Event banner
AMA: Windows update and driver management
Event details
Get the tips and insights you need to manage Windows updates and drivers with ease. This session is designed to answer your questions about unified update management in Microsoft Intune, Windows Autopatch, hotpatch updates, and more. Need help understanding which policies to set—and which to avoid? Curious about moving from Windows 11, version 24H2 to version 25H2 later this year via an enablement package? Looking for more automation and less end user disruption? Come Ask Microsoft Anything (AMA)!
On the panel: Surabhi Calla, Vishal Bajaj, Ken Goossens, and Ranjith Reddy
This event is part of the Tech Community Live: Windows edition.
44 Comments
- Pearl-Angeles
Community Manager
Thanks all for your participation in this AMA! Here are the questions our panelists answered during the session and associated timestamps:
Question – How do we patch devices that are on all day everyday but can only be patched and restarted during the weekends? And if it misses the update&restart during that weekend, to try again the next weekend. Basically, not patch and restart during weekdays at all. Is that even possible with WUfB/Autopatch? - answered at 1:48.
Question - What are your favorite feature areas within Autopatch? - answered at 3:08.
Question – What types of controls do we maintain with Autopatch? - answered at 6:45.
Question – In Intune how can we pause a single Windows Update? At the moment it seems we can only pause ALL updates or NONE? - answered at 9:58.
Question – Will autopatch ever allow user scoping/assignment as opposed to devices? For some of our rings, especially the first groups.. there are hundreds of app owners associated to catch any issues. For now, we are just using the old wufb way of deploying and configuring update rings and assign to user groups based on roles.- answered at 11:58.
Question – What’s new with hotpatching? - answered at 12:51.
Question – Are there any additional cost for Hotpatch updates or is it included if they have Intune licenses? - answered at 14:18.
Question - Can you share more details about Autopatch licenses? - answered at 15:56.
Question - Is there a possibility to automatically enroll the new device in an update ring if you change the device for a user? - answered at 16:36.
Question – Any chance that hotpatch will support ARM64 with CHPE still enabled to avoid perf and app compat issues that may be introduced as a result of disabling CHPE? - answered at 17:59.
Question – Can we please move the installation of drivers in windows to a pre or post user phase (during boot up, or shutdown) to avoid issues driver installs cause while the user is in session such as audio and video interruptions - answered at 19:18.
Feedback – Currently, it's difficult to identify and differentiate between Out-of-Band (OOB) updates when using the Expedite installation of quality updates feature in Intune. To improve clarity and avoid confusion, is it possible to display the corresponding Knowledge Base (KB) numbers alongside each update in the dropdown menu? – answered at 20:33.- To share feedback, please go to aka.ms/IntuneFeedback
Question – What is the best case scenario and how should the setup be done for driver management? Best practices to share? Key issues you noticed with customers? – answered at 22:29.
Question – One of our customers has read about checkpoint cumulative updates – can someone please explain what a checkpoint cumulative update does? - answered at 27:58. - Paul_WoodwardIron Contributor
We'd like the drivers to be there after Autopilot pre-provisioning. I don't want a bunch of drivers landing after the user has signed in for the first time. Is this available, or on the roadmap?
- EricMoe
Microsoft
Thank you for this feedback Paul. The team is looking at ways to improve the driver experience during Autopilot but we have nothing to share at this time.
- Heather_Poulsen
Community Manager
Thank you for joining us! Q&A will be open through 12:00 Pacific Time this Friday. Keep your questions coming and we'll keep working to get you the answers you need to manage Windows updates and drivers with greater ease.
- TechOnDemandCopper Contributor
Can you please describe the hotpatch feature and how it differentiates from legacy autopatch workflow?
- EricMoe
Microsoft
Check out this FAQ article Hotpatch for client: Frequently asked questions - Windows IT Pro Blog that should cover everything you need to know about Hotpatch. In short, Hotpatch is a Windows 11 24H2 feature that allows for an update to be applied to the device without requiring a device reboot. Check out the FAQ for more details!
- Paul_WoodwardIron Contributor
Is it possible to make sure drivers land during the Windows Update reboot phase? When display adapter drivers land it can cause the screen to go blank, and network adapters can result in interruption to service.
