Windows Update

Pckgr helps you manage Windows Update across your device fleet using update rings and patch compliance monitoring.

Windows Update Rings

Update rings are policy templates that control how Windows Updates are applied to groups of devices. They let you stagger updates across your organization - for example, deploying to a pilot group first, then broadly.

Creating an Update Ring

  1. Go to Windows Update in the sidebar.
  2. Click Create Ring.
  3. Enter a name (e.g., "Pilot", "Broad", "Critical").
  4. Optionally add a description.
  5. Click Create. You'll be taken to the ring configuration page.

Configuring a Ring

Basic Settings

  • Name and Description
  • Enabled / Disabled - Whether the ring is actively applied
  • Priority - Determines precedence when a device is in multiple rings (lower = higher priority)

Quality Update Settings

  • Deferral Days - How many days to delay quality (cumulative) updates after release
  • Deadline Days - How many days after the deferral period before the update is forced

Feature Update Settings

  • Deferral Days - How many days to delay feature updates
  • Deadline Days - Deadline for feature update installation

Behavior Settings

  • Automatic Updates - Whether updates download and install automatically
  • Exclude Drivers - Skip driver updates
  • Prevent Reboot When Users Logged On - Avoid forced restarts while users are working
  • Active Hours - Time window when the device should not restart (e.g., 8 AM - 6 PM)
  • Deadline Grace Period - Extra days before enforcement after a deadline passes

Assigning a Ring to Groups

  1. Open the ring's configuration page.
  2. In the assignments section, select a group to assign the ring to.
  3. Confirm the assignment.

Devices in the group will receive the ring's update settings on their next check-in.

Patch Status

The Patch Status page (under Windows Update in the sidebar) shows detailed compliance information for every device.

Compliance Summary

MetricDescription
Total DevicesAll devices reporting update status
Up to DateDevices running the latest cumulative update
Within DeferralDevices within their ring's deferral window
BehindDevices that need updates but aren't yet overdue
OverdueDevices past their update deadline
UnknownDevices without enough baseline data
Not ReportingDevices that haven't sent update status

Filtering

  • Search - Filter by device hostname
  • OS Version - Filter by Windows 10 or Windows 11
  • Group - Filter by device group
  • Ring - Filter by assigned Windows Update ring
  • Status - Filter by compliance state

Compliance States

StateMeaning
Up to DateDevice has the latest cumulative update installed
Within DeferralUpdate available but device is within its configured deferral window
BehindDevice needs updates but hasn't reached the deadline yet
OverdueDevice is past the update deadline and needs immediate attention
UnknownNot enough data to determine compliance
Not ReportingDevice hasn't reported update status recently

Tips

  • Create at least two rings - a Pilot ring with shorter deferrals for early testing, and a Broad ring for the majority of devices.
  • Set deadlines to ensure updates are eventually installed even if deferral periods expire.
  • Use active hours to avoid disrupting users with forced restarts during working hours.
  • Check the Patch Status page regularly to identify overdue devices.