Microsoft will enable hotpatch security updates by default for eligible Windows devices managed via Microsoft Intune or the Microsoft Graph API, starting with the May 2026 Windows security update and delivered through Windows Autopatch. Hotpatch applies security fixes without requiring an immediate reboot, reducing the typical multi-day restart grace period that can leave endpoints exposed; Microsoft says this change can cut the time to reach 90% patch compliance roughly in half. Devices must meet prerequisites and have the April 2026 baseline installed; if a device is not on the baseline, Autopatch will first install it (requiring a restart) before subsequent hotpatches can apply without reboots.
Microsoft indicated additional administrative controls are coming, including a tenant-level opt-out in Intune expected to be available April 1, 2026, and admins can also scope hotpatch behavior to specific devices/groups. The default behavior is described as applying to devices not already governed by an existing quality update policy, while current configurations (e.g., update rings, deferrals, and any previously set hotpatch preferences) remain in effect. Administrators can validate readiness using Intune reporting (e.g., hotpatch/quality update reporting) and adjust the Autopatch tenant setting that controls “apply updates without restarting” behavior as needed.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Because April 2026 is a baseline month, Microsoft said hotpatch deployments would not begin until May 11, 2026, giving administrators time to review readiness and change settings. Organizations can use Intune reporting to verify which devices are eligible and hotpatch-ready before rollout begins.
Starting with the May 2026 Windows security update, Windows Autopatch will automatically deliver hotpatch security updates to eligible unmanaged-by-policy devices by default. Microsoft said this applies to supported systems such as Windows 11 version 24H2 or later and is delivered through Autopatch deployment rings.
Microsoft said devices must install the April 2026 baseline security update and meet all hotpatch prerequisites before they can receive hotpatch updates. Devices that do not qualify will continue receiving standard cumulative updates that require restarts.
Microsoft said tenant-wide controls to opt out of the new default hotpatch behavior will become available on April 1, 2026, with group-level control available through quality update policies. Existing update configurations and policy-level settings will continue to override the tenant default.
Microsoft said eligible devices managed through Microsoft Intune or the Windows updates API in Microsoft Graph will have hotpatch security updates enabled by default starting with the May 2026 Windows security update. The company said the change is intended to reduce restart-related patch delays and improve time to patch compliance.
Microsoft published documentation describing hotpatch updates for Windows Autopatch, including prerequisites such as Windows 11 24H2 or later, Intune quality update policies, Virtualization-based Security, and the latest quarterly baseline release. The documentation also outlined the quarterly cadence of baseline months requiring restarts and hotpatch months that install without restarts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
infosec.pub
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcehelpnetsecurity.com
Open sourcetechcommunity.microsoft.com
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.