To patch Windows with as few reboots as possible, assign Intune update rings that control deferrals, deadlines and restart behavior, then create a Windows quality update policy under Devices > Windows updates > Quality updates with When available, apply without restarting the device ("Hotpatch") set to Allow. Eligible Windows 11 24H2 or later devices with virtualization-based security running then install monthly security updates without a restart in hotpatch months, and restart only for baseline updates, which Microsoft plans once a quarter. Devices that aren't eligible keep receiving the normal cumulative update under the same ring settings.
Who this is for and what you will have at the end
This guide is for Intune administrators who patch Windows 11 devices with Windows Update client policies and want predictable compliance with fewer forced restarts.
At the end you will have:
- A set of update rings (for example pilot, early and broad) with deferrals, deadlines and a restart grace period.
- A hotpatch-enabled quality update policy assigned to eligible devices.
- Devices verified as enrolled in hotpatch, with VBS running.
- A monthly routine that uses the hotpatch calendar, ring actions and reports.
How rings and hotpatch fit together
Update rings and hotpatch solve different problems, so you use both:
| Update rings | Hotpatch quality update policy | |
|---|---|---|
| Controls | When updates are offered and installed, deadlines, restart behavior, user experience | Whether eligible devices get the rebootless version of the monthly security update |
| Applies to | Quality and feature updates | Monthly B release security updates |
| Restart | Required for every cumulative update | Only in baseline months |
| Without it | Windows default update behavior | Devices get the standard latest cumulative update |
Hotpatch updates are the monthly B security releases packaged so they take effect without a restart. Windows Autopatch creates and deploys them to devices that are in a quality update policy with hotpatch turned on. Turning on hotpatch doesn't change deadline-driven or scheduled installation settings, deferrals or active hours; the rings keep doing that job.
The release cycle follows a quarterly pattern:
| Quarter | Baseline (restart required) | Hotpatch (no restart) |
|---|---|---|
| 1 | January | February and March |
| 2 | April | May and June |
| 3 | July | August and September |
| 4 | October | November and December |
Microsoft can make a planned hotpatch month into a baseline month for security reasons without changing the rest of the cadence. That has happened: the published 2026 calendar for Windows 11 version 25H2 shows baselines in January, April, June, July, September and October. Check the Windows 11 hotpatch calendar on the Windows release health site every month before you tell users whether to expect a restart.
Prerequisites
Update rings
- Licensing: Microsoft Intune Plan 1.
- Editions: Pro, Pro Education, Enterprise, Education, Windows IoT Enterprise, plus Windows Team (Surface Hub) and a subset of settings for Windows Holographic for Business. LTSC editions support quality updates only, so the feature update pause, deferral, uninstall period, pre-release and feature update deadline controls don't apply to them.
- Services: the Microsoft Account Sign-In Assistant service (
wlidsvc) enabled and running; without it, Windows Update doesn't offer feature updates.
Hotpatch
- Licensing: Windows 11 Enterprise E3 or E5, Microsoft 365 F3, Windows 11 Education A3 or A5, Microsoft 365 Business Premium, or Windows 365 Enterprise.
- Version: Windows 11, version 24H2 or later, on the latest baseline release. Hotpatch isn't available on Windows 11, version 26H1.
- Virtualization-based security (VBS): turned on and running. You can configure it with the
VirtualizationBasedTechnologypolicy CSP. - Arm64 devices only: compiled hybrid PE (CHPE) usage disabled, either with the
DisableCHPEsystem policy CSP or the registry value below, followed by one restart. - Management: Intune, with the Windows quality update policy.
The Arm64 registry setting, if you don't use the CSP:
Path: HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management
Name: HotPatchRestrictions
Type: DWORD
Value: 1Disabling CHPE can break 32-bit x86 apps on Arm64, such as 32-bit Office add-ins or VBA using Declare statements. Move those to 64-bit, or exclude the devices that need them from the hotpatch policy.
Step 1: Design the rings
Use separate rings for small, early groups and the broad population, assigned to device groups so policy applies without anyone having to sign in. The available update settings are:
| Setting | Range or options |
|---|---|
| Quality update deferral period (days) | 0 to 30 |
| Feature update deferral period (days) | 0 to 365 |
| Set feature update uninstall period | 2 to 60 days |
| Microsoft product updates | Allow or Block |
| Windows drivers | Allow or Block |
| Enable pre-release builds | Release Preview, Beta Channel or Dev Channel |
An example layout, which you should adjust to your own change process:
| Ring | Quality deferral | Quality deadline | Grace period |
|---|---|---|---|
| Pilot (IT staff) | 0 days | 2 days | 1 day |
| Early (a cross-section of departments) | 3 days | 3 days | 2 days |
| Broad (everyone else) | 7 days | 5 days | 2 days |
If you control Windows versions with feature update policies, set Feature update deferral period (days) to 0 in every ring so ring deferrals don't delay or block what the feature update policy offers. Upgrading Windows 11 24H2 to 25H2 with feature update policies covers that side.
Step 2: Create the update rings
- In the Intune admin center, go to Devices > By platform > Windows > Manage updates > Windows updates.
- Select the Update rings tab > Create profile and give the ring a name.
- Configure the update settings from Step 1.
- Configure the user experience settings:
- Automatic update behavior: Auto install at maintenance time installs during automatic maintenance and blocks automatic restarts during Active hours start and Active hours end. Other options include Auto install and restart at a scheduled time and Auto install and reboot without end-user control.
