Using the different servicing channels allows you to deploy Windows "as a service," which conceives of deployment as a continual process of updates that roll out across the organization in waves. In this approach, an update is plugged into this process and while it runs, you monitor for anomalies, errors, or user impact and respond as issues arise--without interrupting the entire process. The first step of controlling when and how devices install updates is assigning them to the appropriate servicing channel.
By dividing devices into different populations "deployment groups" or "rings" you can use servicing channel assignment, followed by other management features such as update deferral policies, to create a phased deployment of any update that allows you to start with a limited pilot deployment for testing before moving to a broad deployment throughout your organization.
In the General Availability Channel, feature updates are released annually. As long as a device isn't set to defer feature updates, any device in this channel will install a feature update as soon as it's released.
If you use Windows Update for Business, the channel provides three months of additional total deployment time before being required to update to the next release. Insider preview releases are made available during the development of the features that will be shipped in the next feature update, enabling organizations to validate new features and compatibility with existing apps and infrastructure, providing feedback to Microsoft on any issues encountered.
There are actually three options within the Windows Insider Program for Business channel:. The Long-Term Servicing Channel is designed to be used only for specialized devices which typically don't run Office such as ones that control medical equipment or ATMs. Devices on this channel receive new feature releases every two to three years. The following table shows the servicing channels available to each edition. Your individual devices then connect to your server to install their updates from there.
Devices using the Insider Fast ring are somehow unstable and this channel is meant to collect feedback from the field or to test against your applications on forehand. Updates are pushed once or twice a week.
When the first feedback is collected and processed, updates are pushed to this ring. This channel gets more stable updates but can still contain bugs, which can make the device unstable. Updates are pushed once a month. Updates in this channel are almost ready for broadly roll-out. You can choose this ring to test out new features but also work on a stable device. When updates are thoroughly tested, they are being released through the public channel. However, sometimes an update is pulled back after release because of a major problem.
To be one step ahead of this, you can set the deferral period for this channel. More on that later. Quality updates defer up to 30 days. Feature updates defer up to days. The deferral period is calculated from the day the update is launched. Here you can find an overview of the Windows 10 releases. In order to use the Insider Preview in your company, you have to sign up your domain first.
After that, your users can opt-in the Insider channels, or you can configure it for them by using Intune for example. For more information, reach out to this page. It can be quite challenging to keep your devices up to date.
It also frustrates people when they cannot use their devices for a while, and sometimes after updates things just break. By creating these different rings, you can roll out an update more gradually in your organization. For example, you can select a subset of users and assign them to an Insider ring. In that case, if something goes wrong, you can fix this before it reaches the broader rings. Try to select a varied set of users, so you can test most of your applications.
This way you can thoroughly test an update before it hits the broader rings. This example illustrates a possible strategy for your update rings:. For quality updates, you can have the same strategy. Since these updates can only be deferred by 30 days, you should handle more quicker in case something goes wrong. The next chapter will discuss this further. Of course, the way of building your rings depends on what kind of organization you work with.
This example is just to give you an idea of what is possible. Stay current is not that simple. If Microsoft releases the updates, they are being offered to the clients right away. Also, you can configure your working hours, so your users are not bothered during the workday. Using WufB you are able to defer updates for a period of time. You can separately defer quality and feature updates.
You can use the same update rings as described in the previous chapter. Each ring has a different deferral period, so you can gradually roll out updates in your organization. Sometimes updates can cause unexpected problems. Also, some organizations need a change freeze during the busiest time in the year. In that case, you can pause your update rings. You can pause up to 35 days. During that period, no updates are installed on your devices. Administrators can even allow their users to pause updates individually.
Quality and feature updates can be paused separately. Windows 10 brought some significant improvements to the end-user experience. Users are being informed when a device needs a reboot for updates to install.
They can ignore this for a period of time, and they can pick a time that fits them best. Administrators can configure deadlines. The deadline forces the updates to install before the deadline expires. In the meantime, users can ignore the updates. The deadline is calculated from the day of release. In previous versions of Windows 10, the deadline was calculated from the moment the device came into the pending reboot state.
Learn more. Using WufB for your Windows 10 devices can cause a tremendous impact on your bandwidth usage. Each and every client have to download the updates individually from the Microsoft update servers in order to install them. Using Delivery Optimization, clients can share updates over the local network using peer to peer technology. Administrators can also configure how many bandwidth the devices can use for this task.
Delivery Optimization can also be used for apps that are downloaded from the Microsoft Store. Downloaded files are stored on the device for a short while and automatically cleaned up afterward. DO is builtin into Windows 10 and can be easily configured using group policies or Intune. If you design a good strategy to stay current you can spend your time monitoring the progress and intervene when needed. Approving and staging updates are a thing of the past. WUfB can be integrated with those services.
Also, many administrators have to get used to the fact that they lose some control when they hand things over to WUfB.
Using WufB can be the first step in the Modern Management approach, and that may take some time to get used to. As mentioned earlier, WUfB can be controlled in many ways. WUfB can even be configured trough registry settings directly. WUfB can help administrators to take more control over the Windows 10 by stepping back and letting WUfB doing all the work. Also good to mention, if you are going WUfB-only, on-premises infrastructure is no longer needed to deploy these updates.
WUfB has no built-in reporting or monitoring. Windows Analytics has an Update Compliance module where you can check the status of your devices. Next to that, you can use the module Upgrade Readiness. In order to use this, Windows uses default telemetry. When you are using Intune, you can make use of this cool new feature called Windows 10 feature updates Preview. With this feature, you can configure your devices to stick on specific feature release.
Peter van der Woude wrote an excellent blog post about this. Go check it out if you want to get started on that. WUfB is free to use for Windows 10 and easy to configure, without the need to invest in extra hardware.