We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft Intune
  2. Windows Autopatch
Windows Autopatch for US organizations

Business Premium got Autopatch in April 2025. Most organizations still do not know they have it.

Feature activation was removed and the service opened up to Business Premium and A3 or above. What you get is automated updating across Windows, the Office applications, Edge and Teams, delivered through rings that run one after another. And Hotpatch, which puts monthly security updates onto machines without asking anybody to restart.

Book an update management reviewSee what it covers
Windows Autopatch update management for US organizations
  • Business PremiumIncluded since April 2025
  • 95%Target for devices on the latest quality update
  • No restartHotpatch monthly security updates
  • Four productsWindows, M365 Apps, Edge, and Teams
The licensing change most people missed

April 2025 changed who can use this, and the announcement did not travel.

In April 2025 feature activation was removed and the capabilities became available to Business Premium and A3 or above. In a market where Business Premium is what most small and mid-size businesses actually buy, that is a very substantial widening, and remarkably few people seem to have heard about it.

  • Prior to that point this was an enterprise capability in practice. Since then, the published tables list role-based access control, update rings, groups, quality and feature updates, Hotpatch, driver and firmware handling, updates for the Office applications, Edge and Teams, and all the reporting, as included at Business Premium, A3 and above, E3 and above, and F3 alike.
  • Exactly one thing sits above that line: raising support requests with the Autopatch Service Engineering Team, restricted to E3 and above or F3. For a large enterprise that distinction carries weight. For a two hundred person company it almost never decides anything.
  • The rollout was noted as taking several weeks, with the caveat that anybody whose experience differed from the documentation might simply not have received it yet. That was well over a year ago so it is long finished, but verify against your own tenant rather than taking our word or anyone else's.
  • Which brings you to the practical point. There is a strong chance a capability you assumed needed an enterprise agreement is sitting unused inside the subscription you are already paying for every month. Confirming that takes a few minutes and it is the first thing worth doing.
Ask us to check your Autopatch entitlement
What it covers

Eight capabilities, and one of them removes the restart.

The published description is a cloud service that automates updates across Windows, Microsoft 365 Apps for enterprise, Edge and Teams, pushing them out through deployment rings in sequence and reacting to reliability and compatibility signals along the way so that fewer people have a bad morning.

Hotpatch, which installs security updates without a restart

Monthly security updates land on the machine and no restart is required to complete them. Think about what actually blocks patching in your organization. It is rarely policy and almost always that people will not reboot, or genuinely cannot mid-shift. Remove that and the whole calculation changes. This is also the capability that most reliably astonishes anybody who assumed the service was simply Windows Update with a schedule attached.

Published service level objectives, which most tools do not have

There are stated aims: ninety five percent of up to date devices carrying the latest quality update, and ninety percent of eligible devices on a supported Monthly Enterprise Channel version for the Office applications. Compare that with how patching success is normally assessed, which is that nobody has complained recently. Having an actual number published by the vendor to report against is a fundamentally different proposition.

Autopatch groups, which are more than device groups

The construct is a logical container binding several directory groups together with the software update policies that govern them, covering both ring policies and feature update policies. The consequence is that your audience and your update behavior become a single object. That single design choice is what prevents the drift everybody suffers otherwise, where the group a machine sits in and the policy that actually reaches it slowly stop corresponding.

Driver and firmware updates, including ones nothing else could reach

Take them automatically or manage the deployment yourself, direct the flow of everything toward a group or toward individual rings inside it, and govern one specific driver or firmware package across the whole tenant through an approval. There is also the ability to approve and deploy drivers and firmware that simply could not be centrally managed before, which quietly closes a gap organizations have been working around for years.

Feature updates with multi-phase release policies

Nobody worries much about a monthly quality update. It is the annual feature release that keeps people awake, because when one goes wrong it goes wrong for everybody simultaneously. Multi-phase release policies let a feature update deployment run through several phases across the groups you already have, so the rollout takes the shape of your business rather than a default cadence somebody accepted during setup and never revisited.

