Windows Update for Business reports (WUfB Reports) gives Intune administrators cloud-based visibility into Windows update compliance, deployment progress, errors and device status. It does not install updates itself. Windows Update for Business policies, Intune update rings, feature-update policies, quality-update policies, expedite policies or Windows Autopatch still control deployment. WUfB Reports uses Windows diagnostic data stored in an Azure Log Analytics workspace, while Intune’s native Windows Update reports use Intune and Windows Update service data. Configure both when you need organization-wide telemetry plus policy-specific operational detail.
WUfB Reports and Intune Windows Update reports are different
Use the reporting surface that matches the question you are trying to answer:
| Capability | WUfB Reports | Intune Windows Update reports |
|---|---|---|
| Main location | Azure Workbook and Microsoft 365 admin center Windows tab | Intune admin center |
| Data source | Windows diagnostic data sent to Log Analytics | Intune and Windows Update service data |
| Best use | Broad quality- and feature-update compliance, trends, readiness, errors and deployment analysis | Feature-update policy states, failures, alerts and installation details |
| WUfB enrollment | Required | Not necessarily required for native feature-update reports |
| Typical refresh | Asynchronous telemetry; active devices generally appear within 72 hours to one week | Service events usually arrive in under an hour; client data refreshes in approximately eight-hour batches |
The architecture is described in Microsoft’s Windows Update for Business reports overview. Intune feature-update reporting is documented in Microsoft’s feature-update reports guide.
Prerequisites checklist
Supported devices and operating systems
- Windows 10 or Windows 11 Professional, Education, Enterprise or Enterprise multi-session.
- Microsoft Entra joined or Microsoft Entra hybrid joined. Entra registered-only (workplace-joined) devices are not supported.
- General Availability Channel devices with the February 2023 cumulative update or a later equivalent.
- At least the Required diagnostic-data level (formerly Basic). Enhanced data for Windows 10 and Optional data for Windows 11 are recommended, not mandatory.
Windows Server, Surface Hub, IoT and other non-standard desktop editions are outside this service. Microsoft lists a known issue in which Enterprise multi-session devices may not display data, even though that edition appears in the eligibility list. Insider devices can be counted, but detailed deployment insights are not currently available for them. Check the current prerequisites and limitations before a production rollout.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
- Instantly productive. Simpler, more intuitive UI and effortless navigation. New features like snap layouts help you manage multiple tasks with ease.
- Smarter collaboration. Have effective online meetings. Share content and mute/unmute right from the taskbar (1) Stay focused with intelligent noise cancelling and background blur.(2)
- Reassuringly consistent. Have confidence that your applications will work. Familiar deployment and update tools. Accelerate adoption with expanded deployment policies.
- Powerful security. Safeguard data and access anywhere with hardware-based isolation, encryption, and malware protection built in.
Azure, cloud and workspace requirements
- An Azure subscription and one Log Analytics workspace in a Microsoft-supported region.
- One tenant mapped to one WUfB Reports workspace. Mapping a tenant to multiple workspaces is unsupported.
- Commercial Azure cloud. WUfB Reports does not meet GCC requirements and is unavailable for GCC High and U.S. Department of Defense customers.
Microsoft does not charge for ingestion of WUfB Reports data. The subscription and workspace can still incur charges for other Azure Monitor or Log Analytics ingestion, retention, export or query usage. Verify the current supported-region table in Microsoft’s prerequisites documentation rather than relying on a shortened regional list.
Roles
| Task | Typical role |
|---|---|
| Enroll through the Azure Workbook | Intune Administrator, Windows Update deployment administrator or an equivalent Intune policy/profile role |
| Enroll through Microsoft 365 admin center | Intune Administrator or Windows Update deployment administrator |
| View workbook data | Log Analytics Reader or equivalent |
| Create or configure the workspace | Log Analytics Contributor or equivalent |
| Use Microsoft 365 admin center | An appropriate Microsoft Entra role |
Log Analytics Reader can view data but cannot necessarily enroll the tenant. A policy and profile manager may be able to complete Intune-related enrollment but does not automatically gain Microsoft 365 admin-center access.
Network and client services
Compare proxy, firewall, SSL-inspection and endpoint allowlists with Microsoft’s current table. Important endpoints include:
*v10c.events.data.microsoft.comumwatsonc.events.data.microsoft.comv10.vortex-win.data.microsoft.comsettings-win.data.microsoft.comadl.windows.comoca.telemetry.microsoft.comlogin.live.com
EU Data Boundary tenants may use EU-specific telemetry and Watson endpoints. DeviceCensus.exe must run regularly for much of the reporting data to be collected, the Microsoft Account Sign-in Assistant service (wlidsvc) must run, and disabling Windows services configuration (OneSettings) can cause missing or incorrect data. Satellite offices and remote devices need the same access as headquarters devices.
Free tools Windows power users keep installed
One-click scans. No signup required.
