Windows 10 reached end of support on October 14, 2025. Intune can still manage Windows 10 devices, but management alone does not entitle them to post-support updates: eligible devices need Windows 10 Extended Security Updates (ESU) for qualifying security fixes. A dedicated Intune quality update policy is optional for ordinary Windows Update delivery; it is mainly useful for cloud orchestration, Autopatch workflows, policy-specific reporting, and eligible hotpatch scenarios.
What is a Windows quality update?
A quality update is a cumulative Windows servicing update that includes security fixes, reliability improvements, and other non-feature changes. Updates are generally released monthly, usually on the second Tuesday, though Microsoft can issue out-of-band updates. Installing the latest applicable cumulative update brings a device current for its installed Windows release. Microsoft’s quality update guidance describes the policy model and update types.
- Quality updates: Security, reliability, and other servicing changes.
- Feature updates: Major Windows releases or version upgrades.
- Driver updates: Hardware driver updates.
- Microsoft product updates: Updates for eligible Microsoft products.
These update types are managed through different controls. In particular, an expedite policy targets a particular eligible update, while an update ring governs Windows Update behavior such as deferrals and restart experience. Windows Update client policies provide the broader controls.
What does an Intune quality update policy do?
An Intune quality update policy provides a cloud-based orchestration surface for a quality-update deployment scenario. It works alongside update rings and other Windows Update client policies; it does not replace them. The quality policy determines the deployment scenario, while rings and client policies remain the primary controls for deferrals, pauses, deadlines, notifications, active hours, and restart behavior. Microsoft’s Intune quality update documentation explains how these policy layers work together.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errors#1 Best Overall
- 14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
Organizations may use a dedicated policy for Autopatch-managed quality updates, eligible hotpatch workflows, or policy-specific reporting. If the requirement is simply to install routine monthly updates under familiar deferral and restart rules, update rings and Windows Update client policies may be enough.
Do you need a quality update policy?
No. Devices without one can continue receiving applicable quality updates through standard Windows Update behavior, controlled by update rings and Windows Update client policies. Choose the policy model that matches the job:
| Need | Use | Why |
|---|---|---|
| Routine monthly updates with deferrals, pauses, deadlines, and restart controls | Update rings and Windows Update client policies | They govern the client-side update experience; a separate quality policy is not required. |
| Cloud-orchestrated quality deployment, dedicated reporting, or an Autopatch workflow | Quality update policy | It provides a dedicated orchestration surface for quality-update deployment. |
| Rapid deployment of one urgent, eligible update to a defined group | Expedite policy | It targets one update without changing the ongoing monthly deployment model. |
| Eligible security updates without an immediate restart | Hotpatch, if the device and update qualify | Availability depends on edition, configuration, and the specific update. |
| Windows 10 security updates after end of support | Windows 10 ESU entitlement, plus suitable deployment controls | Intune manages the device; ESU supplies the post-support security-update entitlement. |
For an urgent update, an expedite policy is not a permanent patch strategy. It applies to a selected update and does not change how future updates are deployed. Microsoft’s expedite policy guidance covers its behavior and limits.
Windows 10’s support status and ESU
Windows 10 reached end of support on October 14, 2025, and version 22H2 was its last regular feature update. Standard Windows 10 installations no longer receive normal quality updates after end of support. Microsoft says Windows 10 can remain enrolled in Intune for core management, but functionality may vary and is not guaranteed. Intune’s supported-platform guidance, Microsoft’s Windows 10 support statement, and the Windows lifecycle FAQ describe these limits.
Rank #2
- 1.1 GHz (boost up to 2.4GHz) Intel Celeron N5030 Quad-Core
- 4GB DDR4 System Memory; 128GB Solid State Drive
- 11.6" HD (1366 x 768) Multi-Touch Display
- Combo headphone/microphone jack - Noble Wedge Lock slot - HDMI; 2 USB 3.1 Gen 1
- Windows 11 Pro
Commercial organizations with eligible devices can enroll in Windows 10 ESU to receive qualifying critical and important security updates for up to three years after end of support. ESU does not provide new features or general Windows support. It is a temporary security bridge, not an extension of full Windows 10 servicing. See Microsoft’s Windows 10 ESU information for current eligibility and purchasing terms.
Choose between migration and ESU
- Upgrade to Windows 11 when the device is compatible and the organization is ready to move to supported Windows servicing. Microsoft recommends upgrading eligible PCs or replacing devices that cannot be upgraded.
- Use ESU as a transition when an application, hardware, regulatory, or operational dependency prevents immediate migration and the organization accepts the limitations of security-only updates.
- Do not treat Intune enrollment as ESU. Intune provides device management; it does not itself grant post-support Windows 10 update eligibility.
