Windows Update Drivers Management in Intune

Поділитися
Вставка
  • Опубліковано 6 сер 2024
  • We go through how to manage Windows Update Drivers and approve the drivers that get installed.
    New Intune feature since July 2023, we approve two drivers for a Dell model and set a date when those can be installed.
    We speak about the requirements for Driver Reports in Intune.
    Links:
    learn.microsoft.com/en-us/mem...

КОМЕНТАРІ • 37

  • @lynetteberg4807
    @lynetteberg4807 7 місяців тому +1

    Imagine my surprise when i'm looking for a video to go over windows update drivers and you are there .....SUPER VIDEO. So glad its you JBN

  • @Inoxtag944
    @Inoxtag944 Рік тому +5

    It s very good !
    It s Best vidéos ever ! ❤

  • @rashkaViking
    @rashkaViking Рік тому +1

    Jag och min kollega pratade om detta härom dagen och du gjorde en bra film igen as usual. Tack för dina fina tutorials

    • @IntuneVitaDoctrina
      @IntuneVitaDoctrina  Рік тому +1

      Tack så mycket Abdirashid, tack för kommentaren. Nästa film som är inspelad men inte redigerad är att köra Remediation skrips on demand.

    • @rashkaViking
      @rashkaViking Рік тому +1

      @@IntuneVitaDoctrina Can't wait!

  • @yuni1401
    @yuni1401 Рік тому +1

    Informative video, as usual. Kindly start a new series for Windows Autopatch.

    • @IntuneVitaDoctrina
      @IntuneVitaDoctrina  Рік тому

      Thank you so much, yes Windows Autopatch deserves it's own video, and since I got 4 devices enrolled, it could maybe work at least to show the concept. I put that on the list of videos, thanks!

    • @yuni1401
      @yuni1401 Рік тому +1

      @@IntuneVitaDoctrina Thank you. Looking forward to learning the Autopatch from your videos. : )

  • @TanuchiSacin
    @TanuchiSacin 7 місяців тому +1

    Thanks for the videos, great content! One question; if I create an Intune Driver policy and set everything for review (nothing approved), and PCs belong to a ring allowing Windows drivers. Does this mean the driver's manual update is blocked? I am experiencing some PCs issues, where a printer's new driver is not working.

    • @IntuneVitaDoctrina
      @IntuneVitaDoctrina  7 місяців тому +1

      thanks, and an excellent question.
      The Driver Policy will override, so it should not get printer driver unless you approve it.
      Please test to verify that it is the case, but according to how it should work that is the idea.
      I was in a similar siltation, but with an audio driver, so approved all except audio driver, now that is fixed and put back to approve them also.

  • @charlymateo8668
    @charlymateo8668 Рік тому +2

    Muchas gracias por compartir

  • @asshollff
    @asshollff 8 місяців тому +1

    Awesome video!
    Quick question, does intune detect a model name from the name of the driver policy?
    How does it know what drivers to look for?

    • @IntuneVitaDoctrina
      @IntuneVitaDoctrina  8 місяців тому

      good question, in my video I manually approved so I chose drivers, but you could allow all and let the system apply those that match. Intune does know which models you got (well targeting) so it can filter by day. Even if you target devices not using the driver it will not install so there is a lot behind the scene going on there.

    • @asshollff
      @asshollff 8 місяців тому +1

      @@IntuneVitaDoctrina so just making sure, if I approve them all, it will only install the latest ones relevent to the device?

    • @IntuneVitaDoctrina
      @IntuneVitaDoctrina  8 місяців тому

      correct, you can target one device to verify you get the result you want before you expand

  • @sXRaider91
    @sXRaider91 Рік тому +2

    Great video! We have configured everything and drivers are found for the model we are testing on. Only thing is, the updates don't seem to come trough. We initially thought it was because via GPO (Hybrid Devices) we had WSUS configured for Driver Updates and changed it to Windows Update, but still, no movement after hours. Anyone has any idea?

    • @WienerWithAD
      @WienerWithAD Рік тому +2

      Having the same exact experience as you. I have yet to find a fix.