Microsoft 365 Apps, Edge, and Teams, all in the same service

The Office applications are held on a supported Monthly Enterprise Channel version, eligible machines are configured to benefit from progressive Edge rollouts on the Stable channel, and Teams is allowed to use its standard automatic update channel. Ask yourself how those three are handled in your organization today. The honest answer is usually separately, poorly, or not at all, and consolidating them costs nothing extra.

Reporting that identifies what to fix

Beyond the standard reports there is a dedicated Hotpatch view giving per-policy status for every machine receiving those updates, plus enhanced quality and feature update reports carrying device alerts, framed as monitoring and remediating hardware that has fallen behind. The alerts are where the value sits, because a percentage tells you how you are doing while a list of devices tells you what to actually do on Monday.

The one thing that still needs E3 or F3

One capability remains gated above the wider tier: raising support requests directly with the Autopatch Service Engineering Team, listed as E3 and above or F3 only. Every other entry in the published feature tables is available at Business Premium and A3 or above. So on Business Premium you get the service itself in full and route support through whichever channel you already use.

How we approach it

Four things that make Autopatch worth adopting properly.

Turning this on takes almost no effort at all, and that ease is precisely the problem. It gets switched on in an afternoon with no thought given to how groups should be shaped, which people belong in the first ring, or who is going to read the alerts afterwards.

We check entitlement before anybody discusses buying anything

The feature tables have included Business Premium and A3 or above since April 2025, which covers a very large share of American small and mid-size companies. So the usual outcome of our first conversation is discovering the capability is already sitting there, which converts what began as a purchasing discussion into a configuration exercise.

We design Autopatch groups around the business, not the org chart

Because a group ties directory membership to update policy, how you group people determines who meets an update first and how much cushion sits behind them. Your opening ring should be people who will spot something wrong and describe it clearly. Your final ring should be whoever genuinely cannot absorb a difficult week. Neither of those is a question your directory structure can answer.

We evaluate Hotpatch seriously rather than as a footnote

Getting monthly security updates installed without demanding a restart tackles the number one practical reason patching fails, which has always been that people simply do not reboot. Anywhere you run shifts, share machines between staff, or employ people who keep forty tabs and six documents open for a month at a time, this is the capability the entire business case should be built around.

We set up the reporting so somebody acts on it

Two published aims give you something concrete to report: ninety five percent carrying the latest quality update, ninety percent of eligible machines on a supported Office channel. Those same figures happen to answer the patch cadence question on every insurance application and SOC 2 audit you will face. Device alerts then convert the shortfall into an actual list. Give nobody ownership of that list and the service will quietly handle ninety percent of the problem while the final tenth stays broken forever.

Where this matters most

Six US situations where Autopatch solves a real problem.

Every organization on earth will tell you it patches. Very few can produce evidence when asked. Below are the six situations where the distance between the claim and the reality tends to be widest.

Shift operations where nobody reboots

Stores, hotels, hospitals, warehouses, production floors: places where one machine is used continuously across changing shifts and the restart prompt gets dismissed by every person who sees it. Delivering monthly security updates without needing that restart is aimed squarely at this population, and in these environments it is comfortably the strongest argument for adopting the service at all.

A firm asked to evidence patch currency

An auditor, an insurance carrier, a customer security questionnaire or an examiner working under the FTC Safeguards Rule or NYDFS Part 500 wants to know what share of your machines are current and how fast security updates actually reach them. The published objectives plus the update reports answer with figures. Saying that updates go out monthly answers with an assertion, and assertions are increasingly being sent back with follow-up questions attached.

A small IT team spending days on updates

One of the stated benefits is optimizing administrator capacity by automating routine endpoint updates, which is a polite way of describing something every small team recognizes. Patching is a recurring cost that produces no visible output whatsoever when it goes well, and enormous visibility when it does not. Taking it off a three person team gives you back genuine capacity rather than a line in a business case.

An organization nervous about annual feature updates

Feature releases reach everybody at once and occasionally break something the business depends on. Phased release policies let the deployment move through your groups in stages you define, which turns an annual event people brace for into a controlled sequence that has an obvious place to stop if the early phases report trouble.

An estate where drivers and firmware are simply never updated

Which describes almost every estate we have ever assessed, for the entirely reasonable reason that no good central mechanism existed. Now you can take them automatically or manage them yourself, direct the flow toward particular groups or rings, approve an individual driver across the whole tenant, and reach packages that were simply beyond central management before.

