Event banner
AMA: Hotpatching Windows - client and server
Event details
Interested in learning how to deploy updates faster, with less restarts? Bring your questions to this Ask Microsoft Anything session. Get tips on how to enable hotpatch updates for client devices and servers. Find the confidence you need to enable day-one protection. We’re here to help you integrate hotpatching as part of your overall update management strategy. This session is part of Tech Community Live: Windows edition.
On the panel: Nevine Geissa, David Callaghan, Vishal Bajaj, Surabhi Calla
41 Comments
- KaranS340Brass Contributor
Hi there,
One question: is this a completely different product, or is it part of Windows Autopatch, which is a feature in Intune? If it's a different product as a whole, then how does it compete with Windows Autopatch (like pro's and con's)?
Thanks.- Per-Larsen
Microsoft
You can enable it both in Microsoft and Autopatch - for more information take a look at this blogpost.
Autopatch and hotpatch goes better hand in hands.
Hotpatch for client comes to Windows 11 - Windows IT Pro Blog- Pearl-Angeles
Community Manager
What about the pricing for hotpatching outside of Azure environments?
- VishalBajaj
Microsoft
For client there is no additional cost. For Azure Arc connected Windows Server 2025 machines that opt into Hotpatching we are yet to finalize. An announcement will be made once that is finalized.
When will hotpatches be available in WSUS Catalog?
- Heather_Poulsen
Community Manager
The panel would love to know more about how this would help you. What use cases do you need to support?
We have servers onprem which are managed by configuration manager update management. Management by Azure Update Manager is no option for the next years.
- Sreekanth_ReddyCopper Contributor
1. Today is the first patch Tuesday after Hot patch available, as per the documentation - it says Baseline Patch available only first month of every quarter. Does this mean we should wait for January month to come to test Hot patch functionality?
2. For Hot patch policy to apply, does the targeted Windows 11 24H2 group should be excluded from regular WUfB update rings? My assumption is PC should not be excluded from WUfB update rings to apply Hot Patch policy - If Yes, today we have received "Pending Reboot" for Dec'2024 security patch from regular WUfB update rings - Can you please explain a little bit?- David_Guyer
Microsoft
- You are correct that a device first needs to be on the baseline before a hotpatch will be applicable, but since the system will still deploy the full update when not applicable to a device, you can configure the policy now. As you point out, you'll probably really see these start to apply hotpatches in February.
2. You don't need to exclude from Update Rings to take advantage of hotpatching. They will work together. Your pending reboot is likely since the device is not yet applicable for the hotpatch (from #1 above) so received the full update.
-HTH,
David
- Pearl-Angeles
Community Manager
Sreekanth_Reddy - thanks for participating in AMA: Hotpatching Windows - client and server. Along with the response above, the panelists covered your first question around 2:38 and your second question around 17:10.
- You are correct that a device first needs to be on the baseline before a hotpatch will be applicable, but since the system will still deploy the full update when not applicable to a device, you can configure the policy now. As you point out, you'll probably really see these start to apply hotpatches in February.
- GrantVennerCopper Contributor
Will .NET Framework cumulative updates also be hotpatch-enabled? If not, it's likely that clients will still require a monthly reboot for these specific update types.
- David_Guyer
Microsoft
Grant, we can appreciate how it would be great to hotpatch other updates, but I don't know of any plans to do so yet, especially since we are in the early life of hotpatching for Windows. Even with a .NET Framework reboot, you are still getting the benefit of having the Windows OS security updates in place faster since you don't have to wait for the reboot, which is a big win.
HTH,-David
- Pearl-Angeles
Community Manager
GrantVenner thanks for participating in AMA: Hotpatching Windows - client and server. Along with David's response, the panelists covered this topic at 13:07.
- satishDavaCopper Contributor
What are the pre-requisites, is the Intune Auto Patch must be enabled for this or just update ring policies should be fine
- David_Guyer
Microsoft
We are in the process of reducing the features that require Autopatch registration and making most of the features available to everyone with the necessary licensing without enabling/registering for Autopatch. For the latest documentation, go here: https://learn.microsoft.com/en-us/windows/deployment/windows-autopatch/prepare/windows-autopatch-prerequisites?tabs=business-premium-a3-entitlements%2Cbusiness-premium-a3-intune-permissions
For example, creating new Feature update, driver, or expedited quality policies does not require Autopatch registration and enablement.
HTH,-David
- satarzaiOccasional Reader
Is Hotpatching available for GCC?
- Pearl-Angeles
Community Manager
Thanks for participating in the AMA: Hotpatching Windows - client and server. For reference, the panel covered this topic around 4:30.