Intune Autopatch 12 min read

Windows Autopatch & Rebootless Hotpatch Deployment

Step-by-step enterprise deployment guide for Windows Autopatch and rebootless Hotpatching across Microsoft Intune environments.

1. Prerequisites, Licensing & RBAC

Before beginning an enterprise Autopatch deployment, verify that your tenant meets core subscription and infrastructure requirements:

  • Licensing: Microsoft 365 Business Premium, Windows 10/11 Enterprise E3/E5, or Windows 365 Enterprise.
  • Roles & Permissions: Requires Global Administrator access for initial tenant consent and Intune Administrator / Policy and Profile Manager roles for ongoing policy assignment.
  • Operating System: Target devices must run Windows 11 Enterprise (version 24H2 or later).
  • Virtualization-Based Security (VBS): VBS must be provisioned and running to secure in-memory code patches.

2. Understanding Hotpatch & Baseline Cycles

Hotpatching allows monthly security updates to be applied to running processes in-memory without forcing device reboots. This drastically minimizes downtime for critical frontline or mission-critical endpoints.

Quarterly Baseline vs. Hotpatch Months

Devices receive standard cumulative updates (requiring a restart) during quarterly baseline months (January, April, July, October). During the remaining 8 months of the year, security patches are delivered entirely as rebootless hotpatches, cutting standard annual reboots down from 12 to 4.

3. Configuring Deployment Rings & Policies

Planning your deployment rings is essential. While default Autopatch groups exist, custom targeting groups can be synchronized with SCCM device collections or managed directly via Microsoft Intune.

Configure the Windows Quality Update Policy in the Intune Admin Center by navigating to Devices → Windows updates → Quality updates, enabling security updates, and toggling the hotpatch parameter to apply updates without restarting when available.

4. Release Schedules & Deferrals

Define update behavior by establishing deferral days, deadline windows, and grace periods. Test rings should use 0 deferral days for immediate validation, whereas production rings require broader rollout windows to monitor stability.

5. Verification & Troubleshooting

On target devices, verify VBS status via System Information (ensuring it shows as Running and Enabled) and check registry paths under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\current\device\Update for AllowRebootlessUpdates = 1.

Official References

Read more

Technical Discussion & Q&A

Secure PostgreSQL Board

Join the Engineering Discussion

Loading discussion threads...

Akash Nagapure

Akash Nagapure

Microsoft Intune and VMware Architect

Microsoft Intune and VMware Architect specialized in designing scalable cloud infrastructure and zero-trust modern workspace solutions.

Sponsored Slot Available

Promote Your Brand to Enterprise Tech Leaders

Reach architects, systems engineers, and cloud professionals. Reserve this prime ad space for your tools, courses, or services.

Was this guide helpful?

Loading community feedback...