msnugget
Hotpatch Is Now On by Default in Windows Autopatch
8 By Jannik Reinhard & Florian Salzmann · Published · Updated

Hotpatch Is Now On by Default in Windows Autopatch

Starting with the May 2026 security update, Microsoft is enabling hotpatch by default for all eligible devices managed through Windows Autopatch or the Graph API. If you have not explicitly configured a quality update policy with a hotpatch setting, eligible devices will start receiving security fixes without requiring a restart. This is not opt-in anymore.

Why this matters

The compliance speed argument is real. Microsoft reports organisations reaching 90% patch compliance in roughly half the time compared to traditional restarts. For large fleets, that difference is operationally significant, and the restart disruption reduction is a legitimate quality-of-life improvement for end users.

The control model is worth understanding. The tenant-level default only applies to devices not already assigned to a quality update policy. If a device is in a policy, that policy’s hotpatch setting takes precedence. So if you already manage patching through scoped quality update policies, most of your fleet is probably already covered.

When/Where you can use it

Good fit for corporate-owned devices on Windows 11 24H2 or later with VBS enabled, especially where restart scheduling is painful or compliance SLAs are tight. Shared devices, kiosk machines, and high-availability endpoints benefit the most from the no-restart model.

Possible Issues and Behaviour to Know

Hotpatch does not replace the full servicing model. Baseline months (January, April, July, October) still require a restart, and certain platform components only move forward with those baselines. Specifically, Secure Boot certificate updates are delivered with baseline updates, not hotpatch months, which matters given that certificates start expiring from June 2026 onwards.

There is also a confirmed recovery issue. The February and March 2026 hotpatch updates broke Push Button Reset on Windows 11 Enterprise LTSC 2024 (24H2 and 25H2), causing “Reset this PC” to fail silently with a black screen and reboot to desktop. The workaround is deploying KB5079471, the March Safe OS Dynamic Update, which only needs to be applied once. The April 2026 cumulative update also resolves this for devices that take the full baseline.

Example Scenario

You have 3,000 devices with no explicit quality update policy assigned. Come May patch Tuesday, all eligible devices start receiving hotpatch silently. Compliance dashboard looks great. But a few LTSC devices still show the February hotpatch in their history and your support team hits a reset failure on a compromised machine. The fix exists, but you need to know to look for it.

Recommendation

Review your quality update policies now and make sure every device group that should behave differently from the new default is explicitly assigned to a policy. Deploy KB5079471 proactively to LTSC 2024 endpoints if you have not already. Do not assume the no-restart story covers everything. Hotpatch is a solid servicing improvement, but the baseline update cadence and platform consistency still require your attention.

References

🔗 Hotpatch Updates, Secure Boot, and the Reset This PC Problem 🔗 Securing devices faster with hotpatch updates on by default – Windows IT Pro Blog

Hotpatch speeds up compliance, but it does not move the entire platform forward at once. Know what it covers and what it does not before it becomes your default.