How to Setup Windows Autopatch and Enable Hot Patch via Intune: A Step-by-Step Guide
Setting Up Windows Autopatch in Intune
Windows Autopatch is a cloud service that automates the process of updating Windows, Microsoft 365 Apps for Enterprise, Microsoft Edge, and Microsoft Teams. Here's a step-by-step guide to set it up:
Prerequisites
Licensing: Ensure you have Windows 10/11 Enterprise E3 or E5 licenses.
Device Requirements: Devices must be Hybrid Azure AD joined or Azure AD joined.
Permissions: You need Global Administrator and Intune Administrator roles.
Steps to Set Up Windows Autopatch
Sign in to the Intune Admin Center: Go to the Microsoft Intune admin center and sign in with your admin credentials.
Enroll Your Tenant:
Navigate to Tenant Administration > Windows Autopatch.
Click on Enroll and follow the prompts to complete the enrollment process.
Run Readiness Assessment:
Use the readiness assessment tool to check for any issues that need to be resolved before enrolling devices.
Add Devices to Autopatch:
Go to Devices > Windows Autopatch > Device Registration.
Add devices to the Autopatch Device Registration group.
Assign Devices to Update Rings:
Navigate to Devices > Windows Autopatch > Update Rings.
Assign devices to the appropriate update rings based on your organization's needs.
Enabling Hotpatch via Intune
Hotpatch is a feature that allows Windows updates to be applied without requiring a system reboot, minimizing disruptions. Here's how to enable it:
Prerequisites
Operating System: Windows 11 Enterprise, version 24H2 or later.
Virtualization-Based Security (VBS): Must be enabled on the device.
Licensing: Available with Microsoft 365 A3+, E3+, and F3 licenses.
Steps to Enable Hotpatch
Sign in to the Intune Admin Center: Go to the Microsoft Intune admin center and sign in with your admin credentials.
Navigate to Windows Updates:
Select Devices > Windows updates > Quality updates.
Create a Quality Update Policy:
Click on Create and select Windows quality update policy (preview).
Enter a name for the policy and configure the settings.
Enable Hotpatch:
In the policy settings, enable the AllowRebootlessUpdates option to activate hotpatching.
Assign the Policy:
Assign the policy to the target groups (users or devices) within your organization.






Comments