To move Windows 11 devices off 24H2, create a feature update policy in the Intune admin center under Devices > Windows > Windows updates > Feature updates, choose Windows 11, version 25H2 as the Feature update to deploy, and assign it to device groups with a gradual rollout. Before you assign it, set Feature update deferral period (days) to 0 in your update rings and run the Windows Feature Update Device Readiness Report so blocked or high-risk devices are fixed first. Pro editions of 24H2 stop receiving updates on 13 October 2026, and Enterprise and Education on 12 October 2027.
Who this is for and what you will have at the end
This guide is for Intune administrators who manage Windows 11 devices with Windows Update client policies (Windows Update for Business) and need to control the move from 24H2 to the next version rather than leave it to deferrals.
At the end you will have:
- Tenant settings that let Intune use Windows diagnostic data for readiness and failure reporting.
- A readiness review of your 24H2 devices against the target version.
- Update rings that no longer fight the feature update policy.
- A pilot policy and a broad policy for 25H2, the broad one using a gradual rollout.
- A way to read the feature update reports and act on their alerts.
Choose the target version
Windows 11 versions released in the second half of the year get 24 months of updates for Home, Pro, Pro Education and Pro for Workstations, and 36 months for Enterprise and Education. The current General Availability Channel versions that matter for this move are:
| Version | Build | Available | End of updates: Pro editions | End of updates: Enterprise and Education |
|---|---|---|---|---|
| 24H2 | 26100 | 2024-10-01 | 2026-10-13 | 2027-10-12 |
| 25H2 | 26200 | 2025-09-30 | 2027-10-12 | 2028-10-10 |
| 26H2 | 26300 | 2026-09-29 | 2028-10-10 | 2029-10-09 |
Version 26H1 isn't part of this decision: Microsoft scoped it to new devices that shipped in 2026, and it isn't offered as an in-place update from 24H2 or 25H2.
This guide targets 25H2: it has been generally available for a year, and the move from 24H2 is light. Devices on 24H2 update to 25H2 with an enablement package: most of the 25H2 files already exist on 24H2 devices with a recent monthly security update, and the package activates the features that were shipped dormant. If you would rather target 26H2, the Intune steps below are the same; you pick that version in the policy and the readiness report instead. Read the 26H2 release notes first, because the 25H2 notes that follow don't cover it.
Two removals in 25H2 deserve a check before you upgrade:
- PowerShell 2.0 is no longer included. Scripts or tools that still depend on it need updating first.
- WMIC is uninstalled during the upgrade. It can be added back from optional features or DISM, but Microsoft doesn't recommend that because it will be removed completely later.
Prerequisites
- Licensing: Microsoft Intune Plan 1 and a Windows license that includes the Windows Autopatch entitlement. Offering the update as optional (rather than required) also needs a Windows Autopatch license.
- Editions: Pro, Pro Education, Enterprise or Education. Windows Enterprise LTSC isn't supported by feature update policies.
- Join type: devices managed by Intune and Microsoft Entra joined or Microsoft Entra hybrid joined.
- Telemetry: diagnostic data set to at least Required.
- Services: the Microsoft Account Sign-In Assistant service (
wlidsvc) enabled and running. Without it, Windows Update doesn't offer feature updates. - Network: access to the Intune, Windows Update and Windows Autopatch endpoints.
- Roles: Policy and Profile manager (or a custom role with the device configuration permissions) to create policies; Read Only Operator, Help Desk Operator, Endpoint Security Manager or a custom role with Managed devices > View Reports to see the reports.
Step 1: Turn on Windows data in the tenant
The readiness reports and the failure alerts depend on Windows diagnostic data that Intune only processes after you opt in.
- In the Intune admin center, go to Tenant administration > Connectors and tokens > Windows data.
- Set Enable features that require Windows diagnostic data in processor configuration to On. The default is Off.
