#Autopatch
Using Windows Autopatch?
You might need to take action!

#WUfB #Windows #WindowsAutopatch
February 4, 2025 at 9:57 AM
MC1478956: Microsoft Windows Autopatch: enhancements to update approval control and management capabilities

Windows Autopatch enhancements, rolling out Sept 1–Oct 15, 2026, offer…

https://blog.tophhie.cloud/message-center/mc1478956

#MicrosoftIntune #WindowsAutopatch #Microsoft365 #MessageCenter
September 25, 2026 at 1:01 AM
FYI: Hotpatching goes default in Windows Autopatch whether you like it or not
Hotpatching goes default in Windows Autopatch whether you like it or not
Microsoft insists rebootless updates are 'the quickest way to get secure' From the department of "what could possibly go wrong?" comes news that Windows Autopatch is enabling hotpatch security updates by default.…
dlvr.it
March 13, 2026 at 7:48 PM
Perfect T-Shirt for presenting a session on #Updates later today #Windows11 #Intune #Autopatch 😜 #MVPBuzz
February 20, 2025 at 7:19 AM
📢 Autopatch Important Change 📢

💡 Message ID MC996580 in the Microsoft 365 Message Center shows an important update with needed actions if you have Autopatch configured. 💡

Check it out here: intunestuff.com/2024/02/11/w...
Setup Windows Autopatch and Enable Hotpatch with Intune
Learn to configure Windows Autopatch and activate Hotpatch swiftly for seamless updates using Intune.
intunestuff.com
February 11, 2025 at 9:15 PM
Hotpatching goes default in Windows Autopatch whether you like it or not
Hotpatching goes default in Windows Autopatch whether you like it or not
Microsoft insists rebootless updates are 'the quickest way to get secure' From the department of "what could possibly go wrong?" comes news that Windows Autopatch is enabling hotpatch security updates by default.…
dlvr.it
March 11, 2026 at 11:46 AM
📢 Hi #Community, I've created a step by step guide on how to configure #Windows #Autopatch in combination with #Hotpatch 📢

🔍 It turned out to be a pretty long blog after all ;-) 🔍

👉 Curious on how to configure it? 👈

🔖 Read all about it here 👇

intunestuff.com/2024/12/11/w...
Setup Windows Autopatch and Enable Hotpatch with Intune
Learn to configure Windows Autopatch and activate Hotpatch swiftly for seamless updates using Intune.
intunestuff.com
December 11, 2024 at 10:45 PM
🚨 New Blog Post! 🚨
Legacy registry settings silently blocked Windows Autopatch onboarding.
I break down:
- Root cause analysis
- Intune remediation scripting
- Ghost hunting with Security Copilot
- Lessons for IT pros

skotheimsvik.no/the-silent-w...

#Intune #WindowsAutopatch #SecurityCopilot
Simon does The Silent Windows Autopatch Killer
Silent Windows Autopatch killer strikes again. Join me for a drive through modern Intune tools and Copilot to fix the legacy settings that kep coming back.
skotheimsvik.no
August 14, 2025 at 10:06 PM
Microsoft has fixed a Windows Autopatch bug that caused driver updates restricted by administrative policies to be deployed on some Autopatch-managed Windows devices in the European Union.
Microsoft fixes Windows Autopatch bug installing restricted drivers
Microsoft has fixed a Windows Autopatch bug that caused driver updates restricted by administrative policies to be deployed on some Autopatch-managed Windows devices in the European Union.
www.bleepingcomputer.com
May 13, 2026 at 2:36 PM
Achieving High Patch Compliance with Windows Autopatch: Configuration and Deployment Best Practices with @goosken.bsky.social and @mauvlan.bsky.social

#MEMSummit
April 25, 2025 at 7:19 AM
📢 Good news for #Microsoft365 Business Premium licensed users regarding #Autopatch 📢

📰 Read the table for the enabled features for Microsoft 365 Business Premium 📰

Check out my blog on how to setup Autopatch with #Hotpatch in your environment 👇

intunestuff.com/2024/02/11/w...

