Skip to content
anavem.com logoanavem.com logo
ReleaseWindows Autopatch hotpatch default for Intune devicesLow severityNewsMicrosoft 365

Microsoft Enables Windows Hotpatch by Default for Eligible Intune Devices

The shift moves eligible enterprise fleets from opt-in to opt-out for restart-free patching; devices that don't meet the prerequisites keep patching as before.

On this page

Key takeaways

  • Hotpatch is on by default for eligible Intune/Graph-managed devices from the May 2026 update.
  • Tenant opt-out controls became available April 1, 2026; deployments began after May 11.
  • Eligible devices get monthly security fixes without a reboot (baseline updates still require one).
  • Microsoft says this can reach 90% compliance in about half the time.
  • Devices that don't meet the prerequisites - and consumer/unmanaged PCs - patch as before.

What to do now

Medium urgency
  1. Confirm devices meet prerequisites (Windows 11 24H2+, VBS, eligible license, current baseline) using Intune readiness reports.
  2. Decide whether to accept the default or opt out at the tenant or per-policy level.
  3. Pilot with a representative group and validate LCU-fallback/rollback before broad acceptance.

Microsoft is making restart-free security patching the default for eligible enterprise devices. Starting with the May 2026 Windows security update, Windows Autopatch enables hotpatch security updates by default for eligible devices managed through Microsoft Intune or the Microsoft Graph API - applying monthly security fixes to running systems without an immediate reboot. Announced on March 10, 2026, the change moved eligible fleets from opt-in to opt-out; tenant-level controls to block it became available April 1, 2026, with a grace period until May 11 before deployments began.

For IT teams, the operational upside is fewer forced reboots and faster compliance, but the shift to opt-out means admins must confirm device eligibility, review governance, and decide whether to accept the default or exclude specific groups.

From the May 2026 update, Windows Autopatch enables hotpatch by default for eligible Intune-managed devices, delivering restart-free monthly security fixes unless admins opt out.

Windows Autopatch now enables hotpatch by default for eligible Intune/Graph devices (from the May 2026 update). Monthly fixes install without a reboot; quarterly baselines still need one. Opt-out arrived April 1, 2026, with a grace period to May 11. Prerequisites (24H2, VBS, eligible license) apply.

Affected & context

Event summary

Microsoft announced on March 10, 2026 that, starting with the May 2026 Windows security update, Windows Autopatch enables hotpatch security updates by default for eligible devices managed through Microsoft Intune or the Windows updates API in Microsoft Graph. Hotpatch applies monthly security fixes to running systems without an immediate restart. Tenant-level opt-out controls became available April 1, 2026, and because April is a baseline month, admins had until May 11, 2026 before hotpatch deployments began under the new default.

Why it matters

This flips eligible enterprise fleets from opt-in to opt-out for restart-free patching. Microsoft says applying fixes without waiting for a reboot can get organizations to 90% compliance in half the time, but it also shifts responsibility onto admins to validate prerequisites and governance.

Who is affected

Organizations using Windows Autopatch via Intune (or Graph) with devices that meet the hotpatch prerequisites. Devices that don't meet the prerequisites, and consumer or unmanaged PCs, continue to patch as they do today.

Vendors
Microsoft
Products
Windows AutopatchMicrosoft IntuneWindows 11 Enterprise 24H2+
Geography
Global
Industry
Any organization using Microsoft Intune / Windows Autopatch

What changed

Windows Autopatch - the service that orchestrates Windows quality updates for Intune-managed fleets - now enables hotpatch security updates by default for eligible devices, starting with the May 2026 Windows security update. The change applies whether an organization uses Autopatch through Microsoft Intune or the Windows updates API in Microsoft Graph. Previously opt-in, hotpatch is now the default behavior for eligible devices unless an administrator explicitly opts out. Microsoft made the controls to block it available on April 1, 2026, and because April is a hotpatch baseline month, organizations had until May 11, 2026 to review and adjust before any hotpatch updates deployed under the new default.

  • Hotpatch on by default for eligible Intune/Graph devices from the May 2026 update.
  • Opt-out controls available April 1, 2026; grace period to May 11.
  • Moves eligible fleets from opt-in to opt-out.

