Every IT administrator who manages Windows devices knows the Patch Tuesday ritual — wait for Microsoft’s monthly release, review what broke last month, approve updates in WSUS or Intune, monitor rollout, troubleshoot failures, repeat. For small IT teams managing hundreds or thousands of devices, this monthly cycle consumes significant time and expertise.
Windows Autopatch is Microsoft’s answer to that problem.
Windows Autopatch is a cloud-based service from Microsoft that automates the process of keeping Windows devices up to date with the latest security patches, drivers, and software updates. Rather than IT administrators manually planning and deploying each update cycle, Autopatch handles the orchestration, the phased rollout, the monitoring, and the rollback decisions automatically.
As of 2026, Windows Autopatch manages updates on more than 10 million production devices. And in May 2026, it took a significant step forward — enabling hotpatch security updates by default, allowing eligible devices to apply security fixes without requiring a restart.
This guide explains exactly what Windows Autopatch is, how its deployment ring system works, what changed in 2026, which licenses include it, and how it compares to alternative update management approaches.
What Does Windows Autopatch Actually Do?
Windows Autopatch helps you minimize the involvement of your scarce IT resources in the planning and deployment of updates for Windows, Microsoft 365 Apps, Microsoft Edge, or Teams.
Specifically, Autopatch automates updates for four product categories:
Windows — monthly quality updates (Patch Tuesday), feature updates (annual version upgrades), and out-of-band emergency updates.
Microsoft 365 Apps for enterprise — the Office application suite including Word, Excel, PowerPoint, Outlook, and Teams desktop app.
Microsoft Edge — the browser updates that previously required separate management.
Microsoft Teams — the Teams client updates across enrolled devices.
IT teams can use Autopatch groups and deployment rings to define rollout cadence, choose whether certain content types are automatic or manually approved, and monitor update compliance across Windows quality updates, feature updates, Microsoft 365 Apps, Edge, Teams, and driver or firmware updates where supported.
The Core Mechanism — Deployment Rings
The deployment ring system is the foundation of how Windows Autopatch reduces update risk. Rather than pushing an update to every device simultaneously — where a problematic update can break thousands of machines at once — Autopatch stages the rollout through progressively larger groups.
The core of how it works is deployment rings. Devices are split into groups, and updates roll out to a small test ring first, then progressively to wider groups only if no problems appear. If an update causes issues, the rollout can be paused before it reaches the bulk of the estate.
The four default deployment rings are:
Test Ring — A small group of devices that receive updates first. Typically used for IT team devices or non-critical test machines. Receives updates immediately on release day.
First Ring — Approximately 1 percent of enrolled devices. Early adopters who receive updates shortly after the test ring validates stability.
Fast Ring — Approximately 9 percent of devices. A wider validation group that receives updates after First confirms no issues.
Broad Ring — The remaining devices — typically 90 percent of the enrolled fleet. Only receives updates after stability signals from Test, First, and Fast rings confirm the update is safe.
Autopatch relies on three key capabilities to help resolve update issues: the ‘Halt’ feature, where updates will not progress to the next ring unless targets for stability are met. Customers can also pause the update.
This means a bad update — like the KB5121767 Dell shutdown issue in July 2026 — would be caught in the Test or First ring before reaching the majority of devices. The rollout halts automatically when stability signals fall below threshold. IT administrators receive alerts and can investigate before approving progression to the next ring.
The Biggest 2026 Change — Hotpatch Enabled by Default
The most significant Windows Autopatch development in 2026 is the default enablement of hotpatch security updates.
Microsoft announced that Windows Autopatch will enable hotpatch security updates by default for all eligible devices starting with the May 2026 Windows security update. The change affects devices managed through Microsoft Intune and the Windows updates API in Microsoft Graph. Hotpatch updates install security fixes without requiring a device restart, accelerating compliance across organizations. Previously, this feature required manual activation by administrators.
What is hotpatching?
Traditional Windows updates replace files on disk during installation. Because Windows cannot replace files that are currently in use, a restart is required to complete the replacement. This restart cycle is the primary source of user disruption from monthly updates.
Hotpatch works differently. Instead of replacing files on disk, it modifies the code of running processes directly in memory. The security fix takes effect immediately on the running system without touching the underlying files — and therefore without requiring a restart.
With Windows Autopatch and hotpatch enabled, security updates install in-memory on running processes without a restart in eight out of twelve months per year, and the service handles ring-based rollout, compliance monitoring, and alerting automatically.
Four months per year still require a traditional restart-required update — these are called “baseline” months — to update the underlying files that hotpatch builds on. But the shift from twelve restart-required updates per year to four is a significant reduction in user disruption.
