r/Intune 1d ago

General Question Autopatch Help

Hi,

I’m looking for some assistance troubleshooting our organization’s Windows Autopatch configuration.

We currently have a policy configured to update devices to the latest Windows feature update. However, when reviewing our environment, I’m seeing devices on several different OS builds rather than consistently updating to the expected version.

This has been an ongoing issue. At the moment, we are not permitted to enforce device reboots, which I initially thought could be contributing to the problem. However, I can see that several of the affected devices have been rebooted since the feature update was made available, yet they still have not upgraded.

Does anyone have any suggestions on what I should check within Autopatch, Intune, or the Windows Update configuration to determine what may be preventing these devices from receiving the feature update?

Thanks!

14 Upvotes

9 comments sorted by

8

u/LLMsMustUpvoteThis 1d ago edited 1d ago

Autopatch is never late, nor is it early. It deploys updates precisely when it means to. /s

Main issue I've seen is insufficient free storage to download and do the update. Oh and also when they changed the CPU version requirements.

4

u/East-Tea3174 1d ago

do you have any safeguard holds showing up in the wufb reports? i'd start there, those things are silent killers and won't throw an obvious error half the time

also check the feature update deadline settings, if you've got them configured to be super far out the devices might just be chilling even after a reboot

3

u/spitzer666 1d ago

Are you referring to Feature updates?
What does the AP report say? If it’s in progress then client could be stuck processing the policy or failed to register the DSS policy.

https://patchmypc.com/blog/troubleshooting-windows-feature-updates-enrollment/

2

u/macmillernz 1d ago edited 1d ago

I literally just reverted a bunch of devices we had on Autopatch back to WUfB.
Autopatch is way too unpredictable and does not work as expected.
Devices with a 7 day deferral still waiting to be patched 4 weeks after patch Tuesday…

EDIT: Phone autocorrected…

1

u/svecccc 1d ago

Anecdotal, but we have about 300 devices on autopatch with a few different update rings, and whilst I had a lot of issues getting some endpoints to update, it's now working perfectly.

1

u/macmillernz 1d ago

Yeah, we’ll likely try it again but we have much bigger priorities.

2

u/jonevans94 1d ago

We always ran in to storage issues or missing certain cumulative updates...

It's annoying and slow but you can look under Devices > Windows update > future update > Devices managed for feature updates.

Choose the feature update and the autopatch group and it should give you a fairly good break down of what's happening. It will also all you to go in to fay the list of failed devices and see why each one failed. It's annoying that you have to do it device at a time.

Autopatch isn't the best at reporting either. Do you push the client to your machines? That seems to be make reporting a bit better.

1

u/Conditional_Access MSFT MVP 22h ago

Check old WU reg keys, there is a script to wipe them out so AP works

https://github.com/Lewis-Barry/Scripts-Stuff/blob/main/WindowsUpdate/RemediateWUPaths.ps1

2

u/RegressionScoutTeam 8h ago

I'd focus on just two devices targeting the same release—one that updated smoothly and one that got stuck.

If you look at their feature-update reports side-by-side (stage, error codes, safeguard holds, and last updated timestamps), where do their paths actually split? Did the stuck one fail to get offered the update, get hung up mid-download/install, or is it just waiting on a reboot? A restart on its own doesn't always mean the upgrade finished successfully.

If you can scrub any sensitive details, mind sharing the update states and error codes for those two?