如何在 Microsoft 托管桌面中处理更新How updates are handled in Microsoft Managed Desktop

Microsoft 托管桌面将所有设备连接到基于云的现代基础结构。Microsoft Managed Desktop connects all devices to a modern cloud-based infrastructure. 使 Windows、Office、驱动程序、固件和适用于企业 Microsoft Store 的应用程序保持最新是速度和稳定性的平衡。Keeping Windows, Office, drivers, firmware, and Microsoft Store for Business applications up to date is a balance of speed and stability. 部署组将用于确保以安全方式推出操作系统更新和策略。Deployment groups will be used to ensure operating system updates and policies are rolled out in a safe manner. 有关详细信息,请参阅视频 Microsoft 托管桌面更改和发布过程For more information, see the video Microsoft Managed Desktop Change and Release Process.

Microsoft 发布的更新是累积更新,并归类为质量更新或功能更新。Updates released by Microsoft are cumulative and are categorized as quality or feature updates. 有关详细信息,请参阅适用于企业 Windows 更新:更新类型For more information, see Windows Update for Business: Update types.

更新组Update groups

Microsoft 托管桌面使用四个 Azure AD 组来管理更新:Microsoft Managed Desktop uses four Azure AD groups to manage updates:

  • 测试:用于验证 Microsoft 托管桌面策略更改、操作系统更新、功能更新以及推送到租户的其他更改。Test: Used to validate Microsoft Managed Desktop policy changes, operating system updates, feature updates, and other changes pushed to the tenant. 不应有任何用户放入测试组中。There should not be any users placed in the test group. 测试组不受任何已建立的服务级别协议和用户支持。The test group is exempt from any established service level agreements and user support. 此组可用于验证应用程序与新策略或操作系统更改的兼容性。This group is available for use to validate compatibility of applications with new policy or operating system changes.
  • First: Contains early software adopters and devices that could be subject to pre-release updates.First: Contains early software adopters and devices that could be subject to pre-release updates. 如果测试圈中的测试期间未涵盖的方案,则此组的设备可能会遇到中断。Devices in this group might experience outages if there are scenarios that were not covered during testing in the test ring.
  • 快速:将速度优先考虑稳定性。Fast: Prioritizes speed over stability. 用于检测质量问题,然后再提供给广泛组。Useful for detecting quality issues before they are offered to the Broad group. 该组充当下一个验证层,但通常比 Test 和 First 组更加稳定。This group serves as a next layer of validation but is typically more stable than the Test and First groups.
  • 广泛:最后一个提供功能和质量更新的组。Broad: Last group to have feature and quality updates available. 此组包含租户中的大多数用户,因此支持部署速度的稳定性。This group contains most of users in the tenant, and therefore favors stability over speed in deployment. 测试应用应在此处完成,因为环境最稳定。Testing of apps should be done here as the environment is most stable.

在更新组之间移动设备Moving devices between update groups

你可能希望某些设备最后接收更新,而其他设备希望先接收更新。You might want some devices to receive updates last and others that you want to go first. 若要将这些设备移动到相应的更新组,请提交 管理员支持请求 ,我们将为用户移动设备。To move these devices into the appropriate update group, submit an administrator support request and we will move the devices for you.


如果需要将用户移动到其他更新组,请提交支持请求。If you need to move a user to a different update group, submit a support request. 不要自己在更新组之间移动设备。Do not move devices between update groups yourself. 如果设备移动不正确,则会导致严重的后果。There are serious consequences if a device is moved incorrectly. 设备可能会意外更新,并且策略可能会发生冲突,并更改设备配置。The device could update unexpectedly and policies might conflict, changing the device configuration.

有关这些部署组内的角色和职责详细信息,请参阅 Microsoft 托管桌面角色和职责For more information on roles and responsibilities within these deployment groups, see Microsoft Managed Desktop Roles and responsibilities

使用 Microsoft 托管桌面更新组Using Microsoft Managed Desktop update groups

你可以管理一些服务部分,如应用部署,其中可能需要面向所有托管设备。There are parts of the service that you manage, like app deployment, where it might be necessary to target all managed devices. 在这些情况下,使用更新组联系这些用户是有意义的,因为用户无法添加、删除或更改这些组的成员身份。In these instances, it makes sense to use update groups to reach those users with the understanding that you cannot add, remove, or change the membership of those groups.

