Windows Autopatch: Requirements, Pricing and Setup Guide (2026)

by | Apr 27, 2024

Windows Autopatch is Microsoft’s cloud service that automates the delivery of Windows quality updates, feature updates, driver and firmware updates, Microsoft 365 Apps, Microsoft Edge, and Microsoft Teams across your managed device fleet. Instead of building and babysitting update rings yourself, you hand the schedule to Microsoft and the service handles ring assignment, phased rollout, and halting a bad update before it reaches everyone.

This guide covers what Windows Autopatch actually does, what it costs, the prerequisites you need in place, how it differs from Intune update rings, and the significant hotpatching change that landed in 2026.

View our application update plans

What Is Windows Autopatch?

Windows Autopatch is a managed update service built on Windows Update for Business. It is included with several Microsoft licenses at no additional cost, and it shifts update management from a task you configure to a service Microsoft operates on your behalf.

The distinction matters. With traditional update management you decide when each ring receives an update, you monitor the rollout, and you decide whether to pause it. With Autopatch, Microsoft assigns devices to deployment rings automatically, releases updates progressively, monitors telemetry across its entire customer base, and can halt a problematic update before it reaches your broader population.

That trade is the entire value proposition: you give up granular scheduling control in exchange for not having to think about it.

What Windows Autopatch Manages

Autopatch covers considerably more than Windows itself, and this breadth is what separates it from Windows Update for Business alone:

  • Windows quality updates — the monthly security and reliability updates, with a service target of keeping at least 95% of eligible devices current within 21 days of release
  • Windows feature updates — annual version upgrades, targeting at least 99% of eligible devices on a supported Windows version
  • Microsoft 365 Apps for enterprise — targeting at least 90% of eligible devices on a supported Monthly Enterprise Channel build
  • Microsoft Edge — kept current on the Stable channel
  • Microsoft Teams — updated automatically alongside the rest of the stack
  • Drivers and firmware — optional management of hardware updates published through Windows Update

Those percentages are service level objectives Microsoft publishes, not guarantees you configure. They are useful benchmarks when you need to demonstrate patch compliance to an auditor.

Windows Autopatch automating patch deployment across managed devices

Windows Autopatch Licensing and Pricing

Windows Autopatch has no separate price tag. It is included with the following licenses:

  • Windows 10/11 Enterprise E3 and E5
  • Microsoft 365 E3 and E5
  • Microsoft 365 Business Premium
  • Windows 10/11 Education A3 and A5

Microsoft broadened eligibility in April 2025, extending Autopatch to Business Premium and A3 licences and removing the separate feature activation step that previously stood between eligible tenants and the service. If you evaluated Autopatch before that change and concluded your licensing did not qualify, it is worth checking again — a large number of small and mid-sized organizations on Business Premium became eligible without realizing it.

The practical cost question is not the licence. It is whether your existing licensing already covers it, in which case Autopatch is free capability you may currently be leaving switched off.

Windows Autopatch Requirements in 2026

Before enabling Autopatch, confirm the following are in place:

  • An eligible licence assigned to the users whose devices you intend to manage
  • Devices managed by Microsoft Intune, or co-managed with Configuration Manager where the Windows Update workload is pointed at Intune
  • Microsoft Entra ID joined or Hybrid Entra ID joined devices — workgroup devices are not eligible
  • Supported Windows editions — Enterprise, Pro, or Education, running a currently serviced version
  • Connectivity to Microsoft update endpoints, which matters if you filter outbound traffic through a proxy

If your devices are not yet enrolled, start there — see our walkthrough on how to enroll a device in Intune. Autopatch has nothing to manage until enrollment is working.

Hotpatching: What Changed in 2026

The most consequential recent change is hotpatching. Beginning with the May 2026 Windows security update, Windows Autopatch enables hotpatch updates by default for all eligible devices.

Hotpatching applies security fixes to in-memory code without requiring a restart. In practice this means eligible devices receive most monthly security updates without the reboot that historically forced a choice between prompt patching and user disruption. Devices still take periodic baseline updates that do require a restart, but the reboot cadence drops substantially across the year.

For organizations that have been deferring updates because of user pushback over restarts, this materially changes the calculation. The most common reason patch compliance slips is not technical failure — it is users postponing reboots indefinitely.

Windows Autopatch vs Intune Update Rings

This is the decision most administrators are actually trying to make, and the answer depends less on features than on how much control you want to retain.

Intune Update Rings

Update rings, built on Windows Update for Business, give you granular control. You define each ring, set deferral periods, choose deadlines and grace periods, and decide when to pause a rollout. You own the schedule entirely. The scope is narrower: Windows updates and drivers, not Microsoft 365 Apps, Edge, or Teams.

Windows Autopatch

Autopatch assigns devices automatically across deployment rings — typically labelled Test, First, Fast, and Broad — distributing them by percentage of your total fleet. You do not choose when updates move between rings, and you do not approve individual updates. In exchange, Microsoft monitors rollouts across its customer base and can halt a problematic update before it reaches your Broad ring. Coverage extends across Windows, drivers, Microsoft 365 Apps, Edge, and Teams.

Which Should You Choose?

Choose Autopatch if update management is a chore rather than a discipline you actively practise, if you lack the staff to monitor rollouts, or if you want Microsoft 365 Apps and browser updates handled in the same motion.

Choose update rings if you have regulatory or change-control requirements dictating exactly when updates land, if you run line-of-business software that breaks in ways requiring you to hold updates, or if you already have a mature patch process that works.

