Cloud & infrastructure

Configure Intune Update Rings and Windows Hotpatch for Fewer Reboots

Build Intune update rings with deferrals, deadlines and restart settings, then turn on Windows hotpatch so most monthly security updates install without a restart.

10 min read
On this page

To patch Windows with as few reboots as possible, assign Intune update rings that control deferrals, deadlines and restart behavior, then create a Windows quality update policy under Devices > Windows updates > Quality updates with When available, apply without restarting the device ("Hotpatch") set to Allow. Eligible Windows 11 24H2 or later devices with virtualization-based security running then install monthly security updates without a restart in hotpatch months, and restart only for baseline updates, which Microsoft plans once a quarter. Devices that aren't eligible keep receiving the normal cumulative update under the same ring settings.

Who this is for and what you will have at the end

This guide is for Intune administrators who patch Windows 11 devices with Windows Update client policies and want predictable compliance with fewer forced restarts.

At the end you will have:

  • A set of update rings (for example pilot, early and broad) with deferrals, deadlines and a restart grace period.
  • A hotpatch-enabled quality update policy assigned to eligible devices.
  • Devices verified as enrolled in hotpatch, with VBS running.
  • A monthly routine that uses the hotpatch calendar, ring actions and reports.

How rings and hotpatch fit together

Update rings and hotpatch solve different problems, so you use both:

Update ringsHotpatch quality update policy
ControlsWhen updates are offered and installed, deadlines, restart behavior, user experienceWhether eligible devices get the rebootless version of the monthly security update
Applies toQuality and feature updatesMonthly B release security updates
RestartRequired for every cumulative updateOnly in baseline months
Without itWindows default update behaviorDevices get the standard latest cumulative update

Hotpatch updates are the monthly B security releases packaged so they take effect without a restart. Windows Autopatch creates and deploys them to devices that are in a quality update policy with hotpatch turned on. Turning on hotpatch doesn't change deadline-driven or scheduled installation settings, deferrals or active hours; the rings keep doing that job.

The release cycle follows a quarterly pattern:

QuarterBaseline (restart required)Hotpatch (no restart)
1JanuaryFebruary and March
2AprilMay and June
3JulyAugust and September
4OctoberNovember and December

Microsoft can make a planned hotpatch month into a baseline month for security reasons without changing the rest of the cadence. That has happened: the published 2026 calendar for Windows 11 version 25H2 shows baselines in January, April, June, July, September and October. Check the Windows 11 hotpatch calendar on the Windows release health site every month before you tell users whether to expect a restart.

Prerequisites

Update rings

  • Licensing: Microsoft Intune Plan 1.
  • Editions: Pro, Pro Education, Enterprise, Education, Windows IoT Enterprise, plus Windows Team (Surface Hub) and a subset of settings for Windows Holographic for Business. LTSC editions support quality updates only, so the feature update pause, deferral, uninstall period, pre-release and feature update deadline controls don't apply to them.
  • Services: the Microsoft Account Sign-In Assistant service (wlidsvc) enabled and running; without it, Windows Update doesn't offer feature updates.

Hotpatch

  • Licensing: Windows 11 Enterprise E3 or E5, Microsoft 365 F3, Windows 11 Education A3 or A5, Microsoft 365 Business Premium, or Windows 365 Enterprise.
  • Version: Windows 11, version 24H2 or later, on the latest baseline release. Hotpatch isn't available on Windows 11, version 26H1.
  • Virtualization-based security (VBS): turned on and running. You can configure it with the VirtualizationBasedTechnology policy CSP.
  • Arm64 devices only: compiled hybrid PE (CHPE) usage disabled, either with the DisableCHPE system policy CSP or the registry value below, followed by one restart.
  • Management: Intune, with the Windows quality update policy.

The Arm64 registry setting, if you don't use the CSP:

Path:  HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management
Name:  HotPatchRestrictions
Type:  DWORD
Value: 1

Disabling CHPE can break 32-bit x86 apps on Arm64, such as 32-bit Office add-ins or VBA using Declare statements. Move those to 64-bit, or exclude the devices that need them from the hotpatch policy.

