Favorite your Message Center and Roadmap items. Access them anytime via your Profile. Export and share with your team or your LLM.

Windows Autopatch is enabling hotpatch updates by default

Message ID
MC1247859
View in Message Center
Service
Windows
Category
Stay Informed
Tag
Admin impact
Rollout
April 2026May 2026

Details

Starting with the May 2026 Windows security update, Windows Autopatch is enabling hotpatch security updates by default because they are the quickest way to get secure. This change in default behavior will impact all eligible Microsoft Intune devices. Additional IT controls are coming in April. 
 
When will this happen: 
  • Devices will start receiving hotpatch updates by default with the May 2026 Windows security update. 
  • The tenant setting to opt out of hotpatch updates is scheduled to go live on April 1, 2026. 
 
How this will affect your organization: 
Devices that meet hotpatch prerequisites will get secure faster because full Windows security updates are applied without waiting for a restart. Devices are secured as soon as the update is installed. You don’t need to wait for devices to restart, saving on average three to five days. 
 
Devices will restart during baseline months, which are January, April, July, and October. 
 
What you need to do to prepare: 
If you already use Windows Autopatch, no action is needed to get hotpatch updates enabled by default. We recommend keeping hotpatch updates enabled for your devices. 
To maximize the number of devices receiving hotpatch updates, ensure they meet prerequisites. Most commonly, this means enabling Virtualization-based Security (VBS) for x86 devices. 
  
If you’re not ready for this change, you can opt out groups of devices using Quality Update policies or the whole tenant.  
 
Additional information: 
Learn more about hotpatch updates with the following resources:   

Change History

Show
No change history available

Never Miss a Microsoft 365 Update

Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.