Sarah Williams, you need to configure three separate Update rings for Windows 10 and later policies within Microsoft Intune and map the deferral values accordingly. For your IT department ring, set the Feature update deferral period (days) to 0 so they receive availability immediately upon Microsoft release. For your pilot testing ring, set this deferral value to 10 & for your broad production ring, assign a value of 30, which ensures the update is withheld from those devices until the specified time has elapsed.
To enforce this deployment timeline strictly and prevent users from delaying installations indefinitely, you should couple these deferrals with specific deadline and grace period settings located within the user experience section of the same update ring policies. Setting a feature update deadline to 7 days and a grace period to 2 days means that once the deferral period expires& the update becomes available to a device, the user has a maximum of 7 days to install it at their convenience before installation is forced, followed by a 2days grace period before a mandatory restart occurs. If this configuration layout addresses your deployment strategy and helps clarify the implementation across your three distinct rings, please consider marking it as Accept Answer so others with the same issue can find the solution. Feel free to leave a comment if you need further information.
Tracy Le.