    • @IntuneVitaDoctrina
      @IntuneVitaDoctrina  Рік тому

      Does it work for AAD joined devices but not Hybrid?
      Normally MDM win over GPO, but as a test on one of these devices could you delete in registry everything under:
      HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\WindowsUpdate
      Then restart the Windows Update service and then check for updates and see if anything different.
      Requirements from: learn.microsoft.com/en-us/mem/intune/protect/windows-driver-updates-overview
      Devices must:
      Run a version of Windows 10/11 that remains in support.
      Be enrolled in Intune MDM and be Hybrid AD joined or Azure AD joined.
      Have Telemetry turned on, with a minimum setting of Required.
      Configure Telemetry as part of a Device Restriction policy for Windows 10/11. In the device restriction profile, under Reporting and Telemetry, configure Share usage data to use a minimum value of Required. Required is the default value. Values of Enhanced (1903 and earlier) or Optional are also supported. Devices with a value of None don't report the data that is required for driver updates policies.
      The Microsoft Account Sign-In Assistant (wlidsvc) must be able to run. If the service is blocked or set to Disabled, it fails to receive the update. For more information, see Feature updates aren't being offered while other updates are. By default, the service is set to Manual (Trigger Start), which allows it to run when needed.

    • @WienerWithAD
      @WienerWithAD Рік тому

      @@IntuneVitaDoctrina Funny enough, after having these settings set for over a month, my groups randomly pulled the drivers today. I work for a school district and teachers came back this week so maybe there is some correlation there with these devices being in use after a while of being turned off? Regardless, thank you!

  • @olegproscurchin8200
    @olegproscurchin8200 Рік тому +1

    Great thanks. Does this apply for all Intune managed devices including WUfB, Autopatch, Autopilot…?

    • @IntuneVitaDoctrina
      @IntuneVitaDoctrina  Рік тому +1

      Good question, yes for WUfB and Autopilot, would assume Autopatch also but need to verify that first.

    • @olegproscurchin8200
      @olegproscurchin8200 Рік тому +1

      May not actually. Found this under a post relater to driver management: “Windows Autopatch automatically creates driver policies that allow you to roll out drivers and firmware across your deployment rings (unless you opt out of the service), with more granular controls coming later this year”

    • @IntuneVitaDoctrina
      @IntuneVitaDoctrina  Рік тому

      that seems to be the answer, thanks! I would had guessed that Driver management "won" but in the case of Autopatch if you don't opt out that doesn't seems to be the case

  • @sunilpal7933
    @sunilpal7933 Рік тому +1

    If we have selected driver update in update ring and if we create driver update ring will it create any conflict or we have to disable windows driver from update ring policy.

    • @IntuneVitaDoctrina
      @IntuneVitaDoctrina  Рік тому +1

      Very good question, one I had to ask myself.
      According to Microsoft (and therefor the correct answer) you need a Windows Update policy that allow drivers in order to manage drivers. So please do NOT disable Windows Driver from Update Ring.
      From link: learn.microsoft.com/en-us/mem/intune/protect/windows-driver-updates-policy
      "Windows update ring policy: Ensure the Windows driver setting is set to Allow."

    • @sunilpal7933
      @sunilpal7933 Рік тому +1

      @@IntuneVitaDoctrina Thanks for response.

  • @gabeintothe1106
    @gabeintothe1106 4 місяці тому +1

    What about an automatic scan of all device models in the tenant and then create a driver update policy and a group for each model: copilot, you there ?

    • @IntuneVitaDoctrina
      @IntuneVitaDoctrina  4 місяці тому +1

      Great idea, maybe a better idea to execute it but one that comes to mind is to have a PowerShell script run once a day and update EntraID groups based on model found through MS GRaph, that is also a good video idea :)

    • @gabeintothe1106
      @gabeintothe1106 4 місяці тому +1

      @@IntuneVitaDoctrina it'd save my life: waiting for another of your great videos!

    • @IntuneVitaDoctrina
      @IntuneVitaDoctrina  3 місяці тому

      If you just want a group for Model, we don't need a Script, that we can fix by Dynamic EntraID groups that reads those values and add devices, so shouldn't be too hard to implement

    • @gabeintothe1106
      @gabeintothe1106 3 місяці тому +1

      @@IntuneVitaDoctrina we should create groups and dynamic rules via powershell though

    • @IntuneVitaDoctrina
      @IntuneVitaDoctrina  3 місяці тому

      oh yes, I'm planning my next video and it will be to run PowerShell script, calling MS Graph API and add devices based on Department value of the owner (Sales, HR etc..)

  • @Pilami_
    @Pilami_ Рік тому +1

    Ska kolla! 👍

    • @IntuneVitaDoctrina
      @IntuneVitaDoctrina  Рік тому

      Tackar, relativt enkel video men visar lite vad man kan göra.