Hotpatch in Microsoft Intune lets you apply security updates to Windows 11 devices without a full reboot. This is one of the most significant quality-of-life improvements for Intune admins in 2026, especially for MSPs managing large fleets where downtime is expensive and user disruption is a constant battle.
Microsoft globally enabled Hotpatch tenant-wide in April 2026. Many organizations saw their first hotpatch updates in May. The feature is designed to reduce reboots while keeping devices secure.
What Is Intune Hotpatch?
Intune Hotpatch is a Windows 11 feature that delivers security updates directly to the kernel and core components without requiring a device restart. It is available for Windows 11 Enterprise and Education editions (24H2 and later) that meet specific prerequisites.
Unlike traditional cumulative updates that bundle everything and often force a reboot, Hotpatch focuses on security fixes that can be applied in the background.
Recent discussions in r/Intune show that once enabled, qualifying devices should start receiving hotpatches automatically in supported months.
How Intune Hotpatch Works
Hotpatch works by installing security updates that do not require a full OS reboot. Microsoft releases both hotpatch and baseline (full reboot) updates on a schedule.
Key points from Microsoft documentation and community feedback:
- Only security updates are delivered via hotpatch in qualifying months.
- Some months are designated as baseline months that require a traditional reboot.
- Devices must be on Windows 11 24H2 or 25H2 Enterprise.
- Works with both Autopatch and standard Intune update rings.
One admin noted in r/Intune that hotpatch versions show different build numbers (e.g., 10.0.26200.8390) compared to the full baseline update.
Prerequisites and Enabling Hotpatch
For Hotpatch to work on a device, these conditions must be met:
- Windows 11 Enterprise or Education, version 24H2 or later.
- Device enrolled in Intune (hybrid or Entra joined).
- Virtualization Based Security (VBS) enabled.
- Telemetry not disabled.
- Proper licensing (E3/E5 or equivalent).
Important PSA from the community: In April 2026, Microsoft globally enabled Hotpatch tenant-wide for all tenants. You can find (and override) the setting here:
Tenant administration > Windows Autopatch > Tenant management.
Many devices became eligible starting with the May 2026 updates without any additional configuration.
Troubleshooting Hotpatch Status Showing as “Undefined”
Several admins have reported devices meeting all requirements but showing “undefined” for hotpatch status. Common checks include:
- Confirm the device is on 24H2/25H2 Enterprise.
- Verify VBS is enabled (check via msinfo32 or Intune reports).
- Ensure diagnostic data/telemetry is set to Required or Enhanced.
- Check that no custom policies are blocking the feature.
- Wait for the next hotpatch cycle — status may not populate immediately.
If issues persist, some teams have used Intune remediations to force re-evaluation or check the hotpatch readiness state.
Benefits of Intune Hotpatch for MSPs and Clients
Hotpatch brings real advantages for managed service providers:
- Reduced downtime — no more scheduling reboots during business hours for security updates.
- Immediate protection — security fixes go live faster without waiting for maintenance windows.
- Better client satisfaction — fewer “why did my computer restart?” tickets.
- Scalable for fleets — especially valuable when managing thousands of devices with Autopatch.
Community members moving to 24H2 are eager to adopt it precisely because it reduces the number of disruptive baseline reboot months.
Understanding the Hotpatch Calendar
Not every month is a hotpatch month. Microsoft publishes a calendar showing which months use hotpatch updates versus baseline (full reboot) updates.
Link: Windows 11 Hotpatch Calendar
Some admins have noted more baseline months than expected in 2026 so far. Plan your communication and maintenance windows accordingly.
How to Configure and Monitor Intune Hotpatch
Hotpatch is largely automatic once prerequisites are met and the tenant setting is enabled. However, you should still control rollout:
- Go to Tenant administration > Windows Autopatch > Tenant management to review the global setting.
- Use pilot groups in your update rings or Autopatch profiles.
- Monitor device status in Intune under Devices > Windows > Windows updates.
- Watch for the specific hotpatch build numbers in your reports.
Even if you don’t use Autopatch, hotpatch can still apply in standard Intune-managed environments.
Real-World Tips and Tricks from the Community
Admins in r/Intune are sharing these practical insights:
- Hotpatch runs side-by-side with regular updates in some months — don’t expect it to completely replace the normal KB cycle.
- Use the feature to improve user experience, but keep clear communication about the few months that will still require reboots.
- If status shows undefined on qualifying devices, double-check VBS and telemetry first before opening tickets with Microsoft.
- Consider excluding certain high-sensitivity or legacy devices from the tenant-wide setting if you need more control.
- Combine Hotpatch with good endpoint analytics and proactive remediations for the best results.
One common sentiment: the reduction in reboots is noticeable and worth the (relatively small) effort to validate prerequisites.
Conclusion
Intune Hotpatch is a genuine step forward for reducing operational friction in 2026. With the tenant-wide enablement, most qualifying Windows 11 Enterprise devices should now be receiving these zero-reboot security updates.
For MSPs, this is a strong talking point when discussing modernization and reduced client disruption. However, it is not magic — you still need to understand the calendar, prerequisites, and occasional baseline months.
Start with a small pilot group, monitor status closely, and leverage the community discussions in r/Intune for real-world gotchas.
For more Intune insights, check our guide on Intune Patch Management and other posts on Windows Autopatch and update strategies.
Frequently Asked Questions
What is Intune Hotpatch?
Intune Hotpatch delivers security updates to Windows 11 without requiring a full device reboot for qualifying devices and months.
Is Hotpatch on by default?
Microsoft enabled it tenant-wide in April 2026. Most devices meeting the prerequisites should start receiving hotpatches automatically.
What are the requirements?
Windows 11 Enterprise 24H2/25H2, VBS enabled, telemetry enabled, and Intune management.
Do I still need Autopatch for Hotpatch?
No. While it integrates well with Autopatch, hotpatch can apply through standard Intune update rings as well.
Why is my device showing “undefined”?
Common causes include missing prerequisites (VBS, telemetry, edition) or the device not yet processed the latest cycle. Check the Microsoft Hotpatch calendar for the current month.
