection to open targets or remove one or more assignments.
Rules
The Rules tab lists the reusable automatic approval rules assigned to the ring. Every assigned rule uses the ring's automatic approval delay.
Select Assign on the right side of the tab row to assign rules. To unassign rules, select them with the table checkboxes, then right-click the selection and select Unassign rule or Unassign selected. Ctrl and Shift selection are supported. Assigning a rule evaluates updates that Ordyn has already discovered as well as future update revisions.
Endpoints
The Endpoints tab lists the endpoints for which the ring is effective.
The table shows:
- endpoint and hostname
- tenant
- operating system
- ring membership status and ring assignment conflicts
- the assignment that selected the ring
- last reconciliation time
Open an endpoint row to inspect that endpoint in the Endpoints area.
Endpoints with an equal-precedence ring conflict appear under every candidate ring with a Conflict status, but they are excluded from the ring's update catalog and cannot run the approved-update installation task.
Set up an update ring workflow
The complete setup uses a Windows Update Policy profile, direct ring assignments, update inventory collection, and an installation job:
- Open
Library>Configuration Profilesand create aWindows Update Policyprofile. - Set
Automatic updates modetoDisabled. - Set
Update sourcetoMicrosoft Update / Windows Update. - Set
Windows Update user accesstoBlockedwhen users must not manually scan for, download, or install updates. This also blocks interactive access for administrators. - Configure any optional schedule or restart settings required by your organization. Ring installation itself does not restart endpoints.
- Assign the policy to the required tenant, endpoint folder, endpoint group, or endpoint scope.
- Use
Remediatebehavior when Ordyn should apply the policy. UseAudit onlywhen GPO or MDM applies the settings and Ordyn should check them. - Run or automate the Windows Update Policy as required for your environment.
- Create or edit a job with
Collect Windows update inventory. SelectMicrosoft Updateand the required classifications. SelectDriverswhen the ring should discover automatic, optional, and firmware offers from Windows Update. - Run or schedule update inventory collection for the intended endpoint scope. Driver and firmware updates cannot appear in the ring until an applicable endpoint reports them.
- Open
Operations>Windows Updates, create the ring, and configure its automatic approval delay and rules. - Open the ring's
Actionsmenu, selectAssign, and choose the required tenant, endpoint folder, endpoint group, or endpoint. - Review the ring's
AssignmentsandEndpointstabs. - Create a job containing
Install approved Windows updatesand run or schedule it for the intended endpoint scope. Each endpoint uses its own effective ring.
The Windows Update Policy and ring assignment scopes can differ. Ring membership does not inspect or enforce the Windows Update Policy.
Assign a ring
To assign a ring:
- Open
Operations>Windows Updatesand select the ring. - Select
Actions>Assign. - Select
Tenant,Folder,Group, orEndpointas the destination type. - Search for and select the destination.
- Select
Assign.
Ring assignments are declarative. They change ring membership and do not change Windows Update settings on an endpoint.
An endpoint can match several ring assignments. Ordyn selects the highest-precedence assignment using this order:
- endpoint
- endpoint group
- deepest matching endpoint folder
- tenant
An assignment at a more specific level overrides matching assignments below it. Multiple assignments at the same highest precedence can select the same ring without creating a conflict.
If assignments for different rings match at the same highest precedence, no ring becomes effective and a ring installation job fails until the conflict is resolved. A common example is an endpoint that belongs to two groups assigned to different rings.
Each tenant, folder, group, or endpoint can be assigned directly to only one ring. Assigning the same target to another ring reports a conflict; remove its existing direct assignment first.
Deleting an assigned tenant, endpoint folder, endpoint group, or endpoint also removes its direct ring assignment. Removing an assignment or deleting its target does not change Windows Update settings.
Configure Windows Update policy
Ordyn recommends an effective, compliant Windows Update Policy that:
- sets automatic updates to
Disabled - sets
Update sourcetoMicrosoft Update / Windows Update
The policy can use Remediate behavior so Ordyn applies the settings, or Audit only behavior when GPO or MDM supplies the effective values.
Ordyn's ring installation job never changes Windows Update policy. Automatic reboot orchestration is disabled by default and can be enabled explicitly in the job step.
The ring workflow installs approved updates only when its job task runs. Set Windows Update user access to Blocked in the effective Windows Update Policy when interactive users must not start Windows Update outside Ordyn. The setting applies to administrators as well as standard users.
Use Windows Update notifications in the same policy to keep the default Windows notifications, show restart warnings only, or turn off all Windows Update notifications. This setting controls notification visibility and does not change installation or restart timing.
