Fix PrintNightmare via Endpoint Manager using expedite updates

Fix PrintNightmare via Endpoint Manager using expedite updates

Introduction

With the expedited updates feature in Microsoft Endpoint you can deploy updates like the most recent patch Tuesday release or out-of-band security updates.

For example, we just saw a flaw with the windows print spooler where the attacker could execute arbitrary code with SYSTEM privileges on a non-patch system.

Not all updates can be expedited as it is currently only available for Windows 10 security updates.

So why use this feature instead of my configured Windows 10 ring rollout?

You want to use this feature to speed things up. Expedite updates uses the available services, like push notification channels, which is a process to download and install updates as soon as possible, without having to wait for the device to check in for updates.

Requirements

Use Intune to expedite Windows 10 quality updates – Azure | Microsoft Docs

Create expedite patch deployment

Go to endpoint.microsoft.com

Choose Devices

clip_image002

 

Choose Windows 10 quality updates (Preview)

clip_image004

 

Create profile

clip_image006

 

Give it a name that you can easily find

clip_image008

 

Add groups

clip_image010

 

I have grouped devices into waves, so that I can test on small groups before going global

clip_image012

 

Create

clip_image014

 

Done

clip_image016

Patch report for your management

When something bad happens and your company is potentially at risk, management usually are a bit pushy on some reports. This is how you can give them what they want.

Go to endpoint.microsoft.com

clip_image018

 

Windows updates (preview)

clip_image020

 

Choose reports

clip_image022

 

Windows Expedited Update report (Preview)

clip_image024

 

Select an expedited update profile

clip_image026

 

Select the expedited update we created earlier

clip_image028

 

Generate

clip_image030

 

Export data and give it to the management.

clip_image032

Summary

I hope this post gave you some insight how to get around with zero-day patching and Endpoint Manager easily and quickly. It is here to ease your life as an admin in your daily job. Go try it out yourself!

Happy patching!

 

Source:

Use Intune to expedite Windows 10 quality updates – Azure | Microsoft Docs

Windows message center | Microsoft Docs

Table of Contents

Share this post
Search blog posts
Search
Authors
Modern Workplace consultant and a Microsoft MVP in Enterprise Mobility.
Modern Workplace consultant and a Microsoft MVP in Windows and Devices for IT.

Infrastructure architect with focus on Modern Workplace and Microsoft 365 security.

Cloud & security specialist with focus on Microsoft backend products and cloud technologies.

Cloud & Security Specialist, with a passion for all things Cybersecurity

Cloud and infrastructure security specialist with background in networking.

Infrastructure architect with focus on design, implementation, migration and consolidation.

Infrastructure consultant with focus on cloud solutions in Office365 and Azure.

follow us in feedly
Categories

Follow on SoMe