#MVPBuzz
How to setup Windows Autopatch and enable Hotpatch - The Complete Step by Step guide
Hi Community, We are almost at the ending of a great year filled with new and cool features all across the Microsoft cloud ecosystem. After Microsoft Ignite
intunestuff.com
April 18, 2025 at 10:11 AM
Microsoft fixes Windows Autopatch bug installing restricted drivers

Microsoft has fixed a Windows Autopatch bug that caused driver updates restricted by administrative policies to be deployed on some Autopatch-managed Windows devices in the European Union. [...]
#hackernews #microsoft #news
Microsoft fixes Windows Autopatch bug installing restricted drivers
Microsoft has fixed a Windows Autopatch bug that caused driver updates restricted by administrative policies to be deployed on some Autopatch-managed Windows devices in the European Union. [...]
www.bleepingcomputer.com
May 14, 2026 at 3:58 PM
Microsoft did a change last night with their Autopatch policies. Office 365 Update policies are now called Microsoft 365 Apps policies.

#MSIntune #Autopatch #MVP
March 4, 2025 at 7:55 AM
Hotpatching for Windows included in A3+ is an unexpected surprise from MS today! I did not expect us lowly A* customers to get anything extra since we can't access the Autopatch service.

learn.microsoft.com/en-us/window...
What is Windows Autopatch?
Details what the service is and shortcuts to articles.
learn.microsoft.com
November 20, 2024 at 1:34 AM
Microsoft stellt für die Enterprise-Kunden mit Windows Autopatch Windows-11-Clients standardmäßig auf Hotpatching um. #Windows
Microsoft aktiviert Hotpatching für Windows 11 standardmäßig
Microsoft stellt für die Enterprise-Kunden mit Windows Autopatch Windows-11-Clients standardmäßig auf Hotpatching um.
www.heise.de
July 2, 2025 at 1:49 PM
What’s new in Windows Autopatch: April 2025: A key focus of Windows Autopatch is to deliver an easy update management experience for IT administrators. With that in mind, we've simplified the update activation process.

