Fix PrintNightmare via Endpoint Manager using expedite updates

Fix PrintNightmare via Endpoint Manager using expedite updates

Introduction

With the expedited updates feature in Microsoft Endpoint you can deploy updates like the most recent patch Tuesday release or out-of-band security updates.

For example, we just saw a flaw with the windows print spooler where the attacker could execute arbitrary code with SYSTEM privileges on a non-patch system.

Not all updates can be expedited as it is currently only available for Windows 10 security updates.

So why use this feature instead of my configured Windows 10 ring rollout?

You want to use this feature to speed things up. Expedite updates uses the available services, like push notification channels, which is a process to download and install updates as soon as possible, without having to wait for the device to check in for updates.

 

 

Requirements

Use Intune to expedite Windows 10 quality updates – Azure | Microsoft Docs

 

 

Create expedite patch deployment

Go to endpoint.microsoft.com

Choose Devices

 

Choose Windows 10 quality updates (Preview)

 

Create profile

 

Give it a name that you can easily find

 

 

 

 

Add groups

 

I have grouped devices into waves, so that I can test on small groups before going global

 

Create

 

Done

 

Patch report for your management

When something bad happens and your company is potentially at risk, management usually are a bit pushy on some reports. This is how you can give them what they want.

Go to endpoint.microsoft.com

 

Windows updates (preview)

 

Choose reports

 

Windows Expedited Update report (Preview)

 

Select an expedited update profile

 

Select the expedited update we created earlier

 

Generate

 

Export data and give it to the management.

 

Summary

I hope this post gave you some insight how to get around with zero-day patching and Endpoint Manager easily and quickly. It is here to ease your life as an admin in your daily job. Go try it out yourself!

Happy patching!

 

Source:

Use Intune to expedite Windows 10 quality updates – Azure | Microsoft Docs

Windows message center | Microsoft Docs

+ posts

Mattias Melkersen is a community driven and passionate modern workplace consultant with 20 years’ experience in automating software, driving adoption and technology change within the Enterprise. He lives in Denmark and works at Mindcore.

He is an Enterprise Mobility Intune MVP, Official Contributor in a LinkedIn group with 41.000 members and Microsoft 365 Enterprise Administrator Expert.

Mattias blogs, gives interview and creates a YouTube content on the channel "MSEndpointMgr" where he creates helpful content in the MEM area and interview MVP’s who showcase certain technology or topic.

Official Contributor here "Modern Endpoint Management":
https://www.linkedin.com/groups/8761296/

Table of Contents

Share this post
Search blog posts
Search
Authors
Modern Workplace consultant and a Microsoft MVP in Enterprise Mobility.

Modern Workplace consultant and a Microsoft MVP in Windows and Devices.

Infrastructure architect with focus on Modern Workplace and Microsoft 365 security.

Cloud & security specialist with focus on Microsoft backend products and cloud technologies.

Cloud & security specialist with focus on Microsoft 365.

Cloud & Security Specialist, with a passion for all things Cybersecurity

Cloud and infrastructure security specialist with background in networking.

Infrastructure architect with focus on design, implementation, migration and consolidation.

Infrastructure consultant with focus on cloud solutions in Office365 and Azure.

Modern workplace and infrastructure architect with a focus on Microsoft 365 and security.

follow us in feedly
Categories

Follow on SoMe