- Set I confirm that my tenant owns one of these licenses to On if you have Windows Enterprise E3/E5, Microsoft 365 F3/E3/E5, Windows Education A3/A5, Microsoft 365 A3/A5 or Windows Virtual Desktop Access E3/E5. The compatibility reports require this attestation.
Diagnostic data typically uploads once a day and is processed in batches, with a maximum end-to-end latency of about 52 hours. Do this step at least two days before you need the reports.
Step 2: Check readiness
- Go to Reports > Device management > Windows updates, select the Reports tab and open Windows Feature Update Device Readiness Report.
- Under Select Target OS, choose Windows 11, version 25H2. Select the scope tags and select Generate report. Generated reports are cached per admin, so colleagues must generate their own.
Each device gets a readiness status:
| Readiness status | Meaning | What to do |
|---|---|---|
| Low risk | No known compatibility risks | Include in the first waves |
| Medium risk | Minor or non-blocking risks, such as apps removed during upgrade | Review the apps, then include |
| High risk | Multiple or blocking risks, such as an app that blocks the upgrade | Fix or exclude until fixed |
| Replace device | Can't upgrade to the target version | Plan hardware replacement |
| Upgraded | Already on the target version or later | Nothing |
| Unknown | No readiness data | Check diagnostic data configuration |
Then open Windows Feature Update Compatibility Risks Report for the same target. It groups risks by application, driver or other asset with the number of affected devices, which tells you which fix unblocks the most devices. Issues such as Blocking upgrade, update application to newest version or Driver won't migrate to new OS come with guidance in the details pane. Entries tagged as safeguards aren't real installed assets; they mark devices affected by a safeguard hold.
Step 3: Align update rings
When a device has both an update ring and a feature update policy, the ring's feature update settings can delay or block the offer. Microsoft recommends using feature update policies as the only control for which version devices get, and keeping rings for the client experience: deadlines, restarts, active hours and notifications.
To switch without exposing devices to an unintended upgrade:
- Create and assign the feature update policy first (Step 4) while the ring deferral is still in place.
- Wait until the Windows Feature Update Report shows the targeted devices in OfferReady, which means Windows Update has processed the policy. This normally takes about 10 minutes but can take longer.
- Edit each ring and set Feature update deferral period (days) to 0.
- Make sure feature updates aren't paused on the ring. A ring pause expires after 35 days; a feature update policy stays in effect until you change or remove it.
Ring deadlines still apply to the upgrade. Deadline for feature updates accepts 2 to 30 days and Grace period 0 to 7 days, under Use deadline settings. Set them so devices that ignore the restart prompt still finish.
Step 4: Create the feature update policies
Create two policies: one for a pilot group and one for everyone else.
- In the Intune admin center, go to Devices > Windows > Windows updates > Feature updates and select Create profile.
- Under Deployment settings, enter a name such as
FU - Windows 11 25H2 - Pilot. - In Feature update to deploy, select Windows 11, version 25H2. Only versions still in support are listed.
- Select Make available to users as a required update. The optional alternative leaves the decision to users and needs a Windows Autopatch license.
- Under Rollout options, choose Make update available as soon as possible for the pilot.
- Assign the policy to a device group, review and select Create.
Repeat for the broad policy, this time with Make update available gradually:
| Setting | What it does |
|---|---|
| First group availability | Date of the first offer; must be at least two days in the future |
| Final group availability | Date by which every remaining device gets the offer |
| Days between groups | Interval between offer groups; determines how many groups are created |
Windows Update assigns devices to offer groups randomly, keeps groups evenly sized and puts at least 100 devices in each. For example, a first date of 1 November, a final date of 10 November and a 3-day interval gives four offers: 1, 4, 7 and 10 November. Devices added to the policy later go into the remaining groups, and devices added after the final date get the offer immediately.