How hotpatch works

Hotpatch applies monthly security fixes to code already running on the device, so the update takes effect without an immediate restart. It works on a quarterly rhythm: a baseline cumulative update (which does still require a reboot) is followed by monthly hotpatch updates that install silently between baselines. In practice that means eligible devices need roughly four baseline reboots a year for security patching instead of twelve, while still receiving monthly fixes. Hotpatch packages are also smaller than standard cumulative updates, so they install faster and use less bandwidth. Microsoft says applying fixes without waiting for a restart can get an organization to 90% compliance in about half the time, closing the window attackers exploit between patch release and full deployment.

  • Monthly hotpatch updates install without a reboot; quarterly baselines still require one.
  • About four baseline reboots per year instead of twelve.
  • Microsoft cites ~50% faster time to 90% compliance.

Which devices are eligible

The default applies only to devices that meet Microsoft's hotpatch prerequisites - not to every Intune-managed device. Eligible devices must run Windows 11 Enterprise version 24H2 or later, be managed by Windows Autopatch via Intune (or Graph), have Virtualization-Based Security (VBS) enabled (Microsoft notes this is most commonly the step needed for x86 devices), hold an eligible license (Windows 11 Enterprise E3/E5, Microsoft 365 F3, Windows 11 Education A3/A5, Microsoft 365 Business Premium, or Windows 365 Enterprise), and have the current quarterly baseline installed. Devices that don't meet the prerequisites automatically continue to receive the standard Latest Cumulative Update as before. ARM64 devices need a one-time step to disable CHPE binaries, and Microsoft has stated there are no plans to support hotpatch on Arm64 devices with CHPE enabled.

  • Requires Windows 11 Enterprise 24H2+, VBS, an eligible license, and the current baseline.
  • Non-eligible devices keep receiving the standard cumulative update.
  • ARM64 requires disabling CHPE; not supported with CHPE enabled.

What admins should do

If you already use Windows Autopatch and want hotpatch on, no action is needed - Microsoft recommends keeping it enabled. To opt out at the tenant level, open Microsoft Intune > Tenant administration > Windows Autopatch > Tenant management, select the Tenant settings tab, and toggle "When available, apply updates without restarting the device (hotpatch)" to Block. Policy precedence matters: if a device belongs to a Windows quality update policy, that policy's hotpatch setting overrides the tenant default - so you can opt the tenant out but allow hotpatch for specific groups, or the reverse. Before accepting the default, verify devices meet the prerequisites (use the Hotpatch quality updates and Quality update status reports in Intune), confirm VBS is enabled across the fleet, validate licensing, and pilot with a representative group, testing LCU-fallback and rollback procedures.

  • Opt out via Intune > Tenant administration > Windows Autopatch > Tenant management > Tenant settings > Block.
  • Quality update policies override the tenant-level default per device group.
  • Use the Hotpatch quality updates report to confirm readiness.

Existing update ring and deferral settings are respected; enabling hotpatch doesn't change them.

What to watch

Hotpatch is proven - it already runs on more than 10 million production devices - but flipping a default at scale is an operational decision. Some hotpatch releases have carried narrow known-issue advisories affecting specific scenarios (for example, certain connectivity or tooling interactions), so regulated environments and those with custom drivers or legacy software should validate before broad acceptance. The change also reinforces a broader pattern: advanced servicing capabilities are increasingly tied to specific Windows editions, licensing, and cloud management via Intune/Autopatch - worth factoring into licensing and governance reviews. Consumer PCs (Windows 11 Home/Pro), unmanaged business devices, and systems not enrolled in Intune/Autopatch are unaffected, and Microsoft has not announced hotpatch defaults for consumer editions.

  • Some hotpatch releases have had narrow known-issue advisories - pilot first.
  • Consumer and unmanaged devices are unaffected.

Timeline

  1. Change announced

    Microsoft announces via the Windows IT Pro blog and Message Center MC1248388 that hotpatch will be enabled by default for eligible Intune devices from the May 2026 update.

    Source: Microsoft Windows IT Pro blog / MC1248388

    Confidence: High

  2. Opt-out controls go live

    Tenant-level controls to block the hotpatch default become available in Intune; April is also a hotpatch baseline month.

    Source: Microsoft Windows IT Pro blog

    Confidence: High

  3. Default takes effect

    Hotpatch updates begin deploying under the new default for eligible devices not explicitly excluded, starting with the May 2026 security update.

