← Back
Windows Autopatch for the US government: How to get started
MC1185309 · build prod-20251231-200323
Category
stayInformed
Severity
normal
Major change
False
Last modified
2025-11-12 18:01:40
Summary source
Azure OpenAI (gpt-4.1)
Action by (Graph)
Action by (AI)
Services
Windows
Tags
Admin impact
Master tags
Security
Roadmap IDs

One-line summary

Windows Autopatch will be available for US government organizations in Microsoft 365 Government starting November 2025, enabling automated update management for GCC devices.

Similar updates

More like this

Details

Body (from Message Center)

The power of automated Windows update management is coming to government SKUs. This cloud-based service has now been approved to be added to the Azure FedRAMP High Provisional Authorization to Operate. If you manage Government Community Cloud (GCC) devices, this service became part of Microsoft 365 Government this month. 
 
When will this happen: 
Windows Autopatch is available to US government organizations starting November 2025. 
 
How this will affect your organization: 
This is what Windows Autopatch allows you to accomplish for your GCC devices: 
  • Control over which content is approved for deployment to which devices 
  • Automation of a safe rollout process 
  • Faster security with hotpatching 
  • Pausing or expediting monthly quality updates or drivers 
  • Simplified update compliance reporting 
  • Policy management and reporting through the Microsoft Intune admin center 
 
What you need to do to prepare: 
Review additional information for prerequisites and complete details. Here’s one way to get started: 
  1. Go to the Microsoft Intune admin center
  2. In the left pane, select Tenant administration and then navigate to Windows Autopatch > Autopatch groups
  3. Create a Windows Autopatch group and assign devices, automating a few things: 
  4. Distribute devices for gradual rollout into a set of Microsoft Entra groups. 
  5. Configure a safe rollout schedule using update rings
  6. (Optional) Configure content approval using feature and driver update policies. 
  7. (Optional) Configure update settings for Microsoft 365 Apps and Microsoft Edge
  8. Enroll devices to receive hotpatch updates, getting them secure faster. 
  9. That’s it! Just monitor the reports to ensure that you’re hitting your update compliance targets. 
 
Additional information: 
 

Raw JSON (for debugging)

Expand/collapse the full payload below.
Show/hide raw
{
  "snapshot_item": {
    "action_required_by": null,
    "ai_action_required_by": null,
    "ai_actions": [
      "Review prerequisites for Windows Autopatch",
      "Create and assign Autopatch groups in Intune",
      "Configure update policies and schedules",
      "Enroll devices for hotpatch updates",
      "Monitor update compliance reports",
      "Set up role-based access control",
      "Configure network for Autopatch"
    ],
    "ai_master_tags": [
      "Security"
    ],
    "ai_model": "gpt-4.1",
    "ai_summary": "Windows Autopatch will be available for US government organizations in Microsoft 365 Government starting November 2025, enabling automated update management for GCC devices.",
    "ai_topics": [
      "Windows",
      "Microsoft 365",
      "Intune",
      "Entra"
    ],
    "category": "stayInformed",
    "details_map": {},
    "id": "MC1185309",
    "importance": 0,
    "is_major_change": false,
    "last_modified": "2025-11-12T18:01:40Z",
    "ms_products": [
      "Windows"
    ],
    "platforms": null,
    "roadmap_ids": [],
    "services": [
      "Windows"
    ],
    "severity": "normal",
    "tags": [
      "Admin impact"
    ],
    "title": "Windows Autopatch for the US government: How to get started"
  }
}