Microsoft to Enable Windows Hotpatch Security Updates by Default
Summary
Hide ▲
Show ▼
Microsoft will enable hotpatch security updates by default for eligible Windows devices managed through Microsoft Intune and the Microsoft Graph API, starting with the May 2026 Windows security update. This change aims to halve the time to reach 90% patch compliance, reducing the window of exposure to attacks. The updates will be delivered through Windows Autopatch, which automatically keeps Windows and Microsoft 365 software up to date. IT administrators will have the option to disable hotpatch updates at the tenant level and enable them for specific devices. Organizations can opt out of hotpatch updates using controls in Microsoft Intune, which will be available starting April 1, 2026.
Timeline
-
10.03.2026 12:35 1 articles · 23h ago
Microsoft to Enable Hotpatch Security Updates by Default in May 2026
Microsoft will enable hotpatch security updates by default for eligible Windows devices managed through Microsoft Intune and the Microsoft Graph API starting with the May 2026 Windows security update. This change aims to halve the time to reach 90% patch compliance, reducing the window of exposure to attacks. The updates will be delivered through Windows Autopatch, which automatically keeps Windows and Microsoft 365 software up to date. IT administrators will have the option to disable hotpatch updates at the tenant level and enable them for specific devices. Organizations can opt out of hotpatch updates using controls in Microsoft Intune, which will be available starting April 1, 2026.
Show sources
- Microsoft to enable Windows hotpatch security updates by default — www.bleepingcomputer.com — 10.03.2026 12:35
Information Snippets
-
Microsoft will enable hotpatch security updates by default for eligible Windows devices managed through Microsoft Intune and the Microsoft Graph API starting May 2026.
First reported: 10.03.2026 12:351 source, 1 articleShow sources
- Microsoft to enable Windows hotpatch security updates by default — www.bleepingcomputer.com — 10.03.2026 12:35
-
Windows Autopatch will deliver the updates, automatically keeping Windows and Microsoft 365 software up to date.
First reported: 10.03.2026 12:351 source, 1 articleShow sources
- Microsoft to enable Windows hotpatch security updates by default — www.bleepingcomputer.com — 10.03.2026 12:35
-
The change is expected to halve the time to reach 90% patch compliance, reducing the window of exposure to attacks.
First reported: 10.03.2026 12:351 source, 1 articleShow sources
- Microsoft to enable Windows hotpatch security updates by default — www.bleepingcomputer.com — 10.03.2026 12:35
-
IT administrators can disable hotpatch updates at the tenant level and enable them for specific devices.
First reported: 10.03.2026 12:351 source, 1 articleShow sources
- Microsoft to enable Windows hotpatch security updates by default — www.bleepingcomputer.com — 10.03.2026 12:35
-
Organizations can opt out of hotpatch updates using controls in Microsoft Intune, available starting April 1, 2026.
First reported: 10.03.2026 12:351 source, 1 articleShow sources
- Microsoft to enable Windows hotpatch security updates by default — www.bleepingcomputer.com — 10.03.2026 12:35
-
Windows Autopatch is currently running on more than 10 million production devices.
First reported: 10.03.2026 12:351 source, 1 articleShow sources
- Microsoft to enable Windows hotpatch security updates by default — www.bleepingcomputer.com — 10.03.2026 12:35