Step 1: Select or create the Log Analytics workspace
- Sign in to the Azure portal.
- Search for Log Analytics workspaces.
- Select a suitable existing workspace or choose to create one.
- Confirm its Azure subscription and Microsoft-supported region.
- Plan for a single workspace mapping for the tenant.
If the organization already uses Azure Update Management, Microsoft recommends using that workspace where appropriate. Changing the mapped workspace can leave stale data visible for approximately 24 hours, and WUfB Reports must then be configured again.
Rank #2
- STREAMLIMED AND INTUITIVE UI | Intelligent desktop | Personalize your experience for simpler efficiency | Powerful security built-in and enabled.
- JOIN YOUR BUSINESS OR SCHOOL DOMAIN for easy access to network files, servers, and printers.
- OEM IS TO BE INSTALLED ON A NEW PC WITH NO PRIOR VERSION of Windows installed and cannot be transferred to another machine.
- OEM DOES NOT PROVIDE PRODUCT SUPPORT | To acquire product with Microsoft support, obtain the full packaged “Retail” version.
Step 2: Enroll the tenant in WUfB Reports
Preferred method: Azure Workbook
- Open the Azure portal.
- Select Monitor, then Workbooks.
- Open Windows Update for Business reports.
- Select Get started.
- Choose the Azure subscription and Log Analytics workspace.
- Select Save settings.
Microsoft documents this workflow in Enable Windows Update for Business reports. Initial service setup can take up to 24 hours; a waiting-for-data message during that period is expected.
Alternative: Microsoft 365 admin center
- Open the Microsoft 365 admin center.
- Expand Health.
- Select Software updates, then the Windows tab.
- Select Configure Settings when prompted.
- Specify the Azure subscription and Log Analytics workspace.
- Save the configuration.
See the Microsoft 365 admin center software-updates guide for this route.
If enrollment returns 403 Forbidden
Check the user’s Entra, Intune, Azure and Microsoft 365 permissions. For an Intune Administrator or Windows Update deployment administrator, Microsoft specifically advises checking the Windows Update Deployment Schedule Service enterprise application and setting Assignment required to No. Its documented application ID is 61ae9cd9-7bca-458c-affc-861e2f24ba3b.
Step 3: Configure Intune devices
- In the Intune admin center, open Devices.
- Select Windows, then Configuration profiles.
- Select Create profile.
- Choose Windows 10 and later and profile type Settings catalog.
- Name the profile, for example
Windows Update for Business Reports – Required Telemetry. - Add the settings below, configure scope tags and applicability rules, and assign the profile to a pilot device group.
Required setting
| Setting | Value |
|---|---|
| Allow Telemetry | OMA-URI ./Vendor/MSFT/Policy/Config/System/AllowTelemetry; data type Integer; value 1 |
Value 1 is the minimum Required diagnostic-data level. A higher level can be used only when organizational privacy and policy requirements permit it.
Recommended settings
| Setting | OMA-URI | Type/value |
|---|---|---|
| Allow device name in Diagnostic Data | ./Vendor/MSFT/Policy/Config/System/AllowDeviceNameInDiagnosticData |
Integer, 1 |
| Configure Telemetry Opt-In Settings UX | ./Vendor/MSFT/Policy/Config/System/ConfigureTelemetryOptInSettingsUx |
Integer, 1 |
| Configure Telemetry Opt-In Change Notification | ./Vendor/MSFT/Policy/Config/System/ConfigureTelemetryOptInChangeNotification |
Integer, 1 |
Allowing device names makes per-device investigation practical but sends the name as diagnostic data. Review privacy, residency and regulatory requirements before enabling it. The two telemetry UX settings help keep user changes and prompts from undermining consistent configuration. Microsoft’s complete Intune procedure is at Configure devices using Microsoft Intune.
Rank #3
- WINDOWS 11 PRO FOR WORKSTATIONS is for people with advanced needs such as data scientists, CAD professionals, researchers, media production teams, graphic designers, and animators.
- WINDOWS 11 PRO FOR WORKSTATIONS helps power through advanced workloads while providing server-grade data protection and performance, and includes all the features of Windows 11 Pro | Users will benefit from greater speed with faster processing and file transfers, greater resilience with server-grade storage, and the full power of high-performance hardware configurations.
- OEM IS TO BE INSTALLED ON A NEW PC with no prior version of Windows installed and cannot be transferred to another machine | Windows 11 Pro for Workstations is required licensing for systems with Intel Xeon or AMD Opteron processors.
- OEM DOES NOT PROVIDE SUPPORT | To acquire product with Microsoft support, obtain the full packaged “Retail” version.
Step 4: Optionally deploy Microsoft’s configuration script
The script is optional when Settings Catalog is used. It can configure registry-backed policy, check required services and test connectivity to required endpoints, making it useful for a pilot or a missing-device investigation.
- Deploy it to a small pilot group.
- Review device-side results and correct policy, service or network failures.