A business where Microsoft 365 Apps versions are all over the place

Colleagues sitting on wildly different builds, a few of them years adrift, generating intermittent faults nobody has ever managed to reproduce on demand. Holding ninety percent of eligible machines on a supported channel version quietly eliminates an entire category of tickets that your service desk never diagnosed as version problems in the first place.

Three positions

How Windows updates are actually managed in US organizations.

Among organizations already running Intune, the middle column dominates: rings that somebody configured during implementation and nobody has opened since. And in nearly every case they cover Windows and nothing else.
Windows quality updates managed
Autopatch in useYes
Update rings, unmanagedYes
Windows Update defaultsPartly
Security updates without a restart
Autopatch in useYes, via Hotpatch
Update rings, unmanagedNo
Windows Update defaultsNo
Feature updates phased deliberately
Autopatch in useYes
Update rings, unmanagedSometimes
Windows Update defaultsNo
Drivers and firmware managed centrally
Autopatch in useYes
Update rings, unmanagedRarely
Windows Update defaultsNo
Microsoft 365 Apps kept current
Autopatch in useYes
Update rings, unmanagedNo
Windows Update defaultsInconsistently
Edge and Teams updates managed
Autopatch in useYes
Update rings, unmanagedNo
Windows Update defaultsInconsistently
A stated target to report against
Autopatch in useYes
Update rings, unmanagedNo
Windows Update defaultsNo
Alerts identifying devices to fix
Autopatch in useYes
Update rings, unmanagedPartly
Windows Update defaultsNo
Rollout responds to reliability signals
Autopatch in useYes
Update rings, unmanagedNo
Windows Update defaultsNo
Frequency in the US mid-market
Autopatch in useUncommon
Update rings, unmanagedCommon
Windows Update defaultsCommon in small businesses
Feature
Autopatch in use
Update rings, unmanaged
Windows Update defaults
Windows quality updates managed
YesYesPartly
Security updates without a restart
Yes, via HotpatchNoNo
Feature updates phased deliberately
YesSometimesNo
Drivers and firmware managed centrally
YesRarelyNo
Microsoft 365 Apps kept current
YesNoInconsistently
Edge and Teams updates managed
YesNoInconsistently
A stated target to report against
YesNoNo
Alerts identifying devices to fix
YesPartlyNo
Rollout responds to reliability signals
YesNoNo
Frequency in the US mid-market
UncommonCommonCommon in small businesses
What gets updated

Four products, and what Autopatch does with each.

Taken from the published feature descriptions. Note that the percentage targets are the vendor own stated aims rather than anything we invented, which is unusual in this space and genuinely useful the moment you need a figure to report against.

Product

Windows quality updates

What Autopatch does
Aims to keep at least 95 percent of up to date devices on the latest quality update

Product

Hotpatch updates

What Autopatch does
Installs monthly B release security updates without requiring a device restart

Product

Windows feature updates

What Autopatch does
Controlled annual rollout, with multi-phase release policies across Autopatch groups

Product

Drivers and firmware

What Autopatch does
Automatic or self-managed, with tenant-wide approvals for specific drivers

Product

Microsoft 365 Apps

What Autopatch does
Aims to keep at least 90 percent of eligible devices on a supported Monthly Enterprise Channel version

Product

Microsoft Edge

What Autopatch does
Configures eligible devices for progressive rollouts on the Stable channel

Product

Microsoft Teams

What Autopatch does
Allows eligible devices to use the standard automatic update channel

Product

Reporting

What Autopatch does
Intune reports, Hotpatch quality update report, and device alerts for devices not up to date
ProductWhat Autopatch does
Windows quality updatesAims to keep at least 95 percent of up to date devices on the latest quality update
Hotpatch updatesInstalls monthly B release security updates without requiring a device restart
Windows feature updatesControlled annual rollout, with multi-phase release policies across Autopatch groups
Drivers and firmwareAutomatic or self-managed, with tenant-wide approvals for specific drivers
Microsoft 365 AppsAims to keep at least 90 percent of eligible devices on a supported Monthly Enterprise Channel version
Microsoft EdgeConfigures eligible devices for progressive rollouts on the Stable channel
Microsoft TeamsAllows eligible devices to use the standard automatic update channel
ReportingIntune reports, Hotpatch quality update report, and device alerts for devices not up to date
How an adoption runs

Five steps, and it is quicker than most Intune work.