更新部署的工作原理:How update deployment works:

  1. Microsoft 托管桌面根据下表中指定的计划部署新功能或质量更新。Microsoft Managed Desktop deploys a new feature or quality update according the schedule specified in the following table.
  2. 在部署期间,Microsoft 托管桌面根据诊断数据和用户支持系统监视故障或中断的迹象。During deployment, Microsoft Managed Desktop monitors for signs of failure or disruption based on diagnostic data and the user support system. 如果检测到任何组,我们会立即将部署暂停到所有当前组和未来组。If any are detected, we immediately pause the deployment to all current and future groups.
    • 示例:如果在将质量更新部署到第一组时发现问题,则更新到 First、Fast 和 Broad 的部署将全部暂停,直到问题得到解决。Example: if an issue is discovered while deploying a quality update to the First group, then update deployments to First, Fast, and Broad will all be paused until the issue is resolved.
    • 可以通过在 Microsoft 托管桌面管理门户中填写票证来报告兼容性问题。You can report compatibility issues by filing a ticket in the Microsoft Managed Desktop Admin portal.
    • 功能和质量更新独立暂停。Feature and quality updates are paused independently. 默认情况下,暂停生效 35 天,但可以减小或延长,具体取决于问题是否已修复。Pause is in effect for 35 days by default, but can be reduced or extended depending on whether the issue is remediated.
  3. 取消暂停组后,部署将按照表中的计划恢复。Once the groups are un-paused, deployment resumes according to the schedule in the table.

虽然每个更新的时间线各不相同,但此部署过程适用于功能和质量更新。This deployment process applies to both feature and quality updates, though the timeline varies for each.

更新部署设置Update deployment settings
更新类型Update type测试TestFirstFirst快速Fast宽泛Broad
操作系统的质量更新Quality updates for operating system0 天0 days0 天0 days0 天0 days3 天3 days
操作系统的功能更新Feature updates for operating system0 天0 days30 天30 days60 天60 days90 天90 days
驱动程序/固件Drivers/firmware遵循质量更新计划Follows the schedule for quality updates
防病毒定义Anti-virus definition通过每次扫描更新Updated with each scan
适用于企业的 Microsoft 365 应用Microsoft 365 Apps for enterprise了解更多Learn more
Microsoft EdgeMicrosoft Edge了解更多Learn more
Microsoft TeamsMicrosoft Teams了解更多Learn more


这些延迟期是特意设计的,以确保所有用户都符合高安全性和性能标准。These deferral periods are intentionally designed to ensure high security and performance standards for all users. 此外,根据在所有 Microsoft 托管桌面设备上收集的数据以及更新的不同范围和影响,Microsoft 托管桌面保留灵活性,可以临时修改任何和所有部署组的上述延迟期的长度。Furthermore, based on data gathered across all Microsoft Managed Desktop devices and the varying scope and impact of updates, Microsoft Managed Desktop reserves flexibility to modify the length of the above deferral periods for any and all deployment groups on an ad hoc basis.

Microsoft 托管桌面会针对每个 Windows 功能版本进行独立评估,以评估其对于托管租户的必要性和实用性。Microsoft Managed Desktop conducts an independent assessment of each Windows feature release to evaluate its necessity and usefulness to its managed tenants. 因此,Microsoft 托管桌面可能会部署所有 Windows 功能更新,也可能不部署。Consequently, Microsoft Managed Desktop might or might not deploy all Windows feature updates.

Windows 预览体验计划Windows Insider Program

Microsoft 托管桌面不支持属于 Windows 预览体验计划的设备。Microsoft Managed Desktop does not support devices that are part of the Windows Insider program. Windows 预览体验计划用于验证预发布 Windows 软件,并且适用于不是任务关键型设备。The Windows Insider program is used to validate pre-release Windows software and is intended for devices that aren't mission critical. 虽然这是一个重要的 Microsoft 计划,但它不适合在生产环境中广泛部署。While it's an important Microsoft initiative, it's not intended for broad deployment in production environments.

使用 Windows 预览体验成员版本发现的任何设备都可能会放入"测试"组中,并且不会从 Microsoft 托管桌面更新服务级别协议和用户支持。Any devices found with Windows Insider builds might be put into the Test group and will be exempt from update service level agreements and user support from Microsoft Managed Desktop.

带宽管理Bandwidth management

我们将传递 优化用于 所有操作系统和驱动程序更新。We use Delivery Optimization for all operating system and driver updates. 这通过从企业网络内的对等方寻求更新来最大程度地减小 Windows 更新服务的下载大小。This minimizes the download size from the Windows Update service by seeking updates from peers within the corporate network.