    Source: Microsoft / BleepingComputer

    Confidence: High

Impact

Eligible Intune-managed Windows 11 fleets now receive monthly security fixes without a reboot by default, cutting forced restarts and improving time-to-compliance - while requiring admins to validate eligibility and governance or opt out.

Business impact

Fewer user interruptions and faster patch compliance for eligible fleets; potential licensing/governance review to confirm eligibility.

Technical impact

Monthly security updates apply without restart on eligible devices; quarterly baselines still require a reboot; non-eligible devices keep receiving standard cumulative updates.

Security impact

Shorter exposure window between patch release and compliance for eligible devices.

Affected audience: IT admins and MSPs managing Windows via Intune/Autopatch, Security and compliance teams, Licensing/governance owners

Action required.

Technical details

Technical references

Response

Vendor statement

Microsoft says Windows Autopatch is enabling hotpatch by default because it is the quickest way to get secure, recommends keeping it enabled, and notes admins can opt out at the tenant level or allow it for specific device groups via quality update policies.

Customer guidance

Confirm device eligibility and the April 2026 baseline via Intune readiness reports; opt out at the tenant or policy level if not ready.

Response status: Acknowledged

FAQ

When does hotpatch become the default?

With the May 2026 Windows security update. Tenant-level opt-out controls became available April 1, 2026, and because April is a baseline month, admins had until May 11, 2026 before any hotpatch updates deployed under the new default.

Does this apply to all Intune devices?

Only to eligible devices. They must run Windows 11 Enterprise 24H2+, be managed by Windows Autopatch, have VBS enabled, hold an eligible license, and be on the current baseline. Devices that don't qualify keep receiving standard cumulative updates.

How many reboots does hotpatch save?

Eligible devices need roughly four baseline reboots a year instead of twelve, since monthly hotpatch updates install without a restart. Quarterly baseline updates still require a reboot.

How do we opt out?

In Microsoft Intune, go to Tenant administration > Windows Autopatch > Tenant management > Tenant settings and set the hotpatch toggle to Block. A quality update policy assigned to a device group overrides the tenant default.

Are consumer PCs affected?

No. Windows 11 Home/Pro, unmanaged devices, and systems not enrolled in Intune/Autopatch are unaffected and continue with the traditional restart-based update flow.

The bottom line

From the May 2026 security update, Windows Autopatch enables hotpatch by default for eligible Intune/Graph-managed devices, delivering monthly security fixes without a reboot. Opt-out controls arrived April 1, 2026, with a grace period to May 11. Prerequisites (Windows 11 Enterprise 24H2+, VBS, eligible licensing, current baseline) apply, and non-eligible or consumer devices are unaffected.

Restart-free monthly patching is now the default for eligible enterprise fleets - validate prerequisites and pilot before accepting it broadly, or opt out at the tenant or policy level.

What happens next

Confirm fleet eligibility and governance, decide whether to accept the default or opt out per policy, and watch Windows release health for any hotpatch known-issue advisories.

What to do

Check device eligibility in Intune readiness reports and set your tenant/policy hotpatch preference.

Sources

  1. Microsoft (Windows IT Pro Blog) · Mar 10, 2026 · Primary source

    Claims supported
    • Windows Autopatch enables hotpatch by default for eligible Intune/Graph devices from the May 2026 update.
    • Opt-out controls go live April 1, 2026; deployments begin after May 11; opt-out path and policy precedence.
  2. Microsoft 365 Message Center (archived) · Mar 10, 2026 · Primary source

    Claims supported
    • The change impacts all eligible Intune devices; VBS is commonly the prerequisite step for x86 devices.
    • No action needed if already using Autopatch and keeping hotpatch on; opt-out via Quality Update policies or tenant.
  3. Microsoft Learn · Jun 1, 2026 · Primary source

    Claims supported
    • Eligible licenses and prerequisites; non-eligible devices receive the standard LCU instead.
    • ARM64 requires disabling CHPE; hotpatch is not supported with CHPE enabled.
  4. BleepingComputer · Mar 10, 2026

    Claims supported
    • Autopatch runs on more than 10 million production devices; readiness can be checked via the Hotpatch quality updates report.
    • Admins have until May 11, 2026 before deployments begin under the new default.
Reader actions
Was this helpful?
Rate this articleRate
5 readers viewed this article

Reader reviews

Rate this articleBe the first to rate
No written reviews yetRate the article above, or be the first to share your experience.