RCWRCW IT TrainingFree hands-on labs & simulators← Back to home
Microsoft Intune · Step-by-step guide

Windows Autopatch Hotpatching & Update Readiness: A Setup Guide

Apply security updates without reboots — enabled by default since May 2026 — and monitor with Update Readiness.

Published August 29, 2026 · RCW IT Training

What it is and why it matters

Starting with the May 2026 Windows security update, hotpatch security updates are enabled by default for eligible devices managed through Intune / Windows Autopatch. Hotpatch applies security updates without a reboot.

Update Readiness is also generally available, with tenant-wide visibility, per-device details, centralized alerts with remediation guidance, and an Update Readiness Checker.

Device eligibility

  • Windows 11 Enterprise 24H2 or later
  • The latest quarterly baseline cumulative update installed
  • Updates deployed through an Intune Windows quality update policy (or Autopatch)

Step 1 — Check which devices are eligible

Go to Devices > Manage updates > Windows updates and open the Hotpatch quality updates report to confirm which devices have the baseline and meet prerequisites.

Step 2 — Set the tenant-level default

  1. Go to Tenant administration > Windows Autopatch > Tenant management.
  2. Select the Tenant settings tab.
  3. Set When available, apply updates without restarting the device (hotpatch) to Allow or Block.

Step 3 — Override per policy (optional)

  1. Go to Devices > Manage updates > Windows updates > Quality updates.
  2. Select Create and choose Windows quality update policy.
  3. On the Settings tab set the hotpatch toggle to Allow or Block.
  4. Assign the policy to the Microsoft Entra groups for those devices.

The policy level overrides the tenant default.

Step 4 — Schedule the baseline update

Ensure out-of-date devices install the quarterly baseline first — devices only receive hotpatch updates once the baseline is in place. Stagger baseline installs (pilot rings first) to control impact.

Step 5 — Monitor with Update Readiness

Open the Update Readiness dashboards under Windows Autopatch and use the tenant-wide view, per-device details, alerts with remediation guidance, and the Update Readiness Checker.

Verify it works

  1. Confirm eligible devices appear Ready in the Hotpatch quality updates report.
  2. After the next monthly security release, verify updates installed without a restart.
  3. Spot-check that non-eligible devices fell back to standard cumulative updates.

Troubleshooting notes

Device not getting hotpatch

Verify Windows 11 Enterprise 24H2+, the quarterly baseline is installed, and the quality update policy allows hotpatch.

Reboots still happening

Hotpatch covers security updates only — feature updates and some non-security fixes still require restarts.

Two control levels

Tenant-level (Autopatch > Tenant management) and policy-level (Quality updates policy) — the policy level overrides the tenant default.

Learn more

Key takeaway: Hotpatch security updates are on by default from May 2026 for eligible Windows 11 Enterprise devices — verify eligibility with the Hotpatch report and use tenant- or policy-level toggles to control it.