Configure Windows Update pause behavior via Intune - ADMIN-controlled pause (maintenance windows) vs USER pause (blocked via separate policy).
Aanbeveling
CONFIGURE (admin-controlled)
Risico zonder
Low
Risk Score
3/10
Implementatie
5u (tech: 2u)
Van toepassing op:
β Windows 10 β Windows 11
Pause use cases: Admin-controlled pause: Planned maintenance window (system upgrades, testing), Major event (conference, product launch - no disruption), Emergency freeze (critical bug in update - Microsoft advisory). User pause (BLOCKED): Users pause β forget β months unpatched (security risk). This policy: Admin pause configuration (HOW to pause when needed), NOT user pause blocking (separate policy: 'block-pause-updates-ability').
PowerShell Modules Vereist
Primary API: Microsoft Graph API Connection:Connect-MgGraph Required Modules: Microsoft.Graph.DeviceManagement
Implementatie
Admin pause configuration: Maximum pause duration: 35 days (Windows 10/11 limit), Pause scope: Feature updates, quality updates, OR both, Resume: Automatic after duration OR manual (admin), Use case: Maintenance window: Pause 7 days β complete system migration β resume.
Vereisten
Intune subscription
Windows 10/11
Change management: Documented pause procedures (when/why to pause)
User pause: BLOCKED (separate policy)
Implementatie
Intune: Windows Update ring β Pause updates: Configure maximum pause duration (7-35 days). Use case: Admin initiates pause via Intune (maintenance window). User pause: Blocked via 'block-pause-updates-ability' policy.
Compliance
BIO 12.06 (Change management), ISO 27001 A.12.6.1.
Monitoring
Gebruik PowerShell-script windows-update-pause.ps1 (functie Invoke-Monitoring) β Controleren.
Remediatie
Gebruik PowerShell-script windows-update-pause.ps1 (functie Invoke-Remediation) β Herstellen.
Compliance & Frameworks
BIO: 12.06.02 -
ISO 27001:2022: A.12.6.1 -
Automation
Gebruik het onderstaande PowerShell script om deze security control te monitoren en te implementeren. Het script bevat functies voor zowel monitoring (-Monitoring) als remediation (-Remediation).