{"id":737,"date":"2023-01-15T10:52:03","date_gmt":"2023-01-15T09:52:03","guid":{"rendered":"https:\/\/mortenknudsen.net\/?p=737"},"modified":"2023-03-18T10:01:48","modified_gmt":"2023-03-18T09:01:48","slug":"how-to-manage-the-gradual-rollout-process-for-microsoft-defender-updates","status":"publish","type":"post","link":"https:\/\/mortenknudsen.net\/?p=737","title":{"rendered":"How to implement a gradual (ring) rollout-process for Microsoft Defender updates"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">It is important to ensure that your security posture systems are up-to-date to be able to prevent attacks. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft Defender Antivirus and Defender for Endpoint includes several components which must be kept updated to protect us:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Endpoint Detection &amp; Response<\/li>\n\n\n\n<li>Next-generation protection&nbsp;with&nbsp;cloud-delivered protection<\/li>\n\n\n\n<li>Attack Surface Reduction<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The updates come out in 2 release cycles: <strong>monthly engine\/platform updates<\/strong> and <strong>daily security intelligence updates<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-table has-small-font-size\"><table><tbody><tr><td><strong>Update type<\/strong><\/td><td><strong>Description<\/strong><\/td><td><strong>Release cycle<\/strong><\/td><td><strong>Deployment<\/strong><\/td><\/tr><tr><td>Security intelligence updates<\/td><td>Contains new and updated malware detections.<\/td><td>Multiple times a day<\/td><td>Deployed using KB2267602 through the Microsoft update channels. <\/td><\/tr><tr><td>Engine updates<\/td><td>Contains update to the core detection engine<\/td><td>Monthly<\/td><td>Deployed as part of the security intelligence updates<\/td><\/tr><tr><td>Platform updates<\/td><td>Updates to the product itself. It can contain new features as well as fixes for existing ones.<\/td><td>Monthly<\/td><td>Deployed using KB4052623 through the Microsoft update channels. <\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I will cover both <strong>how the process is<\/strong> and <strong>how to manage it with a gradual release process<\/strong> in this blog. We do this process to <strong>reduce risks<\/strong> while<strong> still getting computers updated <\/strong>as <strong>fast as possible<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Big thanks to <strong>Paul Huijbregts<\/strong>, Microsoft for helping with the insight and managing the ADMX files mentioned later in the blog. He is also author of several articles covering this, where I try to bring things together from <a href=\"https:\/\/learn.microsoft.com\/en-us\/microsoft-365\/security\/defender-endpoint\/manage-gradual-rollout\" target=\"_blank\" rel=\"noreferrer noopener\">various articles<\/a> into this blog.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Big credits also to <strong>Cloudbrothers<\/strong> covering this topic earlier. I have used a few info from their great article. More info <a href=\"https:\/\/cloudbrothers.info\/en\/gradual-rollout-process-microsoft-defender\/\" target=\"_blank\" rel=\"noreferrer noopener\">here<\/a><\/p>\n\n\n\n<h1 class=\"wp-block-heading\"><br>Understanding the Monthly engine\/platform updates<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">In most cases, the recommended configuration when using Windows Update is to allow endpoints to receive and apply monthly Defender updates as they arrive. This provides the best balance between protection and possible impact associated with the changes they can introduce. But sometimes updates slips through causing issues (luckily this is very rare). <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you want to minimize the impact of issues, you can consider using a gradual (ring) rollout strategy provided by Microsoft. This process helps to enable early failure detection to catch impact as it occurs and address it quickly before a larger rollout; in short \u2018minimizing risc of causing incompatibility.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can think of the rollout as rings, where Microsoft will deploy to ring 0, ring 1, ring 2, etc.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The phases (or &#8220;rings&#8221;) are shown below:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>The first release goes out to <strong>Beta channel<\/strong> subscribers.<\/li>\n\n\n\n<li>After validation, feedback, and fixes, Microsoft start the gradual rollout process in a throttled way and to <strong>Preview channel<\/strong> subscribers first.<\/li>\n\n\n\n<li>Microsoft then proceed to release the update to the rest of the global population, scaling out from 10-100% (<strong>Staged -&gt; Broad<\/strong>)<\/li>\n\n\n\n<li>Lastly the <strong>Critical: Time <\/strong>delay will be updated<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft are continuously monitoring impact and escalate any issues to create a fix as needed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h1 class=\"wp-block-heading\">Update channels for Monthly Updates<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">You can assign a machine to an update channel to define the phase (or &#8220;ring&#8221;) in which a machine receives monthly engine and platform updates.