Prerequisites and supported devices
Microsoft’s current quality-update policy requirements include Intune Plan 1 and a Windows license that includes the Autopatch entitlement. Confirm the licensing assigned to the users and devices in your tenant before deployment; existing Microsoft 365 entitlements and licensing arrangements can affect what must be purchased. The policy supports Windows Pro, Pro Education, Enterprise, and Education editions. Windows Enterprise LTSC is not supported by this policy type; use update ring policies for LTSC devices. Microsoft’s policy requirements provide the current list.
Device, service, and reporting checks
- The device must be managed by Intune and Microsoft Entra joined or Microsoft Entra hybrid joined.
- Windows telemetry must be enabled at the Required minimum.
- The Microsoft Account Sign-In Assistant service,
wlidsvc, must be enabled and running. - Required Intune and Windows Update service endpoints must be reachable; Autopatch workflows may require additional endpoints.
- Enable Intune diagnostic-data access if you need the policy’s reporting.
- Keep restart behavior and user-experience settings in the appropriate update ring or Windows Update client policy.
These are policy prerequisites, not proof that a particular Windows 10 device is entitled to an update. ESU eligibility is a separate servicing entitlement.
Create and assign a quality update policy
Intune navigation and wizard labels can change. The current policy area is under the Windows updates experience in the Microsoft Intune admin center; confirm the exact labels in your tenant before documenting a click-by-click procedure.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
- 256 GB SSD of storage.
- Multitasking is easy with 16GB of RAM
- Equipped with a blazing fast Core i5 2.00 GHz processor.
- Sign in to the Microsoft Intune admin center with an account that can create device update policies.
- Open Devices, then the Windows updates area, and select Quality updates.
- Create the applicable quality update policy and configure the available deployment options for your scenario, including supported hotpatch options if relevant.
- Assign the policy to carefully scoped user or device groups. Avoid broad production assignment until eligibility, licensing, and policy interactions have been checked.
- Monitor applicability, installation, restart state, and errors. Allow devices time to check in and scan before treating a lack of immediate status change as a deployment failure.
For a staged rollout, build groups that reflect real operational differences:
- Validation: IT-owned devices and representative hardware.
- Pilot: A small cross-section of departments, hardware models, VPN users, and critical applications.
- Broad deployment: The main managed population after the pilot meets its acceptance criteria.
- Exception and remediation: Devices with known compatibility, uptime, or business-continuity constraints.
Windows Update client policies support deployment in waves and can pause quality updates for up to 35 days when a problem is discovered. Define pause ownership, approval, and resume criteria in advance. Microsoft’s Windows Update client policy guidance describes these controls.
Quality policies, update rings, and expedite policies compared
| Capability | Quality update policy | Update ring | Expedite policy |
|---|---|---|---|
| Main purpose | Cloud-orchestrated quality-update deployment | Windows Update client behavior and user experience | Accelerate one eligible update for a targeted group |
| Targets a particular update or deployment scenario | Yes, according to the selected policy model | Generally no | Yes, for a selected supported update |
| Deferrals, pauses, deadlines, active hours, notifications | Not the primary control surface | Yes | Not the ongoing control surface |
| Changes future monthly deployment behavior | Can define an ongoing or orchestrated quality deployment model | Yes, through client-side settings | No |
| Hotpatch | Supported for eligible scenarios | No | No |
Use the layers together intentionally: a quality policy can orchestrate deployment while an update ring continues to govern the restart and user experience. Inventory assigned policies and test the specific settings involved; do not assume one universal precedence rule resolves every conflict.
How expedite behaves
An expedite policy selects one supported update and can bypass applicable deferral timing for that update. The device still has to scan, evaluate applicability, communicate with Windows Update, download, install, and—when required—restart. A newer applicable update may be installed instead of the exact selected update. When a restart is required, the policy can set a restart deadline of zero, one, or two days; choose that setting with a documented business-impact plan.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #4
- EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
- 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
- RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
- ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
- LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.
There is a Windows 10-specific exception: Microsoft documents that non-security D-release expedited updates apply to Windows 11 devices. A Windows 10 device assigned such a policy is not expedited and shows an alert in reports. Check the expedite policy documentation before targeting these updates.
Hotpatch: useful, but not universally restart-free
Hotpatch can install certain qualifying security updates without an immediate device restart, but it is limited to eligible editions, configurations, and update scenarios. It should not be described as restart-free patching for every monthly update. Before using it, verify availability for the device’s Windows version and license, which update types qualify, whether a later baseline or periodic restart is required, and how offline or noncompliant devices are handled. The quality update policy documentation is the reference for supported scenarios.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Troubleshoot a policy that is not producing an update
Assignment, applicability, scan, download, installation, restart, and reporting are separate stages. Start by locating the stage where the device stopped rather than assuming that an assigned policy guarantees an immediate install.
Check eligibility and the update offer
- Confirm Windows 10 ESU entitlement if the device is seeking post-support security updates.
- Check the edition and servicing branch; Enterprise LTSC is not supported by the quality update policy type.
- Confirm the selected update applies to the device’s installed build, architecture, edition, and update state.
