如何在 Microsoft 受管理的電腦中處理更新How updates are handled in Microsoft Managed Desktop

Microsoft 受管理的桌面會將所有裝置連接至新式雲端架構基礎結構。Microsoft Managed Desktop connects all devices to a modern cloud-based infrastructure. 保持最新的 Windows、Office、驅動程式、固件及 Microsoft Store for Business 應用程式是速度和穩定性的平衡。Keeping Windows, Office, drivers, firmware, and Microsoft Store for Business applications up to date is a balance of speed and stability. 部署群組將用來確保作業系統更新及原則以安全的方式推出。Deployment groups will be used to ensure operating system updates and policies are rolled out in a safe manner. 如需詳細資訊,請參閱影片 Microsoft 受管理的桌面變更和發行程式。For more information, see the video Microsoft Managed Desktop Change and Release Process.

Microsoft 所發行的更新會累計,而且會分類為品質或功能更新。Updates released by Microsoft are cumulative and are categorized as quality or feature updates. 如需詳細資訊,請參閱 Windows update For Business: Update typesFor more information, see Windows Update for Business: Update types.

更新群組Update groups

Microsoft 受管理的桌面會使用四個 Azure AD 群組來管理更新:Microsoft Managed Desktop uses four Azure AD groups to manage updates:

  • 測試:用於驗證 Microsoft 受管理的桌面原則變更、作業系統更新、功能更新和其他已推入租使用者的變更。Test: Used to validate Microsoft Managed Desktop policy changes, operating system updates, feature updates, and other changes pushed to the tenant. 不應該有任何使用者放置在測試群組中。There should not be any users placed in the test group. 測試群組免除任何已建立的服務等級協定和使用者支援。The test group is exempt from any established service level agreements and user support. 此群組可用於驗證應用程式與新原則或作業系統變更的相容性。This group is available for use to validate compatibility of applications with new policy or operating system changes.
  • First:包含早期的軟體採納者和裝置,其可能會受發行前更新的制約。First: Contains early software adopters and devices that could be subject to pre-release updates. 如果有測試環中測試期間未涵蓋的案例,則此群組中的裝置可能會遇到中斷問題。Devices in this group might experience outages if there are scenarios that were not covered during testing in the test ring.
  • Fast:優先執行速度高於穩定性。Fast: Prioritizes speed over stability. 用於偵測品質問題,再將其提供給廣泛的群組。Useful for detecting quality issues before they are offered to the Broad group. 這個群組是做為下一個驗證層,但通常比測試和第一個群組更穩定。This group serves as a next layer of validation but is typically more stable than the Test and First groups.
  • 廣泛:上一個群組可提供功能和品質更新。Broad: Last group to have feature and quality updates available. 此群組包含租使用者中大部分的使用者,因此會在部署時優先于速度。This group contains most of users in the tenant, and therefore favors stability over speed in deployment. 在環境最穩定的情況時,應該在這裡進行應用程式的測試。Testing of apps should be done here as the environment is most stable.

在更新群組之間移動裝置Moving devices between update groups

您可能想要讓某些裝置接收最後的更新,以及您想要最先移的其他裝置。You might want some devices to receive updates last and others that you want to go first. 若要將這些裝置移至適當的更新群組,請 提交系統管理員支援要求 ,我們會為您移動裝置。To move these devices into the appropriate update group, submit an administrator support request and we will move the devices for you.

注意

如果您需要將使用者移至不同的更新群組,請提交支援要求。If you need to move a user to a different update group, submit a support request. 不要在更新群組之間自行移動裝置。Do not move devices between update groups yourself. 如果裝置移動不正確,將會造成嚴重的後果。There are serious consequences if a device is moved incorrectly. 裝置可能會意外更新,而且原則可能會發生衝突,變更裝置設定。The device could update unexpectedly and policies might conflict, changing the device configuration.

如需這些部署群組中角色和責任的詳細資訊,請參閱 Microsoft 受管理的桌面角色與責任For more information on roles and responsibilities within these deployment groups, see Microsoft Managed Desktop Roles and responsibilities

使用 Microsoft 受管理的桌面更新群組Using Microsoft Managed Desktop update groups

您管理的服務有些部分(如應用程式部署),您可能需要將其設定為針對所有受管理的裝置。There are parts of the service that you manage, like app deployment, where it might be necessary to target all managed devices. 在這些情況下,您可以使用更新群組,以瞭解您無法新增、移除或變更這些群組的成員資格,以達到這些使用者的意義。In these instances, it makes sense to use update groups to reach those users with the understanding that you cannot add, remove, or change the membership of those groups.