In the past, some features like policy management were enabled… #WindowsITPro
What’s new in Windows Autopatch: April 2025
A key focus of Windows Autopatch is to deliver an easy update management experience for IT administrators. With that in mind, we've simplified the update activation process. In the past, some features like policy management were enabled by default while others needed to be activated in the Microsoft Intune console. Now, the activation process has been retired, making Windows Autopatch groups, reporting, and other features even easier to use. This change means you can streamline tasks like distributing devices to set up a safe rollout, configuring multiple policies across update types, and reporting on update compliance. With our April 2025 Windows Autopatch release, there are three major improvements to be aware of: * Windows Autopatch reports now covers all Intune-managed devices, with four-hour client-to-cloud latency. * Windows Autopatch groups are more flexible and intelligent. * Windows Autopatch groups and other management features now operate with least-privilege access. This group of changes is rolling out over the next month significantly improving the security posture of the service, while also making it easier to use for a broader set of people. Here, we'll dig into the details of how each change simplifies your update management experience. Windows Autopatch reports now covers all Intune-managed devices, with four-hour client-to-cloud latency What to know Windows Autopatch reporting has taken a huge step forward in speed and scope. All Intune-managed devices are now covered—not only members of Windows Autopatch groups. Reporting latency has decreased from what used to take more than a day to what now takes four hours or less, bringing you insights faster. What it means Windows Autopatch reporting directly focuses on every device's update compliance. To provide the clearest picture possible, Windows Autopatch enables every report to tell a story. To do this, every device must have a status. This means all Intune-managed devices are given one of three states for quality and feature updates. The three states include: * Up to date: The device is on its targeted version. * In progress: The device isn't up to date, but, based on policies, it hasn't reached its target compliance date. * Not up to date: The device isn't up to date and is beyond its target compliance date or has an issue preventing the update. Historical graphs let you track how your devices have progressed through those states over the last 90 days. If you find any issues, you can click straight through to investigate a group of devices and understand what's going on. When there's a known issue, there's an alert next to the devices that are "Not up to date" providing details around why that device isn't up to date and what to do next. Screenshot of a quality update report showing 90 days of history. The other major change coming to Windows Autopatch reporting is a significant decrease in latency. It used to take 12 to 24 hours to see changes in core device information—for example, seeing the build number. Now, it takes less than four hours. Screenshot of a quality update report showing a list of devices and their statuses. Bottom line Windows Autopatch lets you track update compliance for all your devices more quickly than ever. Windows Autopatch groups are more flexible and intelligent What to know There are no more shared policies between Windows Autopatch groups. Individual content types can now be enabled or disabled for a specific Windows Autopatch group, including Microsoft 365 Apps and Edge. New intelligent defaults provide recommendations for the most common device update scenarios. What this means Administrators used Windows Autopatch groups to target updates to different departments within an organization, but some update types shared settings between groups, which created a lack of flexibility. To provide the right level of control, policies for each content type are now only assigned to a single Windows Autopatch group. Previously, Windows Autopatch groups shared a single feature update policy that set the same minimum version among all Windows Autopatch devices. The challenge existed for Microsoft 365 Apps for Enterprise and Edge update policies, leading many admins to disable those content types and administer them separately. Now, these content types can be enabled or disabled for a group, letting admins tailor their approach. Screenshot showing available content types for a Windows Autopatch group. Windows Autopatch group registration has also become more flexible. Like before, devices are added to one of the deployment groups during registration, helping to ensure they receive the update policies. However now, additional configuration, like the diagnostic data level or the cloud managed desktop extension, are no longer deployed since the service can operate without them. To facilitate this change, the legacy groups that deployed policies to multiple Windows Autopatch groups are being removed. While making these changes to Windows Autopatch groups, we used the opportunity to improve other areas, based on your feedback. Two changes to know about include: * New intelligent defaults provide recommendations for how to configure updates for different types of devices: single user, shared devices, kiosks, or reboot sensitive devices. * The user experience now highlights shared configuration, for example, how quality update deferrals impact both quality updates and drivers. Screenshot showing the release schedules section of the Windows Autopatch group wizard. Bottom line Windows Autopatch groups let you configure safe deployment practices for updates in your environment. With this release, the groups are more intelligent and more flexible, which sets you up for success. Windows Autopatch groups and other management features now operate with least-privilege access What to know  Windows Autopatch now operates with least-privilege access, acting only with the permissions of the person currently signed in. With this change, Windows Autopatch no longer requires a management app with Intune administrator permissions. What this means Operating with least-privilege access limits potential damage by helping ensure that people and processes only have the permissions necessary to perform their tasks. To abide by that principle, Windows Autopatch has changed how the service makes changes in the person's environment, acting with the current user's permission instead with full Intune administrator permissions. This change represents a big step forward in the security of Windows Autopatch. Previously, Windows Autopatch management app had full Intune administrator permissions, meaning that it could change any administrator's policy or group. This level of access was more than was needed to deliver the service, so Windows Autopatch broke our dependency on the management app. Now, Windows Autopatch has moved to a model where we can't do anything beyond what the currently signed-in user can do. Essentially, we've reconfigured the internal structure of Windows Autopatch to operate using a "least privilege" model, meaning there is no action without direct consent from the organization. When an administrator asks Windows Autopatch to do something, like create a policy or a group, it is with that person's permission set—if they don't have the right permissions, the action will fail. Another advantage of the new permission model is that Windows Autopatch features no longer need an activation step. Previously, these features were dependent on Intune administrator permissions, which could only be granted by a Global Administrator. This change has made several features more readily available: * Windows Autopatch groups: Windows Autopatch groups allow you to configure a safe rollout and the device's update behavior. Under the hood, these create policies to configure update settings and populate new Microsoft Entra groups targeting policies based on your choices. * Windows Autopatch reporting: Windows Autopatch reporting tracks whether a device is up to date, in progress, or not up to date. It shows which devices have trended over time for quality and feature updates. Originally, these reports only included members of Windows Autopatch groups, but they now include all Intune-managed devices. * Support experience: With support experience, you can create tickets about update issues. These tickets are then routed to the right team based on their support contract. For people who have given the Windows Autopatch management app Intune administrator permissions, we will be removing those permissions over the coming months to help maximize security. Bottom line Windows Autopatch has changed its permission model to operate for the person with the least-privilege access. This allows Windows Autopatch functions like group management and reporting to operate more securely. Learn more about Windows Autopatch Find out more about Windows Autopatch and the features coming out in April by visiting our Windows Autopatch Learn pages. Explore the concepts and technology in more detail and find answers to frequently asked questions. Simplify update management with new Windows Autopatch features Windows Autopatch has made update management simpler and easier to navigate. Remain nimble, protected, and flexible by taking advantage of these features rolling out over the next month. These features will help you set up a safe rollout, configure multiple policies across update types, and create easier reporting on update compliance. Learn more about Windows Autopatch update management to take full advantage of the capability. --- Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.
bit.ly
April 9, 2025 at 4:03 PM
"Upgrade to Windows 11 with Windows Autopatch groups" buff.ly/oaNpMxZ #Microsoft #techcommunity
Upgrade to Windows 11 with Windows Autopatch groups - Windows IT Pro Blog
Here’s your playbook! Learn to use Windows Autopatch groups to gradually roll out the next Windows feature update.  
buff.ly
July 28, 2025 at 2:36 PM
October 6, 2025 at 9:12 AM
New script just dropped! Ever get stuck on update policies when moving from #ConfigMgr or GPO to #Autopatch? Reset-WindowsUpdateSettings is for you!
It creates a backup of relevant keys from your registry, then deletes and resyncs them where applicable. github.com/MHimken/tool...
toolbox/Intune/Platform Scripts/Reset-WindowsUpdateSettings.ps1 at main · MHimken/toolbox
This is my toolbox. Watch where you step. Contribute to MHimken/toolbox development by creating an account on GitHub.
github.com
March 16, 2025 at 10:17 PM
Two reminders:
1. Hotpatching is available in Windows 11 Enterprise version 24H2. Read that blog here: techcommunity.microsoft.com/blog/windows...
2. January is a baseline month for hotpatch.