- Remember that a device that already has the selected update—or a newer applicable cumulative update—may not install that exact update. Expedite policies can install a newer applicable update instead.
- For Windows 10 D-release expedite assignments, check the documented limitation and report alert.
Check policy prerequisites and connectivity
- Verify Intune management, Entra join status, policy assignment, and the required Windows and Autopatch entitlements.
- Check that telemetry is at the Required minimum and that
wlidsvcis enabled and running. - Verify Windows Update and Intune endpoints are reachable from the device.
- Check whether the device has completed a scan and checked in since assignment.
Check device health, restart state, and competing controls
- Ensure the device is powered, regularly connected, charged, and has enough free disk space. Microsoft recommends at least 10 GB free, at least six hours of use per month including two continuous hours, and regular charging; these are operating recommendations, not a guarantee of installation on that schedule.
- Check whether installation is waiting on a restart and review the assigned ring’s restart deadlines, active hours, and notifications.
- Inventory update rings, Settings Catalog policies, Administrative Templates, Windows Update CSP settings, Group Policy, Configuration Manager co-management workloads, Autopatch-created policies, quality policies, expedite policies, and feature update policies. Determine which settings are intended to control the device and test conflicts at the setting and management-channel level.
- For stale reporting, check device communication, scan timing, diagnostic-data access, and administrator permissions before treating a recent assignment as a failure.
For devices that rarely connect, are blocked from service endpoints, or cannot complete scans, policy assignment alone will not make the update install. Microsoft’s Windows Update guidance covers connectivity and device-use recommendations.
Best Value
- WINDOWS 11 | STABLE PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 system, this laptop delivers stable performance for everyday computing tasks. It supports web browsing, online learning, document editing, email communication, and basic office work with optimized power efficiency, providing a practical and reliable experience for essential daily use for daily use.
- 15.6” FHD IPS DISPLAY: Features a 15.6-inch Full HD IPS display with narrow bezels, offering wider viewing angles and clearer image details compared to standard panels. The improved screen-to-body ratio enhances visual experience for study, reading, document work, and video playback, making it suitable for both productivity and entertainment use.
- 4GB DDR4 + 128GB eMMC STORAGE: Equipped with 4GB DDR4 memory and 128GB eMMC storage for everyday basics such as browsing, documents, email, and online learning platforms. The built-in TF card slot supports storage expansion up to 1TB, giving you more flexibility for files, photos, videos, and daily documents. TF card not included.
- CONNECTIVITY & PORTS: Includes 1× TF card slot, 2× USB 3.2 Gen1 ports, and 2× full-featured Type-C ports (USB 3.2 Gen1). The Type-C ports support data transfer, charging, and video output, enabling flexible connection with external devices such as monitors, storage, and peripherals for daily work and study use.
- LIGHTWEIGHT DESIGN | ONLINE COMMUNICATION: Designed with a slim, portable profile, this laptop is easy to carry for school, commuting, and travel. A built-in 1MP front camera supports online classes, video meetings, remote communication, and everyday conferencing. The 3300mAh battery works with the low-power system design to support practical daily use, while thermal optimization helps maintain quieter operation during extended tasks.
Alternatives and licensing considerations
Windows Update client policies with Intune or Group Policy
This is the lower-complexity option for ordinary update administration. Windows Update client policies can be configured through Intune MDM, Group Policy, or other management tools, and cover update offerings, deferrals, pauses, rollout waves, deadlines, and user-experience controls. Choose this approach when you do not need quality-policy orchestration, hotpatch, Autopatch workflows, or dedicated quality-policy reporting.
Windows Autopatch
Autopatch can reduce manual scheduling, approval, rollout, and safeguard administration for Windows updates, depending on tenant licensing and deployment model. It suits Microsoft-centric organizations seeking less hands-on update-ring administration; it may be unnecessary for a small estate that is comfortable managing rings directly. Confirm the tenant’s eligibility and included entitlements rather than assuming a universal standalone price.
Configuration Manager and co-management
Configuration Manager remains relevant for organizations that need traditional software distribution, on-premises control, or a gradual cloud-management transition. Microsoft’s Intune planning and licensing guidance explains how licensing can differ for co-managed and fully Intune-managed environments.
Third-party endpoint management
ManageEngine Endpoint Central advertises automated patching for Windows, Mac, Linux, and third-party applications, alongside broader endpoint-management functions. It may suit mixed-OS environments or teams seeking third-party application patching in one product. Compare it with the Microsoft-native approach using your actual license entitlements and operational requirements; no single public price comparison establishes which is less expensive for every organization.
Recommended Free Tools
Check existing Microsoft licensing before buying
Microsoft’s licensing guidance says selected advanced Intune capabilities are being distributed into Microsoft 365 E3 and E5 beginning July 2026. Entitlements depend on the specific capability and subscription, so inspect current tenant licenses before purchasing Plan 1, Plan 2, or Intune Suite. The planning guide and Intune pricing page are the appropriate references for current terms.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