<\/p>\n\n\n\n<figure class=\"wp-block-table has-small-font-size\"><table><tbody><tr><td>Channel name<\/td><td><strong>Description<\/strong><\/td><td><strong>Application<\/strong><\/td><\/tr><tr><td>Beta Channel &#8211; Prerelease<\/td><td>Test updates before others<\/td><td>Devices set to this channel will be the first to receive new monthly updates. Select Beta Channel to participate in identifying and reporting issues to Microsoft. Devices in the Windows Insider Program are subscribed to this channel by default. For use in test environments only.<\/td><\/tr><tr><td>Current Channel (Preview)<\/td><td>Get Current Channel updates&nbsp;<strong>earlier<\/strong>&nbsp;during gradual release<\/td><td>Devices set to this channel will be offered updates earliest during the gradual release cycle. Suggested for pre-production\/validation environments.<br><br>Recommendation<br>When planning for your own gradual release, please make sure to always have a few devices subscribed to the preview and staged channels. Then you can test on a few machines &#8211; and give feedback back in case of issues.<\/td><\/tr><tr><td>Current Channel (Staged)<\/td><td>Get Current Channel updates later during gradual release<\/td><td>Devices will be offered updates later during the gradual release cycle. Suggested to apply to a small, representative part of your device population (~10%).<\/td><\/tr><tr><td>Current Channel (Broad)<\/td><td>Get updates at the end of gradual release<\/td><td>Devices will be offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in your production population (~10-100%).<\/td><\/tr><tr><td>Critical: Time Delay<\/td><td>Delay Defender updates<\/td><td>Devices will be offered updates with a 48-hour delay. Best for datacenter machines that only receive limited updates. Suggested for critical environments only.<\/td><\/tr><tr><td>(default)<\/td><td><\/td><td><br>If you disable or do not configure this policy, the device will remain in Current Channel (Default): Stay up to date automatically during the gradual release cycle. Suitable for most devices.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h1 class=\"wp-block-heading\">Update channels for Daily Updates<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Daily updates are being released multiple times a day. This is also why some of your machines can be on different levels\/version. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you want to see the latest available version, it can be done through REST api. <\/p>\n\n\n\n<pre class=\"wp-block-code has-small-font-size\"><code>Invoke-RestMethod -Uri \"https:\/\/www.microsoft.com\/security\/encyclopedia\/adlpackages.aspx?action=info\" | Select -ExpandProperty versions<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Note that unlike the monthly process, there is no Beta channel in the daily signature update process.<\/p>\n\n\n\n<figure class=\"wp-block-table has-small-font-size\"><table><tbody><tr><td>Channel name<\/td><td><strong>Description<\/strong><\/td><td><br>Application<\/td><\/tr><tr><td>Current Channel (Staged)<\/td><td>Get Current Channel updates later during gradual release<\/td><td>Devices will be offered updates later during the gradual release cycle. Suggested to apply to a small, representative part of your device population (~10%).<\/td><\/tr><tr><td>Current Channel (Broad)<\/td><td>Get updates at the end of gradual release<\/td><td>Devices will be offered updates after the gradual release cycle. Best for datacenter machines that only receive limited updates. <br><br>Note: this setting applies to all Defender updates.<\/td><\/tr><tr><td>(default)<\/td><td><\/td><td><br>If you disable or do not configure this policy, the device will remain in Current Channel (Default): Stay up to date automatically during the gradual release cycle. Suitable for most devices<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">In case you wish to force an update to the newest signature instead of leveraging the time delay, you will need to remove this policy first &#8211; or force an update using powershell (Update-MpSignature), Microsoft Defender for Endpoint or Endpoint Manager.<\/p>\n<\/blockquote>\n\n\n\n<h1 class=\"wp-block-heading\">Update Recommendations<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">For environments where there is a need for a more controlled gradual rollout of automatic Defender updates, consider an approach making target groups with machines covering the below groups:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Participate in the Windows Insider program, if you want to be on the edge of testing<\/li>\n\n\n\n<li>Get a few machines in the Beta Channel. I would go with 5 computers in IT.<\/li>\n\n\n\n<li>Designate a pilot group that get in the Preview Channel, typically from different departments using different apps. I would go with 25 computers.<\/li>\n\n\n\n<li>Designate a group of machines that receive updates later during the gradual rollout from Staged channel. Typically, this would be a representative ~10% of the machines.