Two to four weeks gets most organizations to a working state. Switching it on takes an afternoon. What earns the remaining time is shaping the groups and rings sensibly, and settling who is going to own the exceptions once the service is handling everything else.
  1. 1

    Confirm entitlement and readiness

    Three checks. What licensing you actually hold, bearing in mind Business Premium and A3 or above have qualified since April 2025. Whether your machines are already under Intune management. And whether direct support requests to the Service Engineering Team matter to you, since that is the one thing sitting above the wider tier.

  2. 2

    Design the Autopatch groups

    Directory groups get bound to the update policies that ought to govern them, so audience and behavior become a single thing to maintain. Populate the opening ring with people who will notice something wrong and describe it usefully. Populate the closing ring with whoever can least afford a difficult week.

  3. 3

    Decide the update behavior per product

    We work through quality updates and whether restart-free installation suits your estate, how the annual feature release should be phased, whether drivers and firmware come automatically or under your own control, and finally confirming the Office applications, Edge and Teams are all in scope. In our experience they should be, and in most tenants they are not.

  4. 4

    Register devices and watch the first cycle

    Registration happens in the Intune admin center, and then you wait and watch one complete monthly cycle before widening anything. Your early rings are where compatibility problems specific to your own application estate reveal themselves, which is the entire reason sequential rings exist rather than a formality to hurry through.

  5. 5

    Set up reporting and assign the exceptions

    The quality and feature reports go in, along with the dedicated Hotpatch view and the device alerts flagging machines that have fallen behind. Then, crucially, a named individual takes ownership of working that list. The service will handle the overwhelming majority without help. The remainder needs a person who actually cares whether it gets fixed.

Straight answers

What organizations ask about Windows Autopatch.

Not since April 2025, and this single fact is the one almost everybody has missed. Feature activation was removed at that point and the capabilities opened up to Business Premium and A3 or above. Check the published tables and you will find rings, groups, quality and feature updates, restart-free installation, driver and firmware handling, the Office applications, Edge, Teams and all the reporting listed as included at that level.

Precisely one entry: raising support requests with the Service Engineering Team, restricted to E3 and above or F3. Absolutely everything else in the feature list is yours at Business Premium and A3 or above. We have yet to meet a mid-size organization for whom that single distinction was the thing that settled their licensing decision.

It installs the monthly B release security updates and the machine does not need restarting for them to take effect. Consider why that matters so much. Patching rarely fails because updates were not deployed; it fails because nobody rebooted. Anywhere you run shifts or share machines between staff, this one capability is frequently the whole justification for adopting the service.

There is, and vendors rarely publish anything this specific. The stated aims are ninety five percent of up to date machines carrying the latest quality update and ninety percent of eligible machines on a supported Monthly Enterprise Channel version. Having a number the vendor itself committed to gives you something concrete to put in front of a board, an auditor, an insurance carrier or a customer running a supplier review.

A logical container holding several directory groups alongside the software update policies governing them, meaning ring policies and feature update policies. Why it matters: your audience and your update behavior stop being two things that can quietly diverge and become one managed object. That removes the drift every estate otherwise suffers between which group a machine belongs to and which policy actually reaches it.

It can, and of everything on this page this is the capability people are most often unaware of. Receive them automatically or manage deployment yourself, direct the flow of all drivers toward a group or toward specific rings inside it, govern an individual driver or firmware package across the entire tenant through approvals, and deploy packages that previously had no central management path at all.

Through phased release policies, which allow a feature update deployment to run in several customizable phases across the groups you have already built. The effect is to convert the annual release from an event the whole IT team braces for into a sequence where the early phases surface problems while the exposure is small, and where there is an obvious point at which you stop and reconsider.

It does, and this tends to be the most undersold part of the whole proposition. Four products are automated: Windows itself, the Office applications, Edge and Teams