A security consultant is advising a company that uses Windows Update for Business to manage Windows 10 devices. The company wants to ensure that devices receive feature updates only after they have been validated by the IT team, but without using Configuration Manager. Which WUfB feature should the consultant recommend to achieve this controlled rollout?
Deployment rings allow grouping devices into rings with different deferral periods. By assigning a pilot ring with a short deferral and a broad ring with a longer deferral, IT can validate the update on the pilot ring before it reaches the broader ring. This provides a controlled rollout without Configuration Manager. It is the recommended WUfB approach for validation.
Why this answer
Deployment rings with staggered deferral periods are the WUfB feature that enables a controlled rollout. By placing a small set of devices in a pilot ring with a short deferral and the rest in a broad ring with a longer deferral, IT can validate the feature update on the pilot ring before it reaches the broader population. This achieves validation without Configuration Manager.
Other options are for early access, bandwidth optimization, or reporting.
Exam trap
The trap here is confusing Windows Insider Program for Business with production deployment rings; Insider is for pre-release testing, while rings are for staged rollout of released updates.