<\/li>\n\n\n\n<li>Most of the remaining machines go into the Broad &gt;70-80%<\/li>\n\n\n\n<li>For the remaining computers in the critical ring, they will be updated lastly. This can for example be critical production computers<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h1 class=\"wp-block-heading\">How to implement Defender Antivirus gradual release rollout?<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">To create your own custom gradual rollout process for updates, I have chosen to cover the following tools in my blog:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Group policy<\/li>\n\n\n\n<li>Microsoft Endpoint Manager<\/li>\n\n\n\n<li>PowerShell<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For machines receiving updates through, for example, Windows Server Update Services (WSUS) or Microsoft Endpoint Configuration Manager (MECM), more options are available to all Windows updates, including options for Microsoft Defender for Endpoint.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Read more about how to use a solution like WSUS, MECM to manage the distribution and application of updates at&nbsp;<a href=\"https:\/\/learn.microsoft.com\/en-us\/microsoft-365\/security\/defender-endpoint\/manage-updates-baselines-microsoft-defender-antivirus?view=o365-worldwide#product-updates\" target=\"_blank\" rel=\"noreferrer noopener\">Manage Microsoft Defender Antivirus updates and apply baselines &#8211; Windows security<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Group Policy<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">You can use&nbsp;<a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/srvnodes\/group-policy?redirectedfrom=MSDN\">Group Policy<\/a>&nbsp;to configure and manage Microsoft Defender Antivirus on your endpoints.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Download the most current ADMX\/ADML files and put them into your Sysvol\\PolicyDefinitions. The latest file can be found <a href=\"https:\/\/github.com\/KnudsenMorten\/defender-updatecontrols\" target=\"_blank\" rel=\"noreferrer noopener\">here<\/a> (forked from Microsoft)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In general, you can use the following procedure to configure or change Microsoft Defender Antivirus group policy settings:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>On your Group Policy management machine, open the&nbsp;<strong>Group Policy Management Console<\/strong>, right-click the&nbsp;<strong>Group Policy Object<\/strong>&nbsp;(GPO) you want to configure and click&nbsp;<strong>Edit<\/strong>.<\/li>\n\n\n\n<li>Using the Group Policy Management Editor go to&nbsp;<strong>Computer configuration<\/strong>.<\/li>\n\n\n\n<li>Click&nbsp;<strong>Administrative templates<\/strong>.<\/li>\n\n\n\n<li>Expand the tree to&nbsp;<strong>Windows components &gt; Microsoft Defender Antivirus<\/strong>.<\/li>\n\n\n\n<li>Expand the section (referred to as&nbsp;<strong>Location<\/strong>&nbsp;in the table below in this topic) that contains the setting you want to configure, double-click the setting to open it, and make configuration changes.<\/li>\n<\/ol>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"938\" height=\"152\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/av1.jpg\" alt=\"\" class=\"wp-image-739\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/av1.jpg 938w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/av1-300x49.jpg 300w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/av1-768x124.jpg 768w\" sizes=\"auto, (max-width: 938px) 100vw, 938px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"711\" height=\"662\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/av2.jpg\" alt=\"\" class=\"wp-image-740\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/av2.jpg 711w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/av2-300x279.jpg 300w\" sizes=\"auto, (max-width: 711px) 100vw, 711px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<figure class=\"wp-block-table has-small-font-size\"><table><tbody><tr><td><strong>Setting title<\/strong><\/td><td><strong>Description<\/strong><\/td><td>GPO <strong>Location<\/strong><\/td><\/tr><tr><td>Select gradual Microsoft Defender monthly platform update rollout channel<\/td><td>Enable this policy to specify when devices receive Microsoft Defender platform updates during the monthly gradual rollout.<br><br>Beta Channel: Devices set to this channel will be the first to receive new updates. Select Beta Channel to participate in identifying and reporting issues to Microsoft. Devices in the Windows Insider Program are subscribed to this channel by default. For use in (manual) test environments only and a limited number of devices.<br><br>Current Channel (Preview): Devices set to this channel will be offered updates earliest during the monthly gradual release cycle. Suggested for pre-production\/validation environments.<br><br>Current Channel (Staged): Devices will be offered updates after the monthly gradual release cycle. Suggested to apply to a small, representative part of your production population (~10%).<br><br>Current Channel (Broad): Devices will be offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in your production population (~10-100%).