If you deploy a settings catalog profile with Allow WUfB Cloud Processing set to Enabled to the same devices, gradual rollouts become intelligent rollouts: Windows Autopatch builds a diverse first group that acts as a pilot, and can apply likely-issue safeguard holds to devices that are likely to hit a problem.
Keep in mind how multiple policies combine. Each policy targets one version; when a device is in several, Windows Update offers only the latest applicable version. Exclude the pilot group from the broad policy: a device in more than one deployment of the same update type raises a DeploymentConflict alert, and only the first deployment assigned is effective. Feature update policies don't apply during Autopilot OOBE; they apply at the first Windows Update scan after provisioning.
Devices that use hotpatch need one more consideration: upgrade them during a baseline month to keep them on the hotpatch cycle. Intune update rings and Windows hotpatch explains the calendar.
Step 5: Monitor the rollout
Go to Reports > Windows Updates, select Windows Feature Update Report, choose the policy and select Generate report. Service-side data from Windows Update arrives within about an hour; client-side installation data refreshes every eight hours once Windows data is enabled.
The most useful update states and substates:
- Pending > Scheduled: the offer is scheduled for a later offer group.
- Offering > OfferReady: Windows Update is offering the update.
- On hold > Deferred: a client deferral policy is delaying the offer.
- Installing: download start, install complete, restart required and restart complete.
- Installed > Update Installed: done.
- Canceled > Service Cancelled: the content reached end of service or was superseded by a newer deployment.
For errors, go to Devices > Monitor > Feature update failures, select the policy and open each alert.
Troubleshooting
| Alert | Cause | Fix |
|---|---|---|
| SafeguardHold | A known issue blocks the update on this device | Check the hold ID in the Deployment Error Code column against Windows release health; wait for the hold to lift |
| PolicyConflictDeferral | A ring or GPO deferral blocks the update | Set Feature update deferral period (days) to 0 |
| PolicyConflictPause | Updates are paused on the device | Resume the ring |
| DeviceRegistrationInvalidGlobalDeviceId | Microsoft Account Sign-In Assistant disabled | Enable and start wlidsvc |
| DeviceRegistrationInvalidAzureADDeviceId | Device not properly joined to your tenant | Check the device's Microsoft Entra join state |
| DeploymentConflict | Device is in more than one deployment of the same update type | Remove it from the deployments that shouldn't apply |
| DiskFull | Windows partition is full | Free space, then retry |
| RollbackInitiated | Setup hit a serious error and rolled back | Run SetupDiag before retrying |
| EndOfServiceApproaching | Device is on a version nearing end of service | Make sure it is in a feature update policy |
If devices stay in Unknown readiness or never report client-side states, confirm diagnostic data is at least Required and that the Windows data toggle is on.
Plan rollback before you need it. The ring Uninstall action rolls back the latest feature update only within the Set feature update uninstall period (2 to 60 days), and Microsoft documents that it isn't successful when the update was applied through an enablement package, which is how 24H2 devices get 25H2. A thorough pilot is your main safety net.
Checklist
- Target version chosen with its end-of-updates date in mind.
- Windows diagnostic data and license attestation turned on at least two days before reporting.
- Readiness and compatibility risks reports reviewed; high-risk and replace-device machines handled.
- Scripts checked for PowerShell 2.0 and WMIC dependencies.
- Feature update policies created for pilot and broad groups, assigned to device groups.
- Ring deferral set to 0 only after devices reached OfferReady; no ring pause in place.
- Feature update deadlines and grace period set in the rings.
- Feature update report and failure alerts reviewed until every 24H2 device shows Update Installed.
References
- Manage Windows feature updates
- Configure Windows feature update policies
- Configure rollout options for feature update policies
- Reports for Windows feature update policies
- Use compatibility reports for Windows updates in Intune
- Enable Windows diagnostic data and license verification
- Manage Windows update ring policies
- Update rings policy settings
- Windows 11 release information
- What's new in Windows 11, version 25H2 for IT pros