更新部署的運作方式:How update deployment works:

  1. Microsoft 受管理的桌面會根據下表中所指定的排程,部署新的功能或品質更新。Microsoft Managed Desktop deploys a new feature or quality update according the schedule specified in the following table.
  2. 在部署期間,Microsoft 受管理的桌面監視器會根據診斷資料和使用者支援系統,針對失敗或中斷的跡象進行標記。During deployment, Microsoft Managed Desktop monitors for signs of failure or disruption based on diagnostic data and the user support system. 如果偵測到任何情況,我們會立即暫停部署至所有目前和未來的群組。If any are detected, we immediately pause the deployment to all current and future groups.
    • 範例:如果在部署第一個群組的品質更新時會發現問題,則在解決問題之前,先將部署更新為第一個、快速和廣泛的部署。Example: if an issue is discovered while deploying a quality update to the First group, then update deployments to First, Fast, and Broad will all be paused until the issue is resolved.
    • 您可以在 Microsoft Managed Desktop Admin 入口網站中歸檔票證,以報告相容性問題。You can report compatibility issues by filing a ticket in the Microsoft Managed Desktop Admin portal.
    • 會獨立暫停功能和品質更新。Feature and quality updates are paused independently. 預設情況下,Pause 會生效于35天,但可根據問題是否已修正,加以縮短或擴充。Pause is in effect for 35 days by default, but can be reduced or extended depending on whether the issue is remediated.
  3. 當群組未暫停時,將會根據資料表中的排程,繼續進行部署。Once the groups are un-paused, deployment resumes according to the schedule in the table.

此部署程式會同時適用于功能和品質更新,不過每個階段的時程表各有不同。This deployment process applies to both feature and quality updates, though the timeline varies for each.

更新部署設定Update deployment settings
更新類型Update type測試Test名字First快速Fast廣泛Broad
作業系統的品質更新Quality updates for operating system0天0 days0天0 days0天0 days3天3 days
作業系統的功能更新Feature updates for operating system0天0 days30 天30 days60 天60 days90 天90 days
驅動程式/固件Drivers/firmware遵循品質更新的排程Follows the schedule for quality updates
防病毒定義Anti-virus definition更新每個掃描Updated with each scan
Microsoft 365 Apps 企業版Microsoft 365 Apps for enterprise深入了解Learn more
Microsoft EdgeMicrosoft Edge深入了解Learn more
Microsoft TeamsMicrosoft Teams深入了解Learn more

注意

這些延期期間是特意設計,以確保所有使用者的高安全性和效能標準。These deferral periods are intentionally designed to ensure high security and performance standards for all users. 此外,根據在所有 Microsoft 受管理的桌面裝置上收集的資料,以及更新的範圍和影響,Microsoft 受管理的桌面保留可靈活修改任何和所有部署群組的上述延遲週期長度。Furthermore, based on data gathered across all Microsoft Managed Desktop devices and the varying scope and impact of updates, Microsoft Managed Desktop reserves flexibility to modify the length of the above deferral periods for any and all deployment groups on an ad hoc basis.

Microsoft 受管理的桌面會針對每個 Windows 功能版本執行獨立評估,以評估其必要和對其受管理承租人的有用性。Microsoft Managed Desktop conducts an independent assessment of each Windows feature release to evaluate its necessity and usefulness to its managed tenants. 因此,Microsoft 受管理的桌面可能會或不會部署所有 Windows 功能更新。Consequently, Microsoft Managed Desktop might or might not deploy all Windows feature updates.

Windows 測試人員計畫Windows Insider Program

Microsoft 受管理的桌面不支援屬於 Windows 預覽體驗計畫的裝置。Microsoft Managed Desktop does not support devices that are part of the Windows Insider program. Windows 有問必答計畫是用來驗證預先發行的 Windows 軟體,其適用于並非要徑任務的裝置。The Windows Insider program is used to validate pre-release Windows software and is intended for devices that aren't mission critical. 雖然這是一項重要的 Microsoft 倡議,但不適用於實際執行環境中的部署。While it's an important Microsoft initiative, it's not intended for broad deployment in production environments.

任何找到 Windows 測試人員組建的裝置,都可能會放入測試群組,且不會從 Microsoft Managed Desktop 的更新服務等級協定和使用者支援中免除。Any devices found with Windows Insider builds might be put into the Test group and will be exempt from update service level agreements and user support from Microsoft Managed Desktop.

頻寬管理Bandwidth management

我們使用 傳遞優化 來進行所有作業系統及驅動程式更新。We use Delivery Optimization for all operating system and driver updates. 這可透過從公司網路中的對等機器尋找更新,將 Windows Update service 的下載大小降到最低。This minimizes the download size from the Windows Update service by seeking updates from peers within the corporate network.