Windows Autopatch Hotpatching & Update Readiness: A Setup Guide
Apply security updates without reboots — enabled by default since May 2026 — and monitor with Update Readiness.
What it is and why it matters
Starting with the May 2026 Windows security update, hotpatch security updates are enabled by default for eligible devices managed through Intune / Windows Autopatch. Hotpatch applies security updates without a reboot.
Update Readiness is also generally available, with tenant-wide visibility, per-device details, centralized alerts with remediation guidance, and an Update Readiness Checker.
Device eligibility
- Windows 11 Enterprise 24H2 or later
- The latest quarterly baseline cumulative update installed
- Updates deployed through an Intune Windows quality update policy (or Autopatch)
Step 1 — Check which devices are eligible
Go to Devices > Manage updates > Windows updates and open the Hotpatch quality updates report to confirm which devices have the baseline and meet prerequisites.
Step 2 — Set the tenant-level default
- Go to
Tenant administration > Windows Autopatch > Tenant management. - Select the Tenant settings tab.
- Set When available, apply updates without restarting the device (hotpatch) to Allow or Block.
Step 3 — Override per policy (optional)
- Go to
Devices > Manage updates > Windows updates > Quality updates. - Select Create and choose Windows quality update policy.
- On the Settings tab set the hotpatch toggle to Allow or Block.
- Assign the policy to the Microsoft Entra groups for those devices.
The policy level overrides the tenant default.
Step 4 — Schedule the baseline update
Ensure out-of-date devices install the quarterly baseline first — devices only receive hotpatch updates once the baseline is in place. Stagger baseline installs (pilot rings first) to control impact.
Step 5 — Monitor with Update Readiness
Open the Update Readiness dashboards under Windows Autopatch and use the tenant-wide view, per-device details, alerts with remediation guidance, and the Update Readiness Checker.
Verify it works
- Confirm eligible devices appear Ready in the Hotpatch quality updates report.
- After the next monthly security release, verify updates installed without a restart.
- Spot-check that non-eligible devices fell back to standard cumulative updates.
Troubleshooting notes
Verify Windows 11 Enterprise 24H2+, the quarterly baseline is installed, and the quality update policy allows hotpatch.
Hotpatch covers security updates only — feature updates and some non-security fixes still require restarts.
Tenant-level (Autopatch > Tenant management) and policy-level (Quality updates policy) — the policy level overrides the tenant default.