Every Major Autopatch Update Since 2025
Windows Autopatch has evolved substantially since its July 2022 general availability. The most relevant recent changes:
April 2025 — Licensing expanded, feature activation removed
Feature activation was removed, and Autopatch was extended to Business Premium and Education A3 and A5. Previously, Windows Autopatch required Windows Enterprise E3 or E5 licenses — limiting it to larger enterprise customers. The April 2025 expansion brought Autopatch to smaller organizations with Business Premium licenses, opening it to mid-market companies that could not previously justify E3/E5 just for patch management.
November 2025 — Manual approvals added
Manual approvals arrived for security, non-security, and out-of-band updates, with deferral settings and pause and resume. Extended Security Update enrollment also became visible in the quality update reports. This addressed one of the most common criticisms of early Autopatch — that it was too automated with insufficient manual control options for security-conscious organizations.
Q1 2026 — Maintenance windows
Maintenance windows landed, letting you set restart timing down to the hour. Organizations can now specify precise windows for when restarts are allowed — preventing updates from rebooting machines during business hours or peak production periods.
May 2026 — Hotpatch by default
As described above, hotpatch was enabled automatically for all eligible enrolled devices — eliminating the manual activation step that previously created an adoption barrier.
Windows Autopatch vs Windows Update for Business vs WSUS
Three Microsoft options handle Windows updates, and they sit at different points on the control-versus-effort line.
| Windows Update for Business | Windows Autopatch | WSUS | |
|---|---|---|---|
| What it is | Policy framework | Managed service | On-premises update server |
| Effort required | Medium — admin configures policies | Low — service manages orchestration | High — server maintenance + approval workflows |
| Where it runs | Cloud (Intune) | Cloud (Intune) | On-premises |
| Rings/deployment | Admin configures manually | Microsoft-managed + customizable | Manual approval and deployment |
| Covers | Windows only | Windows + M365 + Edge + Teams | Windows + other Microsoft products |
| Restart reduction | Standard | Hotpatch (8 of 12 months) | Standard |
| Rollback | Manual | Automated halt + manual | Manual |
| Status | Active | Active | Deprecated (2024) — still works |
Windows Update for Business gives organisations controls to configure how Windows updates are delivered. Windows Autopatch builds on that foundation by adding Microsoft-managed orchestration, automated deployment rings, update monitoring, and service-driven management for Windows, Microsoft 365 Apps, Edge, and Teams. In short, Windows Update for Business is the policy framework, while Windows Autopatch is the managed service layer that reduces manual administration.
WSUS was deprecated by Microsoft in 2024 — it receives no new features but continues to function. Organizations with significant WSUS investment should plan migration to Autopatch or Update for Business as part of their infrastructure modernization roadmap.
What Windows Autopatch Does NOT Cover
Understanding Autopatch’s limits is as important as understanding what it does. Several categories fall outside its scope:
Third-party applications — Autopatch only manages Microsoft products. Adobe, Chrome, Java, Zoom, and any other non-Microsoft software requires separate patching tools.
Windows Server — Autopatch manages Windows clients (Windows 10 and Windows 11). Windows Server updates — managed through tools like WSUS for Server 2022 — are not covered.
macOS and Linux — Autopatch is Windows-only. Mixed-OS environments need complementary tooling for non-Windows endpoints.
Legacy on-premises environments — Autopatch requires Microsoft Intune. Organizations that have not moved to Intune cannot use Autopatch without first migrating endpoint management to the cloud.
Agent-based Windows patch management covers the servers, Macs, Linux boxes, and third-party applications Autopatch was never built to see.
This coverage gap is why most enterprise environments use Autopatch alongside a third-party patch management tool rather than as a complete replacement for all patch management processes.
Licensing — What You Need
Windows Autopatch is available for organisations with eligible Microsoft licences, including Microsoft 365 Business Premium, Windows Education A3 or A5, Windows Enterprise E3 or E5, and suites that include those entitlements such as Microsoft 365 F3, E3 and E5.
Feature availability varies by license tier. Hotpatching — the no-restart security update capability — requires Windows 11 Enterprise. Basic Autopatch quality update automation is available at the Business Premium level.
Check the Features and capabilities section of Microsoft’s Autopatch documentation to confirm exactly what is available for your specific license before planning a deployment.
How to Get Started With Windows Autopatch
Autopatch works through Microsoft Intune. The enrollment process is managed at the tenant level by IT administrators.
Prerequisites:
Microsoft Intune managing the devices to be enrolled. Windows 10 version 1809 or later, or Windows 11 on enrolled client devices. An eligible Microsoft license as listed above. Devices must be Azure Active Directory joined or Hybrid Azure AD joined. Windows Update for Business must not be blocked by Group Policy.
Enrollment:
Access Windows Autopatch through the Microsoft Intune admin center at intune.microsoft.com. Navigate to Devices, Windows Autopatch. Follow the tenant enrollment wizard which validates prerequisites and configures the necessary policies.
