Windows Update
Pckgr helps you manage Windows Update across your device fleet using update rings and patch compliance monitoring.
Windows Update Rings
Update rings are policy templates that control how Windows Updates are applied to groups of devices. They let you stagger updates across your organization - for example, deploying to a pilot group first, then broadly.
Creating an Update Ring
- Go to Windows Update in the sidebar.
- Click Create Ring.
- Enter a name (e.g., "Pilot", "Broad", "Critical").
- Optionally add a description.
- Click Create. You'll be taken to the ring configuration page.
Configuring a Ring
Basic Settings
- Name and Description
- Enabled / Disabled - Whether the ring is actively applied
- Priority - Determines precedence when a device is in multiple rings (lower = higher priority)
Quality Update Settings
- Deferral Days - How many days to delay quality (cumulative) updates after release
- Deadline Days - How many days after the deferral period before the update is forced
Feature Update Settings
- Deferral Days - How many days to delay feature updates
- Deadline Days - Deadline for feature update installation
Behavior Settings
- Automatic Updates - Whether updates download and install automatically
- Exclude Drivers - Skip driver updates
- Prevent Reboot When Users Logged On - Avoid forced restarts while users are working
- Active Hours - Time window when the device should not restart (e.g., 8 AM - 6 PM)
- Deadline Grace Period - Extra days before enforcement after a deadline passes
Assigning a Ring to Groups
- Open the ring's configuration page.
- In the assignments section, select a group to assign the ring to.
- Confirm the assignment.
Devices in the group will receive the ring's update settings on their next check-in.
Patch Status
The Patch Status page (under Windows Update in the sidebar) shows detailed compliance information for every device.
Compliance Summary
| Metric | Description |
|---|---|
| Total Devices | All devices reporting update status |
| Up to Date | Devices running the latest cumulative update |
| Within Deferral | Devices within their ring's deferral window |
| Behind | Devices that need updates but aren't yet overdue |
| Overdue | Devices past their update deadline |
| Unknown | Devices without enough baseline data |
| Not Reporting | Devices that haven't sent update status |
Filtering
- Search - Filter by device hostname
- OS Version - Filter by Windows 10 or Windows 11
- Group - Filter by device group
- Ring - Filter by assigned Windows Update ring
- Status - Filter by compliance state
Compliance States
| State | Meaning |
|---|---|
| Up to Date | Device has the latest cumulative update installed |
| Within Deferral | Update available but device is within its configured deferral window |
| Behind | Device needs updates but hasn't reached the deadline yet |
| Overdue | Device is past the update deadline and needs immediate attention |
| Unknown | Not enough data to determine compliance |
| Not Reporting | Device hasn't reported update status recently |
Tips
- Create at least two rings - a Pilot ring with shorter deferrals for early testing, and a Broad ring for the majority of devices.
- Set deadlines to ensure updates are eventually installed even if deferral periods expire.
- Use active hours to avoid disrupting users with forced restarts during working hours.
- Check the Patch Status page regularly to identify overdue devices.