Blog Post

Windows IT Pro Blog
4 MIN READ

Hotpatch for Windows client now available

David_Callaghan's avatar
Apr 02, 2025

Hotpatch updates for Windows 11 Enterprise, version 24H2 for x64 (AMD/Intel) CPU devices are now available. With hotpatch updates, you can quickly take measures to help protect your organization from cyberattacks, while minimizing user disruptions.

Hotpatching represents a significant advancement in our journey to help you, and everyone who uses Windows, stay secure and productive. So, let's talk about the benefits, how it works, and how you and your organization can take advantage of this advancement as part of your Windows servicing journey.

 

 

Benefits of hotpatch updates

Hotpatching offers numerous enhancements when it comes to keeping Windows client devices up to date:

  • Immediate protection: Hotpatch updates take effect immediately upon installation, providing rapid protection against vulnerabilities.
  • Consistent security: Devices receive the same level of security patching as the monthly standard security updates released on the second Tuesday of every month.
  • Minimized disruptions: Users can continue their work without interruptions while hotpatch updates are installed. Hotpatch updates don't require the PC to restart for the remainder of the quarter. (Note: OS features, firmware, and/or application updates may still cause a restart in the quarter.)
The Windows Update settings page shows a message that the latest security update was installed without a restart.

How hotpatch technology works

You'll first create a hotpatch-enabled quality update policy in Windows Autopatch through the Microsoft Intune console. All eligible Windows 11 Enterprise, version 24H2 devices managed by this policy will be offered hotpatch updates in a quarterly cycle, as shown below. The hotpatch updates follow the same ring deployment schedule as standard updates. Devices receiving the hotpatch update will see a different KB number tracking the hotpatch release and a different OS version than devices receiving the standard update that requires a restart.

A diagram showing baseline and hotpatch months, illustrating that no restarts are needed on hotpatch month.

Hotpatch updates operate on a quarterly cycle:

  • Cumulative baseline month: In January, April, July, and October, devices install the monthly fixed security update and restart. This update includes the latest security fixes, cumulative new features, and enhancements since the last cumulative baseline.
  • Subsequent two months: Devices receive hotpatch updates, which only include security updates and do not require a restart. These devices will catch up on features and enhancements with the next cumulative baseline month (quarterly).

This cycle reduces the number of required restarts for Windows updates from twelve to just four per year, thanks to eight planned hotpatch updates annually:

QuarterBaseline update 
(requires restart)
Hotpatch update
(no restart required)
1JanuaryFebruary and March
2AprilMay and June
3JulyAugust and September
4OctoberNovember and December

Get started with hotpatch

To enable hotpatching for Windows client devices, you will need:

  • A Microsoft subscription that includes Windows 11 Enterprise E3, E5, or F3, Windows 11 Education A3 or A5, or a Windows 365 Enterprise subscription
  • Devices running Windows 11 Enterprise, version 24H2 (Build 26100.2033 or later) and with the current baseline update installed
  • An x64 CPU including AMD64 and Intel (Note: Arm®64 devices are still in public preview)
  • Microsoft Intune to manage deployment of hotpatch updates with a hotpatch-enabled Windows quality update policy
  • Virtualization-based Security (VBS) enabled

For Arm64 devices, hotpatch updates are still in public preview, so there is an additional prerequisite. Specifically, you will need to set the following registry key to turn off CHPE support:

  • Path: HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management
  • DWORD Key value: HotPatchRestrictions=1

A new DisableCHPE CSP will be provided as an alternative to manually setting the HotPatchRestrictions registry key as shown above. Restart the device to ensure the operating system is enforcing the setting. You only need to set this once. This new CSP will be available shortly after the April 2025 security update. Devices must disable CHPE to be eligible for hotpatch updates.

If you meet the prerequisites for hotpatch updates, you can opt devices in (or out) for automated hotpatch update deployment using Windows Autopatch. From the Microsoft Intune admin center, navigate to Devices > Windows updates > Create Windows quality update policy and toggle it to Allow.

Enabling hotpatch updates by creating a Windows quality update policy in the Intune admin center.

Enroll and prepare now

Good news: The Windows quality update policy can auto-detect if your targeted devices are eligible for hotpatch updates. Devices running Windows 10 and Windows 11, version 23H2 and lower will continue to receive the standard monthly security updates, helping ensure that your ecosystem stays protected and productive.