<br><br>Critical- Time Delay: Devices will be offered updates with a 48-hour delay. Suggested for critical environments only.<br><br>If you disable or do not configure this policy, the device will stay up to date automatically during the gradual release cycle. Suitable for most devices.<\/td><td>Windows Components\\Microsoft Defender Antivirus<\/td><\/tr><tr><td>Select gradual Microsoft Defender monthly engine update rollout channel<\/td><td>Enable this policy to specify when devices receive Microsoft Defender engine updates during the monthly gradual rollout.<br><br>Beta Channel: Devices set to this channel will be the first to receive new updates. Select Beta Channel to participate in identifying and reporting issues to Microsoft. Devices in the Windows Insider Program are subscribed to this channel by default. For use in (manual) test environments only and a limited number of devices.<br><br>Current Channel (Preview): Devices set to this channel will be offered updates earliest during the monthly gradual release cycle. Suggested for pre-production\/validation environments.<br><br>Current Channel (Staged): Devices will be offered updates after the monthly gradual release cycle. Suggested to apply to a small, representative part of your production population (~10%).<br><br>Current Channel (Broad): Devices will be offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in your production population (~10-100%).<br><br>Critical- Time Delay: Devices will be offered updates with a 48-hour delay. Suggested for critical environments only.<br><br>If you disable or do not configure this policy, the device will stay up to date automatically during the gradual release cycle. Suitable for most devices.<\/td><td>Windows Components\\Microsoft Defender Antivirus<\/td><\/tr><tr><td>Select gradual Microsoft Defender daily security intelligence updates rollout channel<\/td><td>Enable this policy to specify when devices receive Microsoft Defender security intelligence updates during the daily gradual rollout.<br><br>Current Channel (Staged): Devices will be offered updates after the release cycle. Suggested to apply to a small, representative part of production population (~10%).<br><br>Current Channel (Broad): Devices will be offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in your production population (~10-100%).<br><br>If you disable or do not configure this policy, the device will stay up to date automatically during the daily release cycle. Suitable for most devices.<\/td><td>Windows Components\\Microsoft Defender Antivirus<\/td><\/tr><tr><td>Disable gradual rollout of Microsoft Defender updates<\/td><td>Enable this policy to disable gradual rollout of Defender updates.<br><br>Current Channel (Broad): Devices set to this channel will be offered updates last during the gradual release cycle. Best for datacenter machines that only receive limited updates.<br><br>Note: This setting applies to both monthly as well as daily Defender updates and will override any previously configured channel selections for platform and engine updates.<br><br>If you disable or do not configure this policy, the device will remain in Current Channel (Default) unless specified otherwise in specific channels for platform and engine updates. Stay up to date automatically during the gradual release cycle. Suitable for most devices.<\/td><td>Windows Components\\Microsoft Defender Antivirus\\MpEngine<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"intune\">Microsoft Endpoint Manager<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">You can choose between 2 methods : Device Update Control, <s>ADMX-file<\/s> or OMI-URI-method.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Previous mentioned method with ADMX isn&#8217;t working anymore. Thank you <strong>Radu Bagdan<\/strong> for pointing that out. I recommend using method #1 which is pretty new. Thx Microsoft.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Method 1 (Device Update Control)<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"463\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/03\/Defender-1-1024x463.png\" alt=\"\" class=\"wp-image-1113\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/03\/Defender-1-1024x463.png 1024w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/03\/Defender-1-300x136.png 300w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/03\/Defender-1-768x347.png 768w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/03\/Defender-1-1536x695.png 1536w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/03\/Defender-1.png 1638w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"504\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/03\/Defender-2-1024x504.png\" alt=\"\" class=\"wp-image-1114\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/03\/Defender-2-1024x504.png 1024w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/03\/Defender-2-300x148.png 300w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/03\/Defender-2-768x378.png 768w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/03\/Defender-2.png 1277w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"518\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/03\/Defender-3-1024x518.png\" alt=\"\" class=\"wp-image-1115\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/03\/Defender-3-1024x518.png 