Windows 9 Update separates feature deferrals from security patches

Microsoft has confirmed that the next iteration of Windows 9 Update introduces a clearer split between the way the operating system handles annual feature releases and the way it handles monthly security patches. Users can now choose to push back feature updates by several months, while security fixes continue to install on the usual schedule. The change is being rolled out across consumer, business, and education editions, and it lands alongside a refreshed policy engine that gives administrators more granular control over what reaches a machine and when.

For Australian households and small businesses, the new behaviour answers a long-running complaint about forced upgrades interrupting work, study, or evening streaming sessions. It also reassures anyone worried that holding back a feature update might leave a device exposed to the latest vulnerabilities. The framework keeps the safety net firmly in place while giving people breathing room on the cosmetic and productivity changes that arrive twice a year.

The controls live in the Windows Update settings panel, under a redesigned Advanced Options area. From there, a user can pick how long to defer feature updates, ranging from a few weeks up to almost a year. The same screen makes it plain that security patches cannot be paused or postponed using this method, and clicking the link reveals the reasoning behind the policy.

Inside the new deferral framework

When a user opens Windows 9 Update settings and selects Advanced Options, the new deferral menu appears as the first choice. A slider lets the user pick a deferral window of one, two, three, or more months, with the longest setting stretching close to twelve. Once selected, any feature update targeting the current branch is held back until the chosen window expires.

Beneath the slider sits a clearly worded note explaining that the deferral applies only to feature updates. Security patches, definition updates for Microsoft Defender, and servicing stack updates remain on the standard cadence. This separation reflects Microsoft's position that vulnerabilities should not be allowed to linger simply because a user prefers a more conservative feature experience.

Australian users running machines in AEST or AEDT will notice that the deferral countdown aligns with local calendar days rather than a fixed UTC offset. That means if you set a four-week deferral on a Wednesday arvo, the next feature update will be offered on the equivalent weekday four weeks later, regardless of daylight saving transitions in states like New South Wales, Victoria, or Tasmania.

Why security patches stay non-negotiable

Microsoft's product team has been unusually direct on why security updates cannot be deferred in the same way as feature updates. The reasoning is straightforward: every Patch Tuesday ships fixes for vulnerabilities, some of which are actively being exploited in the wild. Holding those back, even for a few weeks, leaves a window in which attackers can target unpatched machines.

This stance mirrors guidance from regulators such as the Australian Cyber Security Centre, which regularly reminds households and businesses that timely patching is one of the most effective defences against ransomware and credential theft. By keeping security updates outside the deferral system, the platform removes the temptation to "pause everything" when a new bug emerges, a habit that has historically left systems exposed for far too long.

The platform reserves a small exception for situations where a known regression is being investigated. In those rare cases, a temporary safeguard can be applied through Microsoft's known issue rollback feature, but this is handled out of band and does not require the user to skip patches entirely.

How Australians are responding to the change

Early chatter on Australian tech forums and in community Slack groups suggests a broadly positive reception. Many users in Sydney, Melbourne, and Brisbane have long complained about feature updates arriving during peak work hours and disrupting video calls or compilation jobs. The new deferral option lets them schedule those larger downloads for weekends or quieter periods.

There is also a cultural fit with the way Australians tend to manage software. The phrase "she'll be right" often sums up a relaxed attitude toward minor UI changes, but the same attitude does not extend to security. Splitting the two categories respects that distinction: let the features settle in their own time, but keep the locks changed promptly.

A few local system integrators have noted that some clients running older custom line-of-business applications in regional Victoria and South Australia had been refusing feature upgrades for years. With the new framework, those clients can now adopt a structured deferral instead of disabling Windows Update entirely, which previously left the machines exposed. The third-party update toolkit circulating in community channels has been quietly helping small workshops in these regions manage the transition without disrupting legacy software.

Update deferral options at a glance

The table below summarises how each update category is handled under the new framework. Security-related items remain outside the user's deferral control, while feature and driver updates respect the chosen window.

Update category Can be deferred? Typical cadence Reaches device when
Security patches No Monthly (Patch Tuesday) Immediately after quality validation
Servicing stack updates No As needed With the next Patch Tuesday or out-of-band release
Feature updates Yes, up to roughly 12 months Annually or semi-annually After the chosen deferral window expires
Driver updates Yes Varies by manufacturer After deferral window or manually installed
Microsoft Defender definitions No Several per day Within hours of release

For most readers, the practical takeaway is simple: anything that protects the device arrives on schedule, while anything that reshapes the experience can be timed to suit. That single distinction is what the rest of the platform changes are designed to support.

Pause updates versus defer feature updates

It is worth distinguishing between the long-standing Pause updates toggle and the newer deferral feature. Pause is a temporary stop on all updates, including security patches, and is intended for short troubleshooting sessions. Deferral, by contrast, is a longer-term policy that applies only to feature updates and respects the security cadence throughout. Many Australian users have been unknowingly using Pause as a workaround for feature update fatigue, which inadvertently left them unpatched for weeks.

The two controls now sit next to each other in the Settings app, with tooltip text clarifying the difference. Microsoft has added the same clarification to its Australian support pages and the local help documentation maintained by its Sydney office, which has been fielding questions from confused small business owners since the rollout began.

Enterprise and group policy implications

For IT administrators, the new framework arrives as part of the existing Windows Update for Business policy set. Group Policy and Microsoft Intune both expose the deferral window as a configurable integer, with separate values for feature updates and quality updates. Quality updates, which encompass security patches, default to zero days of deferral and cannot be raised through this path.

Larger Australian enterprises, particularly those with branches spread across Perth, Adelaide, and Hobart where bandwidth can be patchy, have welcomed the explicit separation. They can now confidently let security patches fly through while keeping major feature upgrades staged for change windows that suit their rollout schedule. The result is a tighter security baseline without sacrificing the orderly deployment of new features to fleets that might include thousands of endpoints.

Practical recommendations for Australian users

For users who want a steady, predictable machine, the recommendation is to set a moderate deferral of one or two months. This gives Microsoft time to ship any follow-up fixes to a freshly released feature update before it reaches your device, while still keeping you on a current branch within the year. Anything longer than four months tends to drift the device toward the end of support sooner than expected, particularly for editions that follow the 18 or 24-month servicing lifecycle.

It also pays to keep an eye on the Windows Update tray icon. When security-only updates are downloading, the label will clearly state Security rather than the generic Updates available wording of older builds. Paying attention to that small detail helps Australian households, especially those juggling school laptops and home office desktops, stay aware of what is arriving and when, without needing to open the full settings panel.