- Option to pause Windows updates: Disable stops users pausing updates themselves.
- Option to check for Windows updates: Enable lets users scan on demand.
- Change notification update level: leave restart warnings on unless you have a reason not to.
- Use deadline settings: Allow, then set Deadline for feature updates (2 to 30 days), Deadline for quality updates (2 to 30 days), Grace period (0 to 7 days) and Auto reboot before deadline.
- Add scope tags if you use them, assign the ring to its device group, and select Create.
Deadlines count from when the device's update scan first discovered the update. Microsoft recommends Auto reboot before deadline set to Yes, so the device restarts outside active hours when nobody is using it. With No, the device waits for the deadline and grace period to expire and then restarts, which can happen during active hours.
Step 3: Turn on hotpatch
- In the Intune admin center, select Devices, then under Manage updates select Windows updates.
- Open the Quality updates tab, select Create and choose Windows quality update policy.
- Under Basics, name the policy, for example
QU - Hotpatch - All eligible. - Under Settings, set When available, apply without restarting the device ("Hotpatch") to Allow.
- Choose scope tags, assign the policy to your device groups, and select Create.
You can also edit an existing Windows quality update policy and set the same option to Allow. If you use Windows Autopatch groups, create the hotpatch policy and assign the devices to it; turning hotpatch on doesn't change the deferral applied by the Autopatch group.
You can assign the policy broadly. Devices that don't meet a prerequisite, such as VBS not running or not being on the latest baseline, simply get the standard latest cumulative update and keep their ring settings. In a hotpatch month, a device that isn't on the latest baseline gets the baseline (with restart) and the hotpatch.
Step 4: Verify on a device
- VBS: open System Information and check that Virtualization-based security shows Running in the System summary.
- Policy: open Settings > Windows Update > Advanced options > Configured update policies and look for Enable hotpatching when available.
- Event log: in Event Viewer, filter for
AllowRebootlessUpdates. An entry with the value set shows the device is enrolled and has hotpatch turned on, for example:
"data": { "payload": "{\"Orchestrator\":{\"UpdatePolicy\":{\"Update/AllowRebootlessUpdates\":true}}}", "isEnrolled": 1, "isCached": 1, "vbsState": 2,- Build: after the next hotpatch month, compare the device build with the hotpatch calendar entry for that month.
For the fleet view, go to Reports > Windows Autopatch > Windows quality updates, select the Reports tab and open Hotpatch quality updates. It shows, per policy, devices that are up to date, hotpatched, not up to date, in progress, not ready or paused, with a 90-day trend. The data refreshes every four hours.
Step 5: Run the monthly routine
- Before Patch Tuesday: check the hotpatch calendar to see whether this month is a baseline or a hotpatch month, and warn users about restarts in baseline months.
- Pilot first: the pilot ring's short deferral means problems show up there days before the broad ring.
- Pause if needed: on a ring's overview, Pause stops feature or quality updates for up to 35 days. Devices only receive the pause at their next check-in, so a device that installs a scheduled update before checking in isn't protected. Extend resets the pause to 35 days, and Resume restarts updates.
- Roll back if needed: Uninstall removes the latest feature or quality update from the ring's devices as soon as they receive the policy, without waiting for maintenance windows; if removal needs a restart, users get no option to delay it. It also pauses that update type on the ring. Hotpatch updates can't roll back automatically, but you can uninstall them; uninstalling a hotpatch requires a restart.
- Plan feature updates around the calendar: upgrade hotpatch devices to a new Windows version in a baseline month. If you upgrade in a hotpatch month, the device switches to standard updates and needs a restart, and hotpatch resumes after the next baseline.
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| Device installs the full cumulative update and restarts in a hotpatch month | Not on the latest baseline, VBS not running, or not in the hotpatch policy | Check VBS, the baseline build and the policy assignment |
| Enable hotpatching when available missing from configured policies | Policy not assigned or not yet applied | Check the assignment and sync the device |
| Autopatch alert "Hotpatch – VBS not running" | VBS disabled or unsupported on the device | Turn on VBS with the VirtualizationBasedTechnology CSP |
| Arm64 device misses hotpatches | CHPE still enabled | Set DisableCHPE or HotPatchRestrictions=1 and restart |
| Hotpatch errors in the Application log | The hotpatch monitor service found a problem | Review events filtered on "hotpatch"; on a critical error the device installs the standard update |
| Paused ring still installed an update | Device installed before it checked in | Expect a short lag; use Uninstall if needed |
| Restarts during working hours | Auto reboot before deadline set to No, or deadlines too short | Set it to Yes and review deadlines and active hours |
| Feature updates never offered | wlidsvc disabled | Enable the Microsoft Account Sign-In Assistant service |
Checklist
- Rings assigned to device groups, with deferrals that stagger pilot, early and broad devices.
- Deadlines and grace periods set, with Auto reboot before deadline on Yes.
- Feature update deferral at 0 where feature update policies control versions.
- Hotpatch licensing confirmed; devices on Windows 11 24H2 or later.
- VBS running on target devices; CHPE disabled on Arm64 devices that will use hotpatch.
- Windows quality update policy with hotpatch set to Allow, assigned.
- Devices show Enable hotpatching when available; Hotpatch quality updates report reviewed.
- Monthly check of the hotpatch calendar, with feature upgrades scheduled in baseline months.