Editing for clarity as I found more info out as I was writing this.
I am having trouble getting Update Rings settings to deploy to 1803 devices. It seems so far like any computers on 1803 fail to deploy the settings (I don't yet know if that means they also don't deploy the updates at all).
The setting they are failing on seems new in the April 15th Intune service update: " Block user from scanning for Windows updates". You can only set this to Block or Allow, there's no 'not configured' here.
In the relevant Event Log (Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin) the error is
MDM ConfigurationManager: Command failure status. Configuration Source ID: (C178B088-6AA6-44CB-9DC1-7A2C4D6AEC91), Enrollment Name: (MDMDeviceWithAAD), Provider Name: (Policy), Command Type: (Add: from Replace or Add), CSP URI:...