Skip to content

Windows Update dashboard

The Windows Update Dashboard, under Settings > Devices, reports collected Windows patch state for managed devices within the current access and filter scope.

The agent tracks more than whether updates are outstanding. Per device it records current health, when it last checked, the last error, which updates failed, and whether a reboot is pending after installing.

That distinction is the value of the screen: it separates three populations that look alike in a simple count.

Population Meaning
Up to date No issue in the reported status band; still verify scope and freshness
Behind Updates outstanding, update mechanism working
Unhealthy The update stack itself is broken — will stay behind until repaired

The current quality-status calculation uses the reported last-update age: Current up to 7 days, Exposed above 7 through 15 days, Critical above 15 days, and Unknown without a date. These are reporting bands, not a per-vulnerability verdict or proof that a configured Intune deferral has been evaluated.

When an update requires a restart, installation alone does not establish that the update is fully applied. The dashboard shows this separately, because it is a different action — someone has to restart the machine, and users defer that indefinitely.

Updates can be installed from the panel, and users can be prompted directly — see monitoring and update management for what the user sees when they are.

See Windows patch management for the customer workflow that connects reported status, failed installations, update policy and post-change verification. Keep agent commands, Intune rings, application updates and restart outcomes distinct.