1024w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/03\/Defender-3-300x152.png 300w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/03\/Defender-3-768x389.png 768w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/03\/Defender-3.png 1442w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Method 2 (OMI-URI)<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Follow the instructions in below link to create a custom policy in Intune:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"708\" height=\"575\" src=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/av8.jpg\" alt=\"\" class=\"wp-image-749\" srcset=\"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/av8.jpg 708w, https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/av8-300x244.jpg 300w\" sizes=\"auto, (max-width: 708px) 100vw, 708px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/mem\/intune\/configuration\/custom-settings-windows-10\">Add custom settings for Windows 10 devices in Microsoft Intune &#8211; Azure |Microsoft Docs<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Create the respective entries for each OMI-URI shown below<\/p>\n\n\n\n<figure class=\"wp-block-table has-small-font-size\"><table><tbody><tr><td>.\/Vendor\/MSFT\/Defender\/Configuration\/SecurityIntelligenceUpdatesChannel<\/td><td>Integer<\/td><td>3 (Preview)<br>4 (Staged)<br>5 (Broad \/ Disabled)<br>6 (Critical: Time Delay)<\/td><\/tr><tr><td>.\/Vendor\/MSFT\/Defender\/Configuration\/PlatformUpdatesChannel<\/td><td>Integer<\/td><td>2 (Beta)<br>3 (Preview)<br>4 (Staged)<br>5 (Broad \/ Disabled)<br>6 (Critical: Time Delay)<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">For more information on the Defender CSP used for the gradual rollout process, see&nbsp;<a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/client-management\/mdm\/defender-csp\" target=\"_blank\" rel=\"noreferrer noopener\">Defender CSP<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"powershell\">PowerShell<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Use the&nbsp;<code>Set-MpPreference<\/code>&nbsp;cmdlet to configure roll out of the gradual updates.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Use the following parameters:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Set-MpPreference\n-PlatformUpdatesChannel Beta|Preview|Staged|Broad|Delayed|NotConfigured\n-EngineUpdatesChannel Beta|Preview|Staged|Broad|Delayed|NotConfigured\n-DisableGradualRelease 1|0\n-SignaturesUpdatesChannel Staged|Broad|NotConfigured<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Example:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Use&nbsp;<code>Set-MpPreference -PlatformUpdatesChannel Beta<\/code>&nbsp;to configure platform updates to arrive from the Beta Channel.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Check your settings using this command<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Get-MpPreference | Select *Channel*, *Gradual* | Format-List<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>It is important to ensure that your security posture systems are up-to-date to be able to prevent attacks. Microsoft Defender &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"How to implement a gradual (ring) rollout-process for Microsoft Defender updates\" class=\"read-more button\" href=\"https:\/\/mortenknudsen.net\/?p=737#more-737\" aria-label=\"Read more about How to implement a gradual (ring) rollout-process for Microsoft Defender updates\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":768,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"ngg_post_thumbnail":0,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[42,97],"tags":[98,41,88,122,118,120,119,121],"class_list":["post-737","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-defender-for-endpoint","category-microsoft-defender-antivirus","tag-antivirus","tag-defender","tag-defenderforendpoint","tag-endpoint","tag-gradual","tag-release","tag-rollout","tag-updates","infinite-scroll-item","resize-featured-image"],"featured_image_src":"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/av11-1.jpg","author_info":{"display_name":"Morten Knudsen","author_link":"https:\/\/mortenknudsen.net\/?author=1"},"jetpack_featured_media_url":"https:\/\/mortenknudsen.net\/wp-content\/uploads\/2023\/01\/av11-1.jpg","jetpack_sharing_enabled":true,"jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=\/wp\/v2\/posts\/737","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=737"}],"version-history":[{"count":93,"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=\/wp\/v2\/posts\/737\/revisions"}],"predecessor-version":[{"id":1116,"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=\/wp\/v2\/posts\/737\/revisions\/1116"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=\/wp\/v2\/media\/768"}],"wp:attachment":[{"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=737"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=737"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mortenknudsen.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=737"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}