Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Windows quality update policies in Microsoft Intune support hotpatch, a deployment capability designed to reduce device downtime and user disruption. Hotpatch applies eligible Monthly B security updates so that they take effect without requiring an immediate device restart.
Hotpatch is an extension of Windows Update and is managed through Windows Autopatch using quality update policies. When enabled, Autopatch orchestrates the deployment of hotpatch updates to eligible devices enrolled in the Autopatch quality update policy. This approach helps organizations maintain security compliance while minimizing workflow interruptions.
Key benefits
- Reduced disruption: Hotpatch installs eligible security updates without requiring an immediate device restart, helping users stay productive.
- No changes to existing update rings: Existing update ring configurations remain in effect and are honored alongside hotpatch configurations.
- Policy‑level visibility: The hotpatch quality updates report provides a policy‑level view of update status for devices receiving hotpatch updates.
Prerequisites
Hotpatch has the same prerequisites as Windows quality update policies. This section highlights additional prerequisites specific to hotpatch.
Device configuration requirements
To prepare a device to receive hotpatch updates, configure the following operating system settings on the device. You must configure these settings for the device to be offered the hotpatch update and to apply all hotpatch updates.
Virtualization based security (VBS)
VBS must be turned on for a device to be offered hotpatch updates. For information on how to set and detect if VBS is enabled, see Virtualization-based Security (VBS).Note
Devices might be temporarily ineligible because they don't have VBS enabled or aren't currently on the latest baseline release. To ensure that all your Windows devices are configured properly to be eligible for hotpatch updates, see Troubleshoot hotpatch updates.
Arm 64 devices must disable compiled hybrid PE usage (CHPE) (Arm 64 CPU Only)
Important
Arm 64 device support is in public preview.
To ensure all the hotpatch updates are applied, you must set the Compiled Hybrid Portable Executable (CHPE) disable flag and restart the device to disable CHPE usage. You only need to set this flag one time. The registry setting remains applied through updates.
This requirement only applies to Arm 64 CPU devices when using hotpatch updates. Hotpatch updates aren't compatible with servicing CHPE OS binaries.
To disable CHPE, create and/or set the following DWORD registry key:
Path:
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management DWORD key value: HotPatchRestrictions=1To learn more about CHPE, see here
Note
There are no plans to support hotpatch updates on Arm64 devices with CHPE enabled. Disabling CHPE is required only for Arm64 devices. AMD and Intel CPUs don't have CHPE. If you choose to no longer use hotpatch updates, clear the CHPE disable flag (
HotPatchRestrictions=0) then restart the device to turn on CHPE usage.
Ineligible devices
Devices that don't meet one or more prerequisites automatically receive the Latest Cumulative Update (LCU) instead. Latest Cumulative Update (LCU) contains monthly updates that supersede the previous month's updates containing both security and nonsecurity releases.
LCUs requires you to restart the device, but the LCU ensures that the device remains fully secure and compliant.
Note
If devices aren't eligible for hotpatch updates, these devices are offered the LCU. The LCU keeps your configured Update ring settings, it doesn't change the settings.
Release cycles
For more information about the release calendar for hotpatch updates, see Release notes for hotpatch.
- Baseline: Includes the latest security fixes, cumulative new features, and enhancements. Restart required.
- Hotpatch: Includes security updates. No restarted required.
| Quarter | Baseline updates (requires restart) | Hotpatch (no restart required) |
|---|---|---|
| 1 | January | February and March |
| 2 | April | May and June |
| 3 | July | August and September |
| 4 | October | November and December |
Hotpatch on Windows 11 Enterprise or Windows Server 2025
Note
Hotpatch is also available on Windows Server and Windows 365. For more information, see Hotpatch for Windows Server Azure Edition.
Hotpatch updates are similar between Windows 11 and Windows Server 2025.
- Windows Autopatch manages Windows 11 updates
- Azure Update Manager and optional Azure Arc subscription for Windows 2025 Datacenter/Standard Editions (on-premises) manages Windows Server 2025 Datacenter Azure Edition.
The calendar dates, eight hotpatch months, and four baseline months, planned each year are the same for all the hotpatch-supported operating systems. It's possible for additional baseline months for one OS (for example, Windows Server 2022), while there are hotpatch months for another OS, such as Server 2025 or Windows 11, version 24H2. Review the release notes from Windows release health to keep up to date.
Enroll devices to receive hotpatch updates
Note
If you're using Autopatch groups and want your devices to receive hotpatch updates, you must create a hotpatch policy and assign devices to it. Turning on hotpatch updates doesn't change the deferral setting applied to devices within an Autopatch group.
To enroll devices to receive hotpatch updates:
- In the Microsoft Intune admin center, select Devices > Windows updates.
- Select the Quality updates tab.
- Select Create, and select Windows quality update policy.
- Under the Basics section, enter a name for your new policy and select Next.
- Under the Settings section, set When available, apply without restarting the device ("hotpatch") to Allow. Then, select Next.
- Select the appropriate Scope tags or leave as Default. Then, select Next.
- Assign the devices to the policy and select Next.
- Review the policy and select Create.
These steps ensure that targeted devices, which are eligible to receive hotpatch updates, are configured properly. Ineligible devices are offered the latest cumulative updates (LCU).
Note
Turning on hotpatch updates doesn't change the existing deadline-driven or scheduled install configurations on your managed devices. Deferral and active hour settings still apply.
Roll back a hotpatch update
Automatic rollback of a hotpatch update isn't supported but you can uninstall them. If you experience an unexpected issue with hotpatch updates, you can investigate by uninstalling the hotpatch update and installing the latest standard cumulative update (LCU) and restart. Uninstalling a hotpatch update is quick, however, it requires a device restart.
Hotpatch quality updates report
After a Windows quality update policy has been created with hotpatch updates enabled, you can monitor results, hotpatch deployment status, and errors from the reports.
This report shows the total targeted devices and current update states of all hotpatch update enabled devices.
To access the report:
- In the Microsoft Intune admin center, select Reports
- Under the Windows Autopatch section, select Windows quality updates
- On the Reports tab, select Hotpatch quality updates report.