TL;DR
- What changed: Starting with the May 2026 security update, hotpatch is enabled by default in Windows Autopatch for all eligible devices managed by Intune.
- What hotpatch does: Security updates that install without requiring a device restart. Microsoft estimates this cuts the time to reach 90% patch compliance roughly in half β from 3β5 days to near-immediate.
- What you need to do: Check device eligibility (Windows 11 24H2, VBS enabled, April baseline installed). Decide whether to let the default run, limit it to specific groups, or opt out at the tenant level.
- Key dates: April 1 β opt-out toggle becomes available in Intune. May 11 β hotpatch deployments begin for eligible devices.
- Existing configs are safe: Update rings, deferrals, and existing quality update policies are not changed. The new default only applies to devices with no quality update policy assigned.
The annual update cycle with hotpatch
4 baseline months per year (restart required), 8 as hotpatch candidates (no restart). The pattern repeats every quarter.
Key Dates: What Happens and When
VirtualizationBasedTechnology CSP in Intune. Devices without VBS show "Hotpatch β VBS not running" in the Autopatch report.What to Do Before May 11
- Run the Hotpatch quality updates report in IntuneDevices β Monitor β Windows quality updates β Hotpatch quality updates report. Understand which devices are eligible, which have VBS enabled, and which still need the April baseline.
- Check VBS status across eligible devicesVBS is the prerequisite I see missing most often. Devices without it won't receive hotpatch β they fall back to standard LCU. If you have a large number of affected devices, consider enabling VBS via CSP now. It's also a security baseline control worth having regardless of hotpatch.
- Identify devices without a quality update policy assignedThe new default applies to unassigned devices. Find them, and decide whether to add them to an existing ring or let the default cover them.
- Validate critical applications with their vendorsHotpatch modifies how patches are applied at kernel level. Applications with kernel-mode drivers or low-level components may behave differently. If you have business-critical software with kernel dependencies, confirm vendor support for hotpatch on Windows 11 24H2 before May.
- Confirm your rollback processAutopatch supports pausing and rolling back updates. Before enabling hotpatch at scale, make sure you know how to pause a rollout, remove a specific hotpatch update, and escalate to Microsoft Support if needed. Have the playbook ready before the first deployment.
- Make a conscious decision: enable, limit to groups, or opt outFrom April 1 you have three options: let the default run, configure hotpatch per group via quality update policies, or opt out at the tenant level. Don't let this decision happen by default without a deliberate choice.
Tenant-level opt-out (available from April 1)
1. Open the Microsoft Intune admin center
2. Navigate to:
Tenant administration β Windows Autopatch β Tenant management
3. Select the Tenant settings tab
4. Find the toggle:
"When available, apply updates without restarting the device (hotpatch)"
5. Set to Block to opt out for the entire tenant
Set to Allow to keep hotpatch enabled (default)
Per-group opt-out via quality update policy
1. Navigate to:
Devices β Manage updates β Windows updates β Quality updates
2. Create or edit a Windows quality update policy
3. In Settings, configure:
"When available, apply without restarting the device (hotpatch)" β Block
4. Assign the policy to the relevant Entra ID group
5. Policy-level settings take precedence over the tenant default
β You can have hotpatch enabled for some groups and blocked for others
