Running a work PC means your organization controls how and when Windows receives updates. Windows Update for Business gives IT teams the ability to defer feature updates, quality patches, and driver installations across managed devices. Whether you manage a small fleet of Windows 11 Pro machines or coordinate updates across a Windows 10 Enterprise environment, understanding the deferral options keeps your workflow uninterrupted and your systems stable.
Before You Start: Deferring updates on a work PC usually requires administrative access or an active Microsoft Intune enrollment. If your device is fully managed by your IT department, personal settings may be locked. You will need a supported edition of Windows (Pro, Enterprise, or Education) to access Group Policy tools, while cloud-managed devices rely on Intune update rings.
Step 1: Identify Your Device Management Type
- Open Settings and navigate to Accounts > Access work or school. Review the connection status to determine whether your PC uses Azure AD, Intune, or on-premises Group Policy. Knowing your management type tells you which deferral method applies to your machine.
- Check the Windows edition in Settings > System > About. Windows Update for Business features like update rings and deferred updates only function on Pro, Enterprise, or Education editions. Home editions lack the Group Policy Editor and Intune integration required for enterprise deferral.
- Contact your IT helpdesk if the device shows as managed but you lack permissions. Work PCs often have policy restrictions that block personal update changes. Your administrator can confirm whether you are allowed to defer updates or if you must wait for the next approved deployment window.
Step 2: Pause Updates Temporarily Through Settings
- Navigate to Settings > Windows Update and select Pause for 1 week. This option gives you a five-day window to finish critical tasks without unexpected restarts. The pause timer resets each time you click the button, allowing you to extend the delay up to the maximum allowed by your organization.
- Verify the active hours setting to prevent background restarts. Go to Settings > Windows Update > Advanced options > Active hours and set the time range that matches your typical workday. Windows will avoid restarting your PC during these hours, which reduces the chance of losing unsaved work.
- Monitor the update status in the same Windows Update menu. The interface will display when paused updates are scheduled to resume. If the pause option is grayed out, your IT policy has overridden the local setting, and you will need to use the enterprise deferral methods instead.

Step 3: Configure Update Deferral Using Local Group Policy
- Press
Win + R, typegpedit.msc, and press Enter. The Local Group Policy Editor opens a tree of administrative templates that control Windows Update behavior. This tool is available on Windows 10/11 Pro, Enterprise, and Education editions, and it provides the most reliable way to defer updates on a per-device basis. - Navigate to Computer Configuration > Administrative Templates > Windows Components > Windows Update > Windows Update for Business. Locate the policy named
Configure Automatic Updatesand double-click it to open the configuration window. SelectEnabledto activate enterprise-style update management. - Choose
2 - Notify for download and notify for installfrom the dropdown menu. This setting stops automatic downloads and forces Windows to alert you before installing anything. You can also adjust theDefer Feature UpdatesandDefer Quality Updatespolicies to specify how many days to delay each update category. - Click Apply and close the Group Policy Editor. Open a command prompt and run
gpupdate /forceto immediately apply the new configuration. Windows will now respect the deferral windows you configured until your IT department changes the policy.
Step 4: Create Update Rings in Microsoft Intune
- Open the Microsoft Intune admin center at
endpoint.microsoft.comand sign in with your work credentials. Update rings are the cloud equivalent of Group Policy deferral settings and allow administrators to group devices by department, location, or risk tolerance. Only users with the Intune Administrator or Update Ring Administrator role can create these configurations. - Select Devices > Windows > Update rings and click Create ring. Enter a descriptive name like
Finance Team - 30 Day Deferraland assign the ring to a device group. You will configure separate deferral periods for feature updates, quality updates, and driver updates within this wizard. - Set the deferral values and maximum deadline in the configuration pane. The
Feature update deferral daysfield controls how long a new Windows version waits before reaching your devices. TheDeadline for quality updatesforces installation after a set period, which prevents devices from falling behind on security patches indefinitely. - Assign the ring and wait for the Intune sync cycle to push the policy. Devices typically check in within one to four hours. You can force a sync on the work PC by opening Settings > Windows Update > Advanced options > Restart now, or by running
mssettings://updatesin the Run dialog.

Step 5: Verify the Deferral Policy Applied Correctly
- Open Settings > Windows Update > Advanced options and review the deferral settings. The interface will display the remaining days before a feature update installs and the current status of quality update deferrals. If the values match your configuration, the policy is active and functioning as intended.
- Run
gpresult /rin an elevated command prompt to confirm Group Policy application. The report lists every policy applied to your device and shows which source delivered each setting. Look for the Windows Update for Business policies at the bottom of the report to verify they loaded without errors. - Check the Update History page for any unexpected installations. If updates install outside your deferral window, your IT department may have overridden the local settings, or a critical security patch bypassed the deferral rules. Document the timestamps and share them with your helpdesk for policy review.
Troubleshooting Common Deferral Issues
Group Policy changes are not taking effect. Run gpupdate /force and then gpresult /h C:\gpo-report.html to generate a detailed report. If the report shows Policy Not Applied next to your Windows Update settings, check the Security Filtering tab in Group Policy Management and ensure your user account or device group has Read permissions. Restart the Windows Update service via services.msc if the report still shows no changes.
Intune update rings are not syncing to your device. Open Settings > Accounts > Access work or school and tap Info next to your organization account. Select Sync to force a manual check-in. If the device still ignores the ring, verify that the device is enrolled in Intune by checking the Enrollment status page, and confirm that the update ring assignment matches your device group name exactly.
Updates install despite an active deferral. Windows includes a built-in safety mechanism that forces critical security updates after a maximum deadline, usually 30 days for quality patches and 365 days for feature updates. This behavior prevents devices from becoming vulnerable to known exploits. If you need to extend the deadline, your IT administrator must modify the Maximum deadline for quality updates policy in Intune or Group Policy.
Pro Tip: Always test deferral settings on a single pilot device before rolling them out to your entire department. Create a test device group in Intune or apply a dedicated Group Policy Object to one workstation, then monitor update behavior for two weeks to catch compatibility issues before they affect your team.
Quick Tips for Managing Update Deferrals:
- Document your deferral schedule in a shared team calendar so colleagues know when updates will install.
- Use the
Windows Update Medic Servicestatus page to confirm that deferral policies are not being blocked by system integrity checks. - Keep a backup of your original Group Policy settings before making changes, so you can revert quickly if a deferred update causes workflow disruptions.
Deferring updates on a work PC requires coordination between your local settings, your organization’s management platform, and your IT department’s deployment schedule. By following these steps, you can control when Windows updates reach your machine without sacrificing long-term security. Let us know how your organization handles update scheduling, and share your experience with Windows Update for Business in the comments below.
Over to you: How does your organization handle update scheduling on work PCs?



