Other Intune-related topics, including unsupported scenarios and platform-specific behaviors
Monthly security updates are not described as a phased or “slow roll” release in the provided Microsoft documentation. They are published on the second Tuesday of each month, are cumulative, and are made available through Windows Update, WSUS, and the Microsoft Update Catalog. Microsoft states that most organizations consider these monthly security updates mandatory.
For Windows 11, version 24H2, Microsoft also introduced checkpoint cumulative updates. That changes how some cumulative updates are built, but for devices updating from Windows Update and WSUS, Microsoft states the process is seamless and that no change is needed to the update process.
For devices that are not being offered a monthly security update, the provided documentation supports these points:
- Monthly security updates should be available through the normal servicing channels.
- If devices have recurring installation failures caused by servicing stack file or metadata corruption, they might be unable to install monthly security updates and may not become current without remediation.
- On affected Windows 10/11 devices, Windows can automatically run a Windows Update troubleshooter that targets the device for an in-place upgrade to resolve the corruption. This troubleshooter cannot be run manually.
- On devices with recurring Windows Update problems, there is also a supported recovery path in Settings > System > Recovery using Reinstall now in Fix problems with Windows Updates. The accepted Microsoft Q&A answer states this process does not affect files, settings, or installed apps.
Based on the provided material, the interpretation that monthly security updates are standard broadly released updates is correct. The supplied documentation does not support the claim that these mandatory monthly security updates are generally withheld from otherwise healthy devices as part of a normal slow-roll process.
For the estate described, the most evidence-based checks are:
- Confirm whether the affected laptops are update-managed through policy, Intune, GPO, CSP, Microsoft Graph, or the managed patching tool, because those controls determine what updates are offered and when.
- On a sample affected device, check Start > Settings > Windows Update > Update history to verify whether KB5121003 was installed, superseded, or repeatedly failed.
- If devices show repeated quality update failures, check Start > Settings > Update & Security > Troubleshoot > View history for the Windows Update troubleshooter entry indicating the device was automatically targeted for an in-place upgrade due to recurring installation issues.
- If recurring update failures are present, use Settings > System > Recovery > Reinstall now under Fix problems with Windows Updates on a test device first. This is a repair action, so validate it on a pilot group before wider use.
References:
- Update release cycle for Windows clients
- Description of the Windows Update Standalone Installer in Windows
- Windows Update Troubleshooter for devices experiencing recurring issues installing monthly security updates
- Defining Windows update-managed devices
- Windows Update: FAQ
- Windows 11 latest security patch is failing - Microsoft Q&A