Step 1: Design the rings

Use separate rings for small, early groups and the broad population, assigned to device groups so policy applies without anyone having to sign in. The available update settings are:

SettingRange or options
Quality update deferral period (days)0 to 30
Feature update deferral period (days)0 to 365
Set feature update uninstall period2 to 60 days
Microsoft product updatesAllow or Block
Windows driversAllow or Block
Enable pre-release buildsRelease Preview, Beta Channel or Dev Channel

An example layout, which you should adjust to your own change process:

RingQuality deferralQuality deadlineGrace period
Pilot (IT staff)0 days2 days1 day
Early (a cross-section of departments)3 days3 days2 days
Broad (everyone else)7 days5 days2 days

If you control Windows versions with feature update policies, set Feature update deferral period (days) to 0 in every ring so ring deferrals don't delay or block what the feature update policy offers. Upgrading Windows 11 24H2 to 25H2 with feature update policies covers that side.

Step 2: Create the update rings

  1. In the Intune admin center, go to Devices > By platform > Windows > Manage updates > Windows updates.
  2. Select the Update rings tab > Create profile and give the ring a name.
  3. Configure the update settings from Step 1.
  4. Configure the user experience settings:
    • Automatic update behavior: Auto install at maintenance time installs during automatic maintenance and blocks automatic restarts during Active hours start and Active hours end. Other options include Auto install and restart at a scheduled time and Auto install and reboot without end-user control.
    • Option to pause Windows updates: Disable stops users pausing updates themselves.
    • Option to check for Windows updates: Enable lets users scan on demand.
    • Change notification update level: leave restart warnings on unless you have a reason not to.
    • Use deadline settings: Allow, then set Deadline for feature updates (2 to 30 days), Deadline for quality updates (2 to 30 days), Grace period (0 to 7 days) and Auto reboot before deadline.
  5. Add scope tags if you use them, assign the ring to its device group, and select Create.

Deadlines count from when the device's update scan first discovered the update. Microsoft recommends Auto reboot before deadline set to Yes, so the device restarts outside active hours when nobody is using it. With No, the device waits for the deadline and grace period to expire and then restarts, which can happen during active hours.

Step 3: Turn on hotpatch

  1. In the Intune admin center, select Devices, then under Manage updates select Windows updates.
  2. Open the Quality updates tab, select Create and choose Windows quality update policy.
  3. Under Basics, name the policy, for example QU - Hotpatch - All eligible.
  4. Under Settings, set When available, apply without restarting the device ("Hotpatch") to Allow.
  5. Choose scope tags, assign the policy to your device groups, and select Create.

You can also edit an existing Windows quality update policy and set the same option to Allow. If you use Windows Autopatch groups, create the hotpatch policy and assign the devices to it; turning hotpatch on doesn't change the deferral applied by the Autopatch group.

You can assign the policy broadly. Devices that don't meet a prerequisite, such as VBS not running or not being on the latest baseline, simply get the standard latest cumulative update and keep their ring settings. In a hotpatch month, a device that isn't on the latest baseline gets the baseline (with restart) and the hotpatch.

Step 4: Verify on a device

  1. VBS: open System Information and check that Virtualization-based security shows Running in the System summary.
  2. Policy: open Settings > Windows Update > Advanced options > Configured update policies and look for Enable hotpatching when available.
  3. Event log: in Event Viewer, filter for AllowRebootlessUpdates. An entry with the value set shows the device is enrolled and has hotpatch turned on, for example:
"data": { "payload": "{\"Orchestrator\":{\"UpdatePolicy\":{\"Update/AllowRebootlessUpdates\":true}}}", "isEnrolled": 1, "isCached": 1, "vbsState": 2,
  1. Build: after the next hotpatch month, compare the device build with the hotpatch calendar entry for that month.

For the fleet view, go to Reports > Windows Autopatch > Windows quality updates, select the Reports tab and open Hotpatch quality updates. It shows, per policy, devices that are up to date, hotpatched, not up to date, in progress, not ready or paused, with a 90-day trend. The data refreshes every four hours.

