Is anyone seeing Windows updates repeatedly fail and roll back on devices managed across multiple customer environments? The affected machines install an update, fail during reboot, roll back, allow the user to sign in, and then repeat the same cycle on the next restart. Patching is normally controlled through NinjaOne, but all of the affected customers also have devices enrolled in Intune. We suspect Intune's automatic hotpatch configuration may be forcing a problematic July update, apparently the one ending in 650, even though that update was rejected in NinjaOne. The issue seems especially common on Dell systems. Has anyone confirmed whether hotpatching is responsible, found a reliable remediation, or identified another conflicting management or security product?
4 Answers
Do the affected clients have application-control software such as ThreatLocker installed? We saw a similar combination involving Dell hardware, ThreatLocker, and a hotpatch. It may not be an Intune-only problem—the security agent could be blocking a driver or update component during the reboot, which then causes Windows to roll back.
NinjaOne will effectively lose control when another management platform is configuring Windows Update. It does not necessarily have to be Intune—any competing update policy can override or conflict with NinjaOne. I’d compare the Windows Update and hotpatch policies on the affected machines and confirm which service is actually approving and installing the update.
We’ve run into something similar, including a few machines that ended up in repeated blue-screen loops. The pattern looked like a hotpatch being applied even though the normal patching tool had not approved it, so checking Intune’s global hotpatch settings and removing conflicting Windows Update policies was where we focused first.
The July update ending in 650 was reported as incompatible with the Intel Innovation Platform Framework driver on some Dell devices. Microsoft later addressed the issue with an out-of-band update, KB5121767. It may be worth reassessing the rejected-update policy and making sure the Dell systems have the replacement update and current Intel IPF drivers before continuing to block the original package.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures