You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用PowerShell配置Intune/MEM中的Windows 10更新环?

使用PowerShell配置Intune/MEM中的Windows 10更新环

可以通过Microsoft Graph PowerShell模块完成Windows 10更新环的配置,以下是具体操作步骤:

前提条件

  • 安装最新的Microsoft.Graph模块:
    Install-Module -Name Microsoft.Graph -Force -AllowClobber
    
  • 拥有Intune全局管理员或更新管理员权限
  • 已完成Microsoft Graph身份验证

核心操作步骤

1. 连接到Microsoft Graph

首先获取操作更新环所需的权限:

Connect-MgGraph -Scopes "DeviceManagementConfiguration.ReadWrite.All", "DeviceManagementServiceConfig.ReadWrite.All"

2. 创建Windows 10更新环

根据需求定义更新环参数,然后生成配置:

# 定义更新环核心参数
$updateRingSettings = @{
    DisplayName = "Windows 10 测试更新环"
    Description = "测试设备组:质量更新延迟7天,功能更新立即推送"
    OsVersion = "Windows10"
    FeatureUpdateDeferralPeriodInDays = 0
    QualityUpdateDeferralPeriodInDays = 7
    AllowWindows10Upgrade = $false
    AutomaticUpdateMode = "AutoInstallAndRebootAtMaintenanceTime"
    RebootNotificationStartTime = "09:00:00"
    RebootDeadlineInDays = 3
}

# 创建更新环
$createdUpdateRing = New-MgDeviceManagementWindowsUpdateForBusinessUpdatePolicy @updateRingSettings

3. 将更新环分配给设备组

把创建好的更新环绑定到目标设备组:

# 获取目标设备组的ID(替换为你的组名称)
$targetDeviceGroupId = (Get-MgGroup -Filter "DisplayName eq 'Windows 10 测试设备组'").Id

# 定义分配规则
$assignmentSettings = @{
    Target = @{
        "@odata.type" = "#microsoft.graph.groupAssignmentTarget"
        GroupId = $targetDeviceGroupId
    }
    Intent = "Required"
}

# 添加分配
New-MgDeviceManagementWindowsUpdateForBusinessUpdatePolicyAssignment `
    -WindowsUpdateForBusinessUpdatePolicyId $createdUpdateRing.Id `
    @assignmentSettings

关键参数说明

  • QualityUpdateDeferralPeriodInDays:质量更新(月度补丁)的延迟推送天数
  • FeatureUpdateDeferralPeriodInDays:功能更新(如22H2)的延迟推送天数
  • AutomaticUpdateMode:自动更新执行模式,常用值:
    • AutoInstallAndRebootAtMaintenanceTime:在维护时段自动安装并重启
    • AutoInstallAndRebootWithoutEndUserControl:无需用户交互自动安装重启
  • RebootDeadlineInDays:更新安装后,强制重启的截止天数

验证配置

通过以下命令确认更新环的创建和分配状态:

# 查看指定更新环的详细配置
Get-MgDeviceManagementWindowsUpdateForBusinessUpdatePolicy -WindowsUpdateForBusinessUpdatePolicyId $createdUpdateRing.Id

# 查看更新环的分配情况
Get-MgDeviceManagementWindowsUpdateForBusinessUpdatePolicyAssignment -WindowsUpdateForBusinessUpdatePolicyId $createdUpdateRing.Id

注意事项

  • 避免使用已弃用的Microsoft.Graph.Intune模块,官方推荐使用最新的Microsoft.Graph模块
  • 若需批量配置多个更新环,可将参数封装成数组循环执行
  • 权限不足会导致命令执行失败,确保账号拥有对应的Intune配置权限

内容的提问来源于stack exchange,提问作者Amal Thomas

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.07 21:01:11