#MicrosoftIntune #Autopatch #WUfB #MSIntune
Hotpatch for client comes to Windows 11 - Windows IT Pro Blog
Enhance security and increase productivity with hotpatching in Windows.  
techcommunity.microsoft.com
January 8, 2025 at 7:29 PM
We're thrilled to announce that Surabhi Calla will be speaking at MMS 2025 at MOA! Join Surabhi for her session on "Simplifying Update Management with Autopatch" and gain valuable insights into how to enhance your update strategy effectively.

Register Today: www.mmsmoa.com/mms2025moa
May 4-8, 2025
February 10, 2025 at 6:15 PM
A must-attend session for IT admins looking to optimize patching strategies!

Achieving High Patch Compliance with Windows Autopatch: Configuration and Deployment Best Practices

Adam Nichols and @goosken.bsky.social will dive into the configuration and deployment of Windows Autopatch.

#MEMSummit
March 19, 2025 at 9:00 AM
@liorbela.bsky.social
[New Post] 👉How Intune Plus Autopatch Drive Major Savings on Windows 10 ESU - www.anoopcnair.com/intune-plus-...
🎉How Intune + Windows Autopatch Reduce ESU Expenses
🎉Understanding the Standard Windows 10 ESU Pricing Model
#Intune #MSIntune #HTMDCommunity
November 18, 2025 at 10:41 AM