Hey Artur, Thanks for reaching out!
To answer your first question directly, the scope of the change is all eligible devices in Intune or through Graph API. What eligible means is that the device has the right licenses and meets the Hotpatching pre-requisites. (e.g. Win 11 24H2+ and VBS enabled for x86 devices)
To your second question around Admin choice, we're fully committed to leaving admins in the driver's seat. That's why we're communicating the change early and are adding the option to opt out. To be super explicit about the change timeline:
- March 9th: We're letting you know that changes are coming
- April 1st: The option to opt out at the tenant level will go live in the Intune portal
- Note: The Hotpatch settings you configure in Quality Update Policies will overwrite the tenant level setting for devices assigned to those policies.
- May Security Update: First default on hotpatch security update
This timeline provides six weeks to act before any change occurs, ample time to hit the toggle if you want to stick with traditional patching. As discussed above, the rationale is that devices get secure significantly faster while deploying the exact same set of security fixes. Given that the technology has been proven on millions of devices over the last year without issue, enabling Hotpatch by default is the best thing to do from both a security and user experience perspective.