
Since May 2026, Windows Autopatch installs security updates by default without a restart, using hotpatch. Eight of the twelve monthly updates now go through without interruption. What does your device fleet need, how do you check readiness in Intune, and when is a restart still required?
Restart required. Three words every employee recognises at the worst moment: mid-presentation, just before a client call, or right before a deadline. Security updates have followed the same pattern for decades: install patch, reboot the system, wait. From May 2026 onwards, that changes for organisations managing Windows through Intune. Windows Autopatch enables hotpatch updates by default for all eligible devices, meaning eight of the twelve monthly security updates are now installed without a restart.
This is not an optional setting or an experimental mode. It is the new default. For IT teams, it means less scheduling overhead, fewer end-user complaints, and a significantly shorter window of vulnerability. This article explains how hotpatch works, which devices qualify, and what you can check right now in Intune.
A traditional security update replaces files on disk and then reloads the operating system to activate the changes in memory. That restart requirement exists because running processes still hold the old code. Hotpatch works differently: the patch is injected directly into the memory of the running operating system, without replacing files on disk or restarting processes.
This is possible because Windows Virtualization-based Security manages a protected memory area. The hotpatch update is loaded into that secured area and replaces the vulnerable code in running processes in real time. The result: the vulnerability is remediated without the user or the system noticing anything.
Hotpatch targets only security-relevant code changes in the Windows kernel and core components. Feature changes, quality fixes, and driver updates are out of scope. That makes the updates narrower in nature, more targeted, and with a significantly lower risk of side effects than a full cumulative update.
Windows Autopatch follows a quarterly cycle. In four baseline months per year — January, April, July, and October — Windows installs a cumulative update that bundles all changes from the preceding quarter. That update requires a restart, because the baseline contains code changes that cannot be applied via hotpatch. This is unavoidable but limited: once per quarter, at a predictable and plannable moment.
In the remaining eight months — February, March, May, June, August, September, November, and December — only hotpatch updates are deployed. No restart required. Devices that have installed the quarterly baseline receive the monthly security fix without interruption.
Microsoft estimates that the time to reach 90 per cent of devices patched is halved with hotpatch compared to the traditional approach. In practice, the vulnerable window stays open for a shorter period, measurably reducing the attack surface for organisations.
Exceptions are possible. In June 2026, Microsoft had to roll out an additional baseline update for certain device groups due to the severity of CVE-2026-45585, which required an unexpected restart. Such exceptions are rare but unavoidable when a vulnerability is of a nature that cannot be remediated via hotpatch. Communicate this proactively to users so that the exception does not undermine confidence in the normal hotpatch rhythm.
Not all devices in your Intune environment qualify automatically. Four requirements must be met for a device to receive hotpatch updates.
Operating system: Windows 11 version 24H2 or later is required. Devices still running Windows 11 23H2 or earlier, or Windows 10, do not receive hotpatch updates. Virtualization-based Security: VBS must be enabled. VBS is active by default on modern hardware purchased in the past four years, but can be blocked by incompatible drivers, older BIOS configurations, or third-party security software.
Licensing: hotpatch via Windows Autopatch is available for devices with a Windows Enterprise licence or certain Microsoft 365 bundles, including Business Premium. Finally, enrolment: the device must be enrolled in Windows Autopatch via an Intune quality update policy that has hotpatch enabled. Devices managed via WSUS or Configuration Manager without Intune integration fall outside the scope.
In the Microsoft Intune admin centre, the Hotpatch quality updates report provides per-device insight. Two columns are most relevant: Hotpatch Readiness and Hotpatch Enabled. The first column shows whether a device technically qualifies; the second confirms that hotpatch is active for that device.
Devices with a lower Windows version or with VBS disabled appear as not ready. For those devices, a traditional security update with restart requirement is deployed until the prerequisites are met. Filter the Hotpatch Readiness column on Not Ready and analyse the cause per device: OS version, VBS status, or missing policy configuration. This gives an accurate picture of the remaining migration work.
Devices not yet on the latest quarterly baseline will first receive that baseline update including a restart, before becoming eligible for the next hotpatch month. Recently reinstalled or newly enrolled devices will therefore always go through one restart cycle before being placed on the hotpatch schedule.
Organisations not yet ready for hotpatch by default can opt out via a tenant-wide setting in the Intune admin centre. Individual device groups can also be excluded via update policy. Microsoft made this opt-out available from April 2026 as a transition option.
Valid reasons for temporary deferral are limited but real. If a substantial portion of the device fleet uses VBS-incompatible drivers, it may be logical to resolve the driver issue before broadly embracing hotpatch. Existing test procedures for baseline updates must also be adapted to account for the new rhythm of four baselines and eight hotpatch months per year.
Outside those specific scenarios, disabling hotpatch offers few benefits. The updates are narrower in scope, more targeted at security, and fully tested by Microsoft before deployment. The risk of application disruption from a hotpatch is considerably lower than from a traditional cumulative update, because feature changes remain out of scope.
Open the Hotpatch quality report in Intune and filter on Not Ready. Inventory why devices do not qualify: Windows version, VBS blockage, or missing policy. This determines the scope of the remaining migration work.
Plan the Windows 11 24H2 migration for devices still running an older version. Until that step is taken, that group will not benefit from hotpatch. Tie this to your regular hardware refresh cycle or your planned feature update rollout.
Communicate internally that the quarterly baseline restart remains, but that eight months per year no longer require an update-related restart. This lowers user resistance and increases the speed at which patches are accepted. Need help configuring your Windows Autopatch and Intune update policies or analysing the readiness of your device fleet? Contact Zarioh.
Zarioh Digital Solutions
IT specialists from Utrecht, the Netherlands. We help businesses with Microsoft 365, AI agents, hosting and telephony — and share what we learn in practice. Follow us on LinkedIn

Microsoft 365

Microsoft 365

Microsoft 365