- If required, package it as a Win32 app for broader deployment.
- Save logs to a location administrators can retrieve.
Win32 deployment logs are not automatically available to administrators unless the deployment process saves them to a shared location or someone can access the device. The script cannot override Group Policy or a later MDM assignment. Read Microsoft’s configuration-script guidance before packaging it.
Step 5: Verify enrollment and view reports
Azure Workbook
Use the workbook for the broadest WUfB view: overall compliance, quality- and feature-update status, deployment progress, readiness, trends, errors, at-risk devices and drill-down lists. It is telemetry-backed, not a real-time console.
Microsoft 365 admin center
Open Health → Software updates → Windows for a simpler view of cumulative-update and feature-update compliance sourced from WUfB Reports.
Intune feature-update report
- Open the Intune admin center.
- Select Reports, then Windows Updates.
- Open Windows Feature Update Report.
- Select the feature-update profile and Generate report.
- Filter by update status, ownership or available columns.
Columns can include device name, UPN, Intune device ID, Microsoft Entra device ID, last event time, update state, update substate and aggregated status.
Rank #4
- MICROSOFT WINDOWS 11 PRO (INGLES) FPP 64-BIT ENG INTL USB FLASH DRIVE
Understand reporting delays
- Initial WUfB Reports service setup: up to 24 hours.
- Active, daily-connected devices: commonly under 72 hours and generally within one week.
- Less-active devices: potentially up to two weeks.
- Intune service-side feature-update events: typically under one hour.
- Intune client-based feature-update data: approximately eight-hour processing batches after collection is configured.
An Intune sync does not guarantee immediate appearance. Enrollment, policy processing, device activity, diagnostic upload, endpoint connectivity and backend processing all affect visibility.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Troubleshoot missing or incorrect data
No devices appear
- Confirm tenant enrollment and the selected workspace.
- Verify Entra joined or hybrid joined status rather than registered-only status.
- Confirm supported edition and the February 2023-or-later servicing baseline.
- Check that Allow Telemetry is at least Required.
- Enable Allow device name in Diagnostic Data if names are expected.
- Test telemetry, Windows Update and identity endpoint access.
- Check
DeviceCensus.exe,wlidsvcand OneSettings-related configuration. - Allow the documented activity and processing window.
- Inspect Group Policy, co-management, security baselines, custom OMA-URI profiles and other configuration tools for overwrites.
- Account for the Enterprise multi-session known issue.
Devices appear without names
Deploy ./Vendor/MSFT/Policy/Config/System/AllowDeviceNameInDiagnosticData as Integer value 1, or use the Microsoft script. Existing records may not become immediately identifiable until new telemetry is processed.
Data is delayed
Check uptime, internet activity, endpoint access, diagnostic policy, service health and whether you are waiting for a service-based or client-based report. Do not recreate the workspace or redeploy every policy before the documented interval has elapsed.
Data changes after a workspace switch
Microsoft documents approximately 24 hours of stale data after changing workspaces. Configure WUfB Reports again for the new workspace.
The script succeeds but the device is absent
A successful local script run proves only that local checks and settings completed. It does not prove that telemetry reached Microsoft, device identity was accepted, a conflicting policy stayed away, or the report backend processed the upload.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteBest Value
- Windows 11Pro for Workstations
Which tool should handle each patching question?
| Need | Best fit |
|---|---|
| Microsoft Windows cumulative- and feature-update telemetry | WUfB Reports |
| Feature-update policy state and Intune operational failures | Intune Windows Update reports |
| Install and schedule Microsoft updates | Intune update rings, feature/quality policies, expedite policies, Windows Autopatch or another deployment policy |
| Third-party application patching | A separate application-management or patching platform |
| Windows Server, macOS, Linux or broader cross-platform patching | A platform designed for those operating systems |
WUfB Reports does not patch Chrome, Adobe Reader, Zoom, Java or other third-party applications. Organizations needing that scope can evaluate products such as Patch My PC or Action1; those are broader patch-management services, not replacements for Microsoft’s native Windows telemetry.
Frequently Asked Questions
Is WUfB Reports included with Intune?
WUfB Reports is a separate Azure-hosted reporting service. Intune can configure the clients, but the tenant still needs an Azure subscription, Log Analytics workspace and WUfB enrollment.
Does WUfB Reports install updates?
No. It reports Windows update status and telemetry. Update rings, feature- and quality-update policies, expedite policies, Windows Autopatch or another deployment mechanism install updates.
Are WUfB Reports ingestion charges applied?
Microsoft states that ingestion of WUfB Reports data is not charged. Other Log Analytics or Azure Monitor data and features can still be billable.
Can Entra registered devices or Windows Server use this service?
No. Registered-only devices and Windows Server are unsupported for WUfB Reports.
Do I have to deploy the configuration script?
No. Microsoft supports an Intune Settings Catalog configuration. The script is optional and is most useful for local service, registry and connectivity validation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




