Microsoft to Turn on Reboot-Free Windows Security Updates by Default
Mar 10, 2026 // 15:19 - Tristan Wall


Starting with the May 2026 Windows security update, Microsoft will enable hotpatching by default for all eligible devices managed through Microsoft Intune and the Microsoft Graph API. This change shifts from an opt-in model to a default-on approach for enterprise environments using Windows Autopatch.

Key Details of the Rollout

  • Target Audience: Organizations using Windows Autopatch via Microsoft Intune. This generally does not impact standard home users.
  • Effective Date: Default activation begins with the May 2026 security update.
  • Opt-Out Period: Controls to opt out at the tenant or group level will be available starting April 1, 2026.
  • Compliance Benefit: Microsoft estimates hotpatching can help organizations reach 90% patch compliance in half the time compared to traditional methods.

How Windows Hotpatching Works

Hotpatching applies security updates to the in-memory code of running processes, eliminating the need for a system restart for most monthly updates.

  • Quarterly Cycle: Restarts are still required once per quarter (January, April, July, and October) for “baseline” updates.
  • Prerequisites:
    • OS: Windows 11 Enterprise or Education, version 24H2 or later.
    • Architecture: x64 (Intel/AMD); Arm64 support is currently in public preview.
    • Security: Virtualization-based Security (VBS) must be enabled.

Management for IT Admins

  • Existing Policies: Current hotpatch settings in quality update policies will be respected. If no policy is assigned, the new tenant-level default will apply.
  • Monitoring: Admins can use the Hotpatch quality updates report in Intune to track “Hotpatch ready” devices.
  • Exclusions: Devices that don’t meet hardware or software prerequisites will continue to receive standard monthly updates that require reboots.

#default  #microsoft  #news  #reboot-free  #security  #turn  #updates  #windows   —   News