Step 5: Run the monthly routine

  • Before Patch Tuesday: check the hotpatch calendar to see whether this month is a baseline or a hotpatch month, and warn users about restarts in baseline months.
  • Pilot first: the pilot ring's short deferral means problems show up there days before the broad ring.
  • Pause if needed: on a ring's overview, Pause stops feature or quality updates for up to 35 days. Devices only receive the pause at their next check-in, so a device that installs a scheduled update before checking in isn't protected. Extend resets the pause to 35 days, and Resume restarts updates.
  • Roll back if needed: Uninstall removes the latest feature or quality update from the ring's devices as soon as they receive the policy, without waiting for maintenance windows; if removal needs a restart, users get no option to delay it. It also pauses that update type on the ring. Hotpatch updates can't roll back automatically, but you can uninstall them; uninstalling a hotpatch requires a restart.
  • Plan feature updates around the calendar: upgrade hotpatch devices to a new Windows version in a baseline month. If you upgrade in a hotpatch month, the device switches to standard updates and needs a restart, and hotpatch resumes after the next baseline.

Troubleshooting

SymptomLikely causeFix
Device installs the full cumulative update and restarts in a hotpatch monthNot on the latest baseline, VBS not running, or not in the hotpatch policyCheck VBS, the baseline build and the policy assignment
Enable hotpatching when available missing from configured policiesPolicy not assigned or not yet appliedCheck the assignment and sync the device
Autopatch alert "Hotpatch – VBS not running"VBS disabled or unsupported on the deviceTurn on VBS with the VirtualizationBasedTechnology CSP
Arm64 device misses hotpatchesCHPE still enabledSet DisableCHPE or HotPatchRestrictions=1 and restart
Hotpatch errors in the Application logThe hotpatch monitor service found a problemReview events filtered on "hotpatch"; on a critical error the device installs the standard update
Paused ring still installed an updateDevice installed before it checked inExpect a short lag; use Uninstall if needed
Restarts during working hoursAuto reboot before deadline set to No, or deadlines too shortSet it to Yes and review deadlines and active hours
Feature updates never offeredwlidsvc disabledEnable the Microsoft Account Sign-In Assistant service

Checklist

  • Rings assigned to device groups, with deferrals that stagger pilot, early and broad devices.
  • Deadlines and grace periods set, with Auto reboot before deadline on Yes.
  • Feature update deferral at 0 where feature update policies control versions.
  • Hotpatch licensing confirmed; devices on Windows 11 24H2 or later.
  • VBS running on target devices; CHPE disabled on Arm64 devices that will use hotpatch.
  • Windows quality update policy with hotpatch set to Allow, assigned.
  • Devices show Enable hotpatching when available; Hotpatch quality updates report reviewed.
  • Monthly check of the hotpatch calendar, with feature upgrades scheduled in baseline months.

References

Questions people ask

Does hotpatch remove the need for update rings?

No. Hotpatch is enabled with a Windows quality update policy, and Microsoft states that your existing update ring configurations are honored alongside it. Deferrals, deadlines and active hours from the rings still apply.

How often do hotpatched devices still need to restart?

Devices restart for baseline updates, which Microsoft plans for January, April, July and October. The other months are hotpatch months with no restart. Microsoft can add unplanned baseline months for security reasons, so check the hotpatch calendar each month.

Which licenses are required for Windows hotpatch?

Microsoft lists Windows 11 Enterprise E3 or E5, Microsoft 365 F3, Windows 11 Education A3 or A5, Microsoft 365 Business Premium and Windows 365 Enterprise. Devices also need Windows 11 version 24H2 or later and Intune to deploy the quality update policy.

What happens to a device that isn't eligible for hotpatch?

It receives the standard latest cumulative update instead, which needs a restart. Its update ring settings stay as configured.

Microsoft IntuneWindows Update for BusinessWindows HotpatchWindows 11 Enterprise
  1. Upgrade Windows 11 24H2 to 25H2 with Intune Feature Update Policies

    Move devices off Windows 11 24H2 before end of servicing: check readiness reports, create an Intune feature update policy for 25H2, roll it out in stages and track it.

  2. Autopilot device preparation vs classic Autopilot: choosing the right one

    Compare Windows Autopilot device preparation and classic Windows Autopilot on join types, modes, app limits, registration, ESP and reporting, and pick the right one for each device population.

  3. Azure point-to-site VPN with Entra ID sign-in, MFA and the Azure VPN Client

    Configure an Azure VPN Gateway point-to-site connection that signs users in with Microsoft Entra ID, enforce MFA, and deploy the Azure VPN Client profile with Intune.