I have about 1,500 devices enrolled in Intune, but WSUS is still our primary patching system. Some devices show different OS versions in the two systems—for example, Intune reports 10.0.19045.6456 while WSUS reports 10.0.19041.6093. The device's last WSUS reporting time is today, so why don't the build numbers match?
3 Answers
A current WSUS reporting timestamp only proves that the client checked in; it doesn’t guarantee that every inventory field has been refreshed or that WSUS is displaying the same build information as Intune. The two services collect and expose device data differently, and WSUS can retain stale or less precise OS-version metadata even while update status is current. Check the actual build locally or through Intune, and review the Windows Update and WSUS client logs if the discrepancy affects patch compliance.
Using cloud update management doesn’t necessarily mean every device must download the full update directly over the internet. Delivery Optimization, peer caching, update rings, and bandwidth policies can reduce external traffic. It may be worth comparing those controls with the operational cost of continuing to rely on WSUS for a large Intune-managed fleet.
WSUS is also a declining platform from Microsoft’s perspective, so reporting inconsistencies and other limitations are becoming more noticeable. Windows Update for Business or Autopatch may provide better alignment with Intune, although they generally require clients to obtain update content from Microsoft’s cloud rather than exclusively from an internal WSUS server.

Bandwidth is the main reason we still use WSUS, so any move to cloud-based updating would need careful testing and throttling rather than an all-at-once change.