- Paul_WoodwardIron Contributor
This looks to users like a fault, when it's just routine maintenance. The user needs some heads up that driver updates are happening, or they should not land during a user session. Thanks!
- Katie_Yao
Microsoft
We recommend setting up Autopatch Groups and utilize the release schedule preset for installation, reboot, and notification behavior settings. For example, the "Reboot-sensitive devices" option only allows devices to update at a scheduled time. Manage Windows Autopatch groups | Microsoft Learn
- HeyHey16KIron Contributor
If there is a mix of 23H2/24H2 devices in the same newly created Windows Update Ring, will it cause any issues? i.e. is hotpatching clever enough to only target the 24H2 computers in the Ring?
- EricMoe
Microsoft
Yes, it's clever enough to only target 24H2 with hotpatch updates. The device will query for available updates, and 24H2 that meet the pre-reqs for hotpatch should scan and see the available hotpatch and apply it. 23H2 devices will see the 23H2 update that is applicable for the month. And 24H2 devices that don't meet the pre-reqs would get offered the non-hotpatch update for the month.
- mdooseCopper Contributor
Any chance that hotpatch will support ARM64 with CHPE still enabled to avoid perf and app compat issues that may be introduced as a result of disabling CHPE?
- Pearl-Angeles
Community Manager
Thanks for your question! In additional to Vishals response here, the panelists covered this topic at 17:59 during the live session.
- VishalBajaj
Microsoft
CHPE needs to be disabled for hotpatching of ARM devices. Currently we are not exploring options with CHPE enabled. Please check app compatibility with CHPE disabled on your specific devices to avoid disruption. Besides CHPE, Virtualization Based Security (VBS) needs to be running. If CHPE is enabled and the device is enrolled in hotpatching, then the device will not be offered hotpatches.
- YesaitRavantyCopper Contributor
To add to the question on installing on a scheduled day, from a real-world scenario, we have implemented Autopatch groups and specified scheduled install days (Wednesday, Thursdays, etc..) but what we are seeing is that machines miss the install day and/or they do get it installed but never reboot. How can we find out why the machine is not rebooting? Of course, deadline/grace-period is the best option, but then this forces the install during active hours which might not be ideal so curious if there are any other options? I did create a new App in Intune which creates a Scheduled Tasks that looks for specific registry keys in the middle of the night and forces a reboot, but this did NOT work for Feature Updates as it reboots and never installs unless it is manually rebooted.
Appreciate it in advance! - ChristianSSchneiderCopper Contributor
Is there a possibility to get automatically the new device in an update ring if you change the device for a user?
- Surabhi_Calla
Microsoft
If your Autopatch groups are configured using dynamic Microsoft Entra ID (formerly Azure AD) device groups, then:
- New devices assigned to a user will be automatically discovered by Windows Autopatch.
- The service runs a device discovery process hourly to detect new devices added to the Entra group. Once discovered, the device undergoes eligibility checks (e.g., Intune enrollment, OS version, connectivity).
- If eligible, the device is automatically registered and assigned to the appropriate deployment ring within the Autopatch group.
- Use dynamic device-based Entra ID groups for Autopatch group membership.
- Ensure your dynamic membership rules are based on device attributes (e.g., device name, OS version, ownership).
- ArshadJ685Copper Contributor
Can someone please explain what does the Checkpoint cumulative update do? https://learn.microsoft.com/en-us/windows/deployment/update/catalog-checkpoint-cumulative-updates
We are seeing brand new devices failing Windows Updates right out of the box once at the desktop.- EricMoe
Microsoft
"With Windows 11, version 24H2, we’re introducing a new concept of checkpoint cumulative updates. This will allow you to get features and security enhancements via the latest cumulative update through smaller, incremental differentials containing only the changes since the previous checkpoint cumulative update. This means that you can save time, bandwidth, and hard drive space." Introducing Windows 11 checkpoint cumulative updates | Windows IT Pro Blog Checkpoint cumulative updates are a bandwidth-saving feature. If you are seeing devices failing Windows Updates right out of the box, you will need to investigate the errors deeper, I'm unsure what relation that would have with Checkpoint cumulative updates.