Ring assignment:
After enrollment, devices are automatically discovered and assigned to rings. A function called Windows Autopatch Discover Devices will trigger hourly searching for new devices. The Entra Device ID is then used to query attributes in Intune and Entra for registration.
Administrators can move specific devices between rings — for example, moving IT team machines into the Test ring — to align ring membership with organizational needs.
How Autopatch Manages the July 2026 Patch Tuesday
To make the Autopatch workflow concrete, consider how it handles a significant monthly update like the July 2026 KB5101650 — which fixed a record 570 vulnerabilities and added Point-in-Time Restore to Windows 11.
On release day (July 14, 2026), Autopatch begins deploying KB5101650 to Test ring devices. If no significant issues are detected over the following days, deployment expands to First ring devices. After First ring validates stability, Fast ring devices receive the update. Finally, Broad ring devices — the majority of the fleet — receive the update.
When an issue like the Dell Intel IPF driver conflict emerged with KB5101650, Microsoft blocked the update on affected hardware. In Autopatch environments, this block propagates automatically — IT administrators do not need to manually identify and exempt affected Dell devices. The monitoring system detects the failures and halts progression before the issue reaches Broad ring.
This is the practical value of deployment rings: catching the kind of issues that drove the KB5121767 emergency Dell fix before they affect the majority of an organization’s fleet.
Windows Autopatch and the End of Windows 11 24H2 Support
For organizations running Windows 11 24H2 on Home or Pro devices, the October 13, 2026 end of support deadline creates an immediate action item.
Windows Autopatch simplifies this transition for enrolled devices. Feature update management in Autopatch handles the 24H2-to-25H2 upgrade through the same ring-based deployment as quality updates. IT administrators set the target version to Windows 11 25H2, and Autopatch orchestrates the rollout — starting with Test ring devices and progressing to Broad ring after stability is confirmed.
For organizations that have already enrolled in Autopatch, managing the 24H2-to-25H2 migration at scale is significantly simpler than managing it through manual WSUS approvals or per-device Windows Update settings.
Frequently Asked Questions
What is Windows Autopatch?
Windows Autopatch is a cloud-based Microsoft service that automates update management for Windows, Microsoft 365 Apps, Microsoft Edge, and Microsoft Teams. It uses deployment rings to stage updates across progressively larger groups of devices, monitoring stability before each expansion. It runs through Microsoft Intune and is included in eligible licenses including Windows Enterprise E3/E5 and Microsoft 365 Business Premium.
Does Windows Autopatch replace Patch Tuesday?
No. Windows Autopatch does not replace Patch Tuesday. It automates the deployment of Patch Tuesday updates through a phased ring-based rollout rather than replacing the updates themselves. Microsoft still releases monthly security updates — Autopatch manages how and when those updates reach enrolled devices.
What is hotpatch in Windows Autopatch?
Hotpatch is a feature that applies security updates by modifying code in running processes in memory, eliminating the need for a device restart. Starting with the May 2026 Windows security update, hotpatch is enabled by default for all eligible Autopatch-enrolled devices. Hotpatch eliminates the restart requirement in eight of twelve months per year. Four baseline months per year still require a traditional restart for underlying file updates.
Which licenses include Windows Autopatch?
Windows Autopatch is included in Microsoft 365 Business Premium, Windows Enterprise E3 and E5, Windows Education A3 and A5, and Microsoft 365 F3, E3, and E5. Feature availability varies by tier — hotpatching requires Windows 11 Enterprise. Verify exact feature entitlement in Microsoft Intune before deployment.
What does Windows Autopatch NOT cover?
Windows Autopatch does not manage third-party applications, Windows Server, macOS devices, Linux devices, or any non-Microsoft software. It is limited to Windows client devices (Windows 10 and Windows 11), Microsoft 365 Apps, Edge, and Teams. Organizations with mixed environments need supplementary tools for non-covered endpoints and applications.
How is Windows Autopatch different from Windows Update for Business?
Windows Update for Business is a policy framework — it defines rules for how updates are configured on Windows devices. Windows Autopatch is a managed service that builds on top of Windows Update for Business, adding Microsoft-managed orchestration, automated deployment rings, health monitoring, and rollback capabilities. Autopatch does the work that administrators would otherwise do manually with Update for Business policies.
Is WSUS being replaced by Windows Autopatch?
Microsoft deprecated WSUS in 2024 — no new features are added, though it continues to function. Windows Autopatch is the cloud-native replacement for organizations migrating away from on-premises WSUS infrastructure. However, Autopatch does not cover Windows Server or third-party applications, so organizations with complex WSUS deployments may need additional tooling alongside Autopatch.
How many devices does Windows Autopatch manage?
As of 2026, Windows Autopatch manages updates on more than 10 million production devices globally.