← Back to blog
Microsoft 365

Windows Hotpatch enabled by default: security updates without restart from May 2026

By Zarioh Digital Solutions·3 April 2026
Share
Windows Hotpatch enabled by default: security updates without restart from May 2026

Microsoft will automatically enable Windows Hotpatch in May 2026 for all Intune-managed devices. Security updates will be installed without a restart, applied directly to running processes in memory. IT administrators who are not yet ready must act before 11 May.

Anyone managing a Windows device through Microsoft Intune will soon face a significant change. Microsoft will enable Windows Hotpatch by default in May 2026 for all devices managed through Windows Autopatch. This means security updates will be installed without requiring the device to restart.

What is Windows Hotpatch?

Windows Hotpatch is an update technology where security patches are applied directly to active processes in memory, without requiring a restart. The patch is layered on top of the running code. This differs fundamentally from the traditional method where the update is installed and changes only take effect after a restart.

The result is that devices are protected immediately after the patch is deployed, without users having to interrupt their work. Microsoft reports that the average time to fully patch 90 percent of devices in an organisation decreases significantly, from weeks to days.

Which devices are eligible?

Hotpatch does not work on every device. Requirements are: Windows 11 version 22H2 or higher, device enrolled in Microsoft Intune, device joined to Microsoft Entra ID, and the April 2026 baseline update must be installed before hotpatch can become active.

What changes for IT administrators?

Microsoft will automatically activate hotpatch on 11 May 2026 for all eligible devices. From 1 April 2026, an opt-out button is available in the Intune admin centre under Windows Updates. Organisations that deliberately want to opt out of automatic activation must configure this before 11 May.

What does this mean for the user experience?

For most users, little changes visibly. They will no longer receive notifications about a scheduled restart for security updates, which is generally seen as an improvement. Updates are applied more quietly and quickly, without users needing to save their work and interrupt their activities.

Want to know whether your environment is ready for Windows Hotpatch and what you need to arrange before 11 May? Contact Zarioh for a quick assessment.

← Back to all articles
Share