Maintain robust security with hotpatch updates

The general availability of hotpatch technology for Windows clients marks a significant step forward in enhancing security and productivity for Windows 11 Enterprise users.

"Hotpatching has been a game-changer for keeping our devices secure without disrupting work. Initially, we didn't realize how significant it was to have security updates take effect immediately—without waiting for a reboot. But now, we see the real advantage: security is applied instantly, reducing risk and improving efficiency."

-- Michael Meier, Senior System Administrator, Krones AG


Hotpatch updates help ensure that devices are secured and that users stay productive with minimal disruptions. We encourage organizations to take advantage of this new feature to maintain a robust security posture while minimizing the impact on the user experience. Hotpatch updates are generally available on Intel and AMD-powered devices as of today, April 2, 2025, with the feature becoming available on Arm64 devices at a later date.    

For more information, please refer to:


Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.

Updated Apr 02, 2025
Version 1.0

14 Comments

  • hoyty76's avatar
    hoyty76
    Steel Contributor

    Does this work with Windows 11 Education (the sister SKU to Enterprise)? Not talking about Pro Education.

  • CK6218's avatar
    CK6218
    Copper Contributor

    That mean NASA need to take note for their Windows clients during January, April, July, and October, it might auto reboot during rocket in launching stage.

  • Xyz00777's avatar
    Xyz00777
    Copper Contributor

    Nice feature and cool that windows is closing the feature gap to what Linux can since years. 

    But what I really don't understand is, why only business and why only with office 365 business subscriptions. Especially a feature like that who can break many things I would have suspected to first came out on windows home and pro users and than later to business and educations license users so it is already tested and really stable . . . So things like the above with arm systems would not happen to enterprise people , where time can literally be money...

    So I hope that this really strange limitations will get lifted and normal consumer can also be using it in the future :) 

    And again nice work implementing it! 

  • harveyarscott's avatar
    harveyarscott
    Copper Contributor

    I have enabled Hotpatch on my 24H2 device and it's working well. One thing I have noticed is that insider preview patches no longer appear. I assume this is correct and the insider preview patches do not work alongside Hotpatch?

    • David_Callaghan's avatar
      David_Callaghan
      Icon for Microsoft rankMicrosoft

      That is the expected behavior. The Windows Quality Update policy will keep the hotpatch enabled devices on the patch Tuesday update cadence and not offer "D" releases.

  • Hello! Great news! David_Callaghan 

    But I have a question about which would be the correct Virtualization-based Security (VBS) configuration, 1 or 2?

     

    This is something that can be very confusing, as the names are similar.

    • David_Callaghan's avatar
      David_Callaghan
      Icon for Microsoft rankMicrosoft

      #2 is the VBS setting you want to enable. Must reboot the device to take effect.  Check "System Information" scroll to the bottom - you want to see "Virtualization Based Security" - Running

  • Can this be extended so users with Windows 11 Enterprise license + Intune subscription can use it too? In other words, rather than requiring a Windows 11 Enterprise as a subscription, enable it so users with valid Windows 11 Enterprise licenses can use it too.

  • Be careful not to deploy the Intune policy to ARM64 devices yet, it screwed up my Surface Laptop 7 and I had to manually get rid of all the hotpatching settings.

    • David_Swenson's avatar
      David_Swenson
      Steel Contributor

      Thats interesting... it worked great for us via Intune with a filter applied for ARM64 when using

      ./Device/Vendor/MSFT/Policy/Config/Registry/HKLM/SYSTEM/CurrentControlSet/Control/SessionManager/MemoryManagement/HotPatchRestrictions

      Integer = 1

      Worked on 2nd Gen Surface Pro X and Surface Pro 9. I am hopeful for a more native support approach by the time Summer rolls around... 

      • MaximeRastello's avatar
        MaximeRastello
        Brass Contributor

        I will give it a try, as this requirement was not documented when I tried a few months back ;)

  • David_Swenson's avatar
    David_Swenson
    Steel Contributor

    Please enable Hotpacthing for Microsoft 365 Business Premium users/Windows 11 Pro Business SKUs. This is an essential feature that should extend to all Windows 11 users if they are managed by Intune. 

OSZAR »