Removing a ring assignment changes ring membership only. Manage the Windows Update Policy assignment separately when its endpoint configuration should also change.
Update grouping
Ordyn groups discoveries from different endpoints by the Microsoft Update ID and revision number. The update type remains part of each exact installation request.
This means:
- the same revision discovered on many endpoints appears once in the ring table
- the missing count shows how many non-conflicted intended endpoints currently report that revision as missing
- one approval applies that exact revision to all eligible endpoints in the ring
- a newly discovered revision requires its own decision
This prevents endpoint-specific inventory records from creating duplicate approval rows while keeping Microsoft revisions distinct.
Approve or reject updates
Each update has one of these ring-specific decision states:
Eligible: no decision has been recordedApproved: the ring installation job may install this exact revisionRejected: the ring installation job excludes this revision
Use the decision filter in the table header to include approved or rejected updates. Eligible updates include revisions currently missing from ring endpoints and revisions scheduled by an assigned automatic approval rule. An approved or rejected revision is marked Expired when no effective endpoint currently reports it as missing or installed. Expired decisions are hidden by default and remain available through the availability filter.
To update decisions:
- Select one or more rows with the checkboxes.
- Right-click the selection.
- Select
Approve,Reject, orClear decisionfrom the context menu.
You can also use the row context menu. Standard table selection is supported:
CtrlorCommandadds or removes individual rows from the selection.Shiftselects a range from the selection anchor.- The header checkbox selects or clears the loaded rows.
Clearing a decision returns the update to Eligible.
If an active automatic approval rule still matches the update, clearing its decision schedules it again. An overdue update can be approved again during the next automatic approval evaluation. Reject the update to suppress automatic approval for that ring and revision.
Decisions belong to one ring. Approving an update in one ring does not approve it in another ring.
Configure automatic approval rules
Select Automatic approvals above the update-ring tree to manage reusable matching rules.
To create a rule:
- Select
Actions>New automatic approval rule. - Enter a name and optional description.
- Select at least one classification. Select
Driversfor Windows Update driver and firmware offers. - Optionally select products or enter an
Update name containsvalue. - For driver rules, optionally select providers, manufacturers, driver classes, device models, or hardware IDs.
- Keep the rule enabled and save it.
- Open a ring's
Rulestab and assign the rule.
To preview a saved rule, right-click that rule and select Preview. The preview opens separately and lists the most recently discovered Microsoft update revisions that currently match the rule.
Classification is required. Product, classification, and driver values are selected from metadata already reported by endpoints. Matching is case-insensitive:
- an update may match any selected product
- an update may match any selected classification
- every populated matcher group must match
- values within one matcher group use OR matching
Update name containsperforms simple substring matching and does not support regular expressions- driver provider, manufacturer, class, model, and hardware ID values use exact matching
Driver applicability can differ between endpoints even when Microsoft gives the update the same ID and revision. A driver rule matches the shared update when at least one effective endpoint in the ring has one applicability record that satisfies every populated driver matcher group. The resulting approval applies that exact Microsoft update identity to all endpoints in the ring where Windows reports it as applicable.
Firmware delivered through the Windows Update driver channel is shown as Firmware. Approving it authorizes installation in the same way as any other driver. Review vendor release information and test firmware approvals in an appropriate ring before wider deployment.
The approval date is calculated from the time Ordyn first discovered the Microsoft Update ID and revision:
First discovered + ring delay = automatic approval date
For example, the same rule assigned to rings with delays of 0, 3, and 5 days schedules the exact revision immediately for the first ring, after three days for the second ring, and after five days for the third ring. Discovery on any endpoint starts the shared delay calculation. A rule is scheduled for a ring only while at least one effective endpoint in that ring reports the update as missing and satisfies its applicability matchers.
The update table shows scheduled automatic approvals with the rule name and approval date. Disabled rings show their schedules as paused. When a ring is enabled, an overdue update becomes approved during the next evaluation.
Before approval, a scheduled entry is removed when no effective endpoint in the ring reports the revision as missing or when the assigned rules do not match it. An Approved decision remains recorded until an operator changes or clears it.
Manual decisions take precedence. A manual rejection prevents a matching rule from approving that ring and revision. Editing, disabling, unassigning, or deleting a rule does not revoke approvals already created by the rule.
Automatic approval only changes the ring decision. It does not start an installation job or reboot an endpoint.
Install approved updates with a job
Use the dedicated job task for ring installations:
- Open
Operations>Jobs. - Create or edit a job.
- Add the
Install approved Windows updatestask. - Optionally select classifications or products to limit this job to a subset of the ring's approved updates.
- Save the job.
- Run the job manually or configure a time automation.
When an endpoint reaches the task, Ordyn checks that:
- the endpoint has an effective ring
- the effective ring is enabled
- the endpoint has no equal-precedence ring conflict
The task then requests installation of the exact Microsoft Update IDs, revisions, and update types currently approved for that endpoint's effective ring and matching the job filters. Rejected, eligible, and nonmatching approved updates are not included. Windows performs its normal applicability checks before installing software, drivers, or firmware.
Filters are inclusive. Multiple selected classifications match any selected classification, and multiple selected products match any selected product. When both filters contain values, an update must match both groups. Empty filters include all approved updates. To run a frequent Defender-only job, select Microsoft Defender Antivirus under products. Leave classifications empty to include all Defender update classifications.
While the task is running, its details list the approved updates sent to the endpoint. After Windows finishes, the details separate successfully installed updates from updates that failed to download or install. Failed entries include the Windows error code when one is available.
A successful task can report that no approved updates were applicable. This means Windows did not offer any of the requested revisions to that endpoint at execution time; it is not an installation failure. The task details show the requested, discovered, and matched update counts to make that outcome explicit.
One job can target endpoints from multiple rings. Ordyn resolves every endpoint independently, so each endpoint receives only the approvals from its own effective ring. An endpoint without an effective ring, with a disabled effective ring, or with an equal-precedence conflict fails safely without installing updates.
Approvals and jobs are independent. Changing an approval changes what a later execution can install; it does not start a job or modify an already delivered endpoint task.
See Available Tasks for the job task reference.
Reboot behavior
Automatic reboot orchestration is disabled by default. With the default setting, an update that requires a reboot remains pending until the user restarts the device or Windows completes its normal restart handling.
When automatic reboot orchestration is enabled explicitly, the job can restart after Windows reports that a reboot is required, wait for the endpoint to reconnect, check Windows Update readiness, and optionally rerun the same approved identities until clean. Enable this only for scopes where job-initiated restarts are acceptable.
Delivery Optimization and peer sharing
Windows Delivery Optimization is configured as a normal configuration profile. It is separate from update rings because it controls how Microsoft content is downloaded, not which updates are approved.
To configure peer sharing:
- Open
Library>Configuration Profiles. - Create a profile with type
Windows Delivery Optimization. - Select a download mode:
HTTP only (no peer sharing)Local network peersPrivate peer group
- For a private peer group, enter the peer group ID used by endpoints that may share content.
- Configure optional cache age, cache size, minimum cached file size, and VPN peer-sharing settings.
- Assign the profile to the required Windows endpoint scopes and configure remediation behavior.
Delivery Optimization profiles can be assigned independently of rings. Use the same private peer group ID on endpoints that should share content across the selected group boundary.
If Delivery Optimization is already controlled by GPO, MDM, or another provider, remediation reports an error and makes no policy changes.
See Configuration Profiles for the complete profile behavior.
Permissions
Windows Updates uses separate permissions for:
- reading rings, assignments, endpoints, and decisions
- managing rings
- approving, rejecting, or clearing update decisions
- managing reusable automatic approval rules and settings
Windows Updates: Settings manages reusable rule definitions. Windows Updates: Manage configures ring delays and rule assignments.
Creating a job also requires the normal job-design permissions. Running or scheduling the job requires the corresponding job-operation permissions for the target scope.
Creating, editing, assigning, or deleting a ring requires Windows Updates: Manage.
In the fixed-role catalog, Platform Admin has all Windows Updates management and approval permissions. A super admin bypasses normal permission checks.
Troubleshooting
The ring has no eligible updates
Check that:
- the ring is enabled
- the ring has intended, non-conflicted endpoints
- those endpoints have reported update inventory
- at least one intended endpoint reports a Microsoft update of a collected type as missing
- or an enabled assigned automatic approval rule matches a discovered revision
- the decision filter includes
Eligible
For missing driver updates, confirm that the Collect Windows update inventory job selects the Drivers classification.
An intended endpoint is missing from the Endpoints tab
The assignment may be overridden by a more specific assignment. Equal-precedence conflicts appear under every candidate ring rather than disappearing from the tab.
Review all matching tenant, endpoint-folder, group, and endpoint ring assignments.
The job task fails because no ring is effective
The endpoint must have one enabled effective ring at execution time. Check the ring's Assignments and Endpoints tabs for a missing assignment, a disabled ring, or equal-precedence assignments to different rings.
An installed update still requires a restart
This is expected for updates that require reboot completion. Ordyn does not actively restart ring-managed endpoints.