← Back
(Updated) Hotpatch for Windows client now available
MC1046878 · build prod-20251231-200323
Category
stayInformed
Severity
normal
Major change
False
Last modified
2025-04-09 18:13:50
Summary source
Azure OpenAI (gpt-4.1)
Action by (Graph)
Action by (AI)
Services
Windows, Windows Autopatch
Tags
Admin impact
Master tags
Security
Roadmap IDs

One-line summary

Hotpatch updates are now generally available for Windows 11 Enterprise 24H2 (x64), enabling rapid, restart-free security updates via Windows Autopatch and Intune; Arm64 support remains in preview.

Similar updates

More like this
MC1068760 Resources to get started with hotpatch updates for Windows 11, version 24H2
Prerequisites include:  Windows Autopatch prerequisites   Devices running Windows 11 Enterprise, version 24H2 (Build 26100.2033 or later) and with the current baseline update installed  An x64 CPU including AMD64 and Intel (Note: Arm64 devices are still in public preview)  Microsoft Intune to manage deployment of hotpatch updates with a.
MC999973 Reminder: Hotpatch eligibility and prerequisites
Reminder: Hotpatch eligibility and prerequisites Hotpatch for Windows Autopatch is in public preview; devices need Windows 11 24H2 with Jan 2025 update, VBS enabled, and specific registry changes for Arm64 to deploy without restarts. (Updated 2/7 8:00pm to call out additional prerequisites related to OS version) Hotpatch is an extension of.
MC1115741 Hotpatching now available for 64-bit Arm architecture
Hotpatching now available for 64-bit Arm architecture Hotpatching for Windows 11 24H2 Arm64 devices is now generally available, enabling security updates without restarts; admins must disable CHPE and enroll devices in a hotpatch policy. More ente... Hotpatching is now available for Windows 11, version 24H2 Arm64 devices. Hotpatching for Windows.
MC1107364 Hotpatching now enabled by default for new Windows quality update policies
Hotpatching now enabled by default for new Windows quality update policies New Windows quality update policies in Autopatch now enable hotpatch by default, improving security compliance and reducing downtime for supported devices. ...ch updates enabled by default to streamline policy creationWhat you need to do to prepare:   Create your new.
MC1073823 Hotpatch for client: Frequently asked questions
Hotpatch for client: Frequently asked questions May 2025 hotpatch update for Windows 11 24H2 is available; review new FAQ to prepare devices and understand hotpatching eligibility, deployment, and technical details. Hotpatching offers faster compliance for devices running Windows 11 Enterprise or Education, version 24H2. ...selection of.
MC1138549 Hotpatch readiness: Enable VBS at scale
Hotpatch readiness: Enable VBS at scale To use Windows Autopatch hotpatching (security updates without restart), you must enable virtualization-based security (VBS) on Windows clients using Intune, PowerShell, or Command Prompt. Additional information:   Find step-by-step instructions to enable VBS and to validate and monitor enablement at .

Details

Body (from Message Center)

Updated April 3, 2025: The language in the first paragraph was updated to provide more clarity on the update process. 

Hotpatch updates are now available for organizational devices on Windows 11 Enterprise, version 24H2 and x64 (AMD/Intel) CPU. With hotpatch updates, you can quickly take measures to help protect your organization from cyberattacks, while minimizing user disruptions. You’ll first create a hotpatch-enabled quality update policy in Windows Autopatch through the Microsoft Intune console. Eligible devices managed by this policy will be offered hotpatch updates in a quarterly cycle. Eight months out of twelve, you won’t need to restart the device for the security update to take effect.  

When will this happen: 
  • Hotpatch updates are generally available on Intel and AMD-powered devices as of today, April 2, 2025, with the feature becoming available on Arm64 devices at a later date. 
  • For Arm64 devices, hotpatch updates are still in public preview.     
  • A new DisableCHPE CSP will be available for Arm64 devices shortly after the April 2025 security update. 

How this will affect your organization: 
Hotpatch updates take effect immediately upon installation, providing rapid protection against vulnerabilities. Devices receive the same level of security patching as the monthly standard security updates released on the second Tuesday of every month. Users can continue their work without interruptions while hotpatch updates are installed. Hotpatch updates don’t require the PC to restart for the remainder of the quarter. (Note: OS features, firmware, and/or application updates may still cause a restart in the quarter.) 

What you need to do to prepare: 
Check if your devices are eligible for hotpatch updates by reading Additional information. If you meet the prerequisites, you can opt devices in (or out) for automated hotpatch update deployment using Windows Autopatch. From the Microsoft Intune admin center, navigate to Devices > Windows updates > Create Windows quality update policy and toggle it to Allow.  
 
Additional information: 
Read more about hotpatch for Windows client, its benefits, how it works, and how your organization can take advantage of it today.  

Raw JSON (for debugging)

Expand/collapse the full payload below.
Show/hide raw
{
  "snapshot_item": {
    "action_required_by": null,
    "ai_action_required_by": null,
    "ai_actions": [
      "Check device eligibility for hotpatch",
      "Create/update Windows quality update policy in Intune",
      "Opt devices in or out of hotpatch deployment"
    ],
    "ai_master_tags": [
      "Security"
    ],
    "ai_model": "gpt-4.1",
    "ai_summary": "Hotpatch updates are now generally available for Windows 11 Enterprise 24H2 (x64), enabling rapid, restart-free security updates via Windows Autopatch and Intune; Arm64 support remains in preview.",
    "ai_topics": [
      "Windows",
      "Windows Autopatch",
      "Intune"
    ],
    "category": "stayInformed",
    "details_map": {},
    "id": "MC1046878",
    "importance": 1,
    "is_major_change": false,
    "last_modified": "2025-04-09T18:13:50Z",
    "ms_products": [
      "Windows",
      "Windows Autopatch"
    ],
    "platforms": null,
    "roadmap_ids": [],
    "services": [
      "Windows",
      "Windows Autopatch"
    ],
    "severity": "normal",
    "tags": [
      "Admin impact"
    ],
    "title": "(Updated) Hotpatch for Windows client now available"
  }
}