如何使用PowerShell配置Intune/MEM中的Windows 10更新环?
使用PowerShell配置Intune/MEM中的Windows 10更新环
可以通过Microsoft Graph PowerShell模块完成Windows 10更新环的配置,以下是具体操作步骤:
前提条件
- 安装最新的
Microsoft.Graph模块:Install-Module -Name Microsoft.Graph -Force -AllowClobber - 拥有Intune全局管理员或更新管理员权限
- 已完成Microsoft Graph身份验证
核心操作步骤
1. 连接到Microsoft Graph
首先获取操作更新环所需的权限:
Connect-MgGraph -Scopes "DeviceManagementConfiguration.ReadWrite.All", "DeviceManagementServiceConfig.ReadWrite.All"
2. 创建Windows 10更新环
根据需求定义更新环参数,然后生成配置:
# 定义更新环核心参数 $updateRingSettings = @{ DisplayName = "Windows 10 测试更新环" Description = "测试设备组:质量更新延迟7天,功能更新立即推送" OsVersion = "Windows10" FeatureUpdateDeferralPeriodInDays = 0 QualityUpdateDeferralPeriodInDays = 7 AllowWindows10Upgrade = $false AutomaticUpdateMode = "AutoInstallAndRebootAtMaintenanceTime" RebootNotificationStartTime = "09:00:00" RebootDeadlineInDays = 3 } # 创建更新环 $createdUpdateRing = New-MgDeviceManagementWindowsUpdateForBusinessUpdatePolicy @updateRingSettings
3. 将更新环分配给设备组
把创建好的更新环绑定到目标设备组:
# 获取目标设备组的ID(替换为你的组名称) $targetDeviceGroupId = (Get-MgGroup -Filter "DisplayName eq 'Windows 10 测试设备组'").Id # 定义分配规则 $assignmentSettings = @{ Target = @{ "@odata.type" = "#microsoft.graph.groupAssignmentTarget" GroupId = $targetDeviceGroupId } Intent = "Required" } # 添加分配 New-MgDeviceManagementWindowsUpdateForBusinessUpdatePolicyAssignment ` -WindowsUpdateForBusinessUpdatePolicyId $createdUpdateRing.Id ` @assignmentSettings
关键参数说明
QualityUpdateDeferralPeriodInDays:质量更新(月度补丁)的延迟推送天数FeatureUpdateDeferralPeriodInDays:功能更新(如22H2)的延迟推送天数AutomaticUpdateMode:自动更新执行模式,常用值:AutoInstallAndRebootAtMaintenanceTime:在维护时段自动安装并重启AutoInstallAndRebootWithoutEndUserControl:无需用户交互自动安装重启
RebootDeadlineInDays:更新安装后,强制重启的截止天数
验证配置
通过以下命令确认更新环的创建和分配状态:
# 查看指定更新环的详细配置 Get-MgDeviceManagementWindowsUpdateForBusinessUpdatePolicy -WindowsUpdateForBusinessUpdatePolicyId $createdUpdateRing.Id # 查看更新环的分配情况 Get-MgDeviceManagementWindowsUpdateForBusinessUpdatePolicyAssignment -WindowsUpdateForBusinessUpdatePolicyId $createdUpdateRing.Id
注意事项
- 避免使用已弃用的
Microsoft.Graph.Intune模块,官方推荐使用最新的Microsoft.Graph模块 - 若需批量配置多个更新环,可将参数封装成数组循环执行
- 权限不足会导致命令执行失败,确保账号拥有对应的Intune配置权限
内容的提问来源于stack exchange,提问作者Amal Thomas
相关产品推荐
相关产品推荐