The two are not mutually exclusive across a fleet. Many organizations run Autopatch for general knowledge-worker devices and retain manual update rings for servers, kiosks, or specialist workstations where an unexpected update is genuinely expensive.

Windows Autopatch update policies and deployment ring configuration

How Autopatch Deployment Rings Work

Autopatch distributes devices across four rings by default:

  • Test — a small validation group you populate deliberately, typically IT staff
  • First — roughly 1% of devices, the earliest broad signal that an update is healthy
  • Fast — approximately 9% of devices, expanding coverage before general release
  • Broad — the remaining ~90% of the fleet, receiving updates once earlier rings look clean

Devices are assigned automatically, but you can move specific machines into a different ring when it matters — putting your own workstations in Test, for example, or ensuring an executive’s laptop sits in Broad rather than First. Ring membership is the main lever you retain, so use it deliberately rather than accepting defaults for devices that carry real business risk.

Setting Up Windows Autopatch

  1. Verify licensing and prerequisites using the checklist above.
  2. Open the Intune admin center at intune.microsoft.com and navigate to Tenant administration > Windows Autopatch. If you are unfamiliar with the console layout, our Microsoft Intune Admin Center guide covers navigation and permissions.
  3. Run the readiness assessment. Autopatch checks your tenant settings and flags conflicts — most commonly existing update ring policies that would compete with the service.
  4. Resolve policy conflicts. Existing Windows Update for Business policies targeting the same devices will conflict. Decide which devices move to Autopatch and remove competing assignments for those groups.
  5. Add devices to the Windows Autopatch Device Registration group. Devices register and receive ring assignment automatically.
  6. Populate the Test ring deliberately with IT and pilot devices rather than leaving it empty.
  7. Monitor the first cycle closely. The first month tells you whether your device population has readiness problems — unsupported versions, devices that never check in, or hardware that fails driver updates.

Windows Autopatch reporting and update compliance monitoring

Monitoring and Reporting

Autopatch reporting lives in the Intune admin center and surfaces quality update status, feature update progress, and devices flagged as not ready or not up to date. The two reports worth checking regularly are update status by ring, and the list of devices Autopatch has classified as ineligible.

That ineligible list is where problems accumulate quietly. Devices drop out of management for mundane reasons — a machine left powered off for months, a laptop that never reconnects to the corporate network, an OS version that fell out of support. None of these generate an alert. They simply stop being patched, and they are exactly the devices an attacker finds first.

Limitations Worth Knowing

Autopatch is genuinely useful, but it is not a complete patch management solution, and it is worth being clear about the gaps:

  • It does not patch third-party applications. Autopatch covers Microsoft’s own products. Chrome, Firefox, Adobe Reader, Zoom, 7-Zip, Notepad++, and the rest of a typical software estate are outside its scope entirely.
  • You lose scheduling control. If your change management process requires updates on specific dates, Autopatch will not satisfy it.
  • It requires cloud management. Devices must be Intune-managed or co-managed; there is no on-premises-only path.
  • Ring timing is not configurable. You can move devices between rings, but not change how quickly updates progress through them.

The third-party gap is the one that catches organizations out. Autopatch keeps Windows and Microsoft apps current, which addresses a significant share of the attack surface but far from all of it. Vulnerabilities in browsers, PDF readers, and collaboration tools are among the most commonly exploited, and none of them are covered here. Closing that gap requires a separate approach — whether that is Patch My PC, another third-party patching tool, or a managed application packaging service that keeps your full application catalogue current in Intune.

Frequently Asked Questions

Is Windows Autopatch free?

There is no separate charge. Autopatch is included with Windows Enterprise E3 and E5, Microsoft 365 E3 and E5, Microsoft 365 Business Premium, and Windows Education A3 and A5. If you hold one of those licences, you already have it.

What is the difference between Windows Autopatch and Windows Update for Business?

Windows Update for Business is the underlying technology. Autopatch is a managed service built on top of it that handles ring assignment, phased rollout, and update halting on your behalf, and extends coverage to Microsoft 365 Apps, Edge, and Teams.

Does Windows Autopatch require Intune?

Yes. Devices must be managed by Microsoft Intune, or co-managed with Configuration Manager where the Windows Update workload is directed to Intune.

Can I control when updates are installed with Autopatch?

Not directly. Autopatch controls rollout timing across its deployment rings. You can move individual devices between rings, but you cannot set specific installation dates. If you need that level of control, Intune update rings are the better fit.

Does Windows Autopatch update third-party software?

No. Autopatch covers Windows, drivers and firmware, Microsoft 365 Apps, Microsoft Edge, and Microsoft Teams. Third-party applications require a separate patching solution.

What is hotpatching in Windows Autopatch?

Hotpatching applies security updates to running code without requiring a restart. From the May 2026 security update, Autopatch enables hotpatching by default on eligible devices, substantially reducing how often users must reboot to stay secure.

How long does it take for an update to reach all devices?

Autopatch targets at least 95% of eligible devices receiving a quality update within 21 days of release. Progression through the Test, First, Fast, and Broad rings is managed by the service.

Getting the Rest of Your Software Estate Current

Windows Autopatch solves Microsoft patching well, and for most organizations it is worth enabling if the licensing is already in place. The remaining question is what happens to everything else in your application catalogue — the third-party software that Autopatch does not touch and that typically represents the larger ongoing maintenance burden.

See our application update plans for how we keep third-party applications packaged, tested, and current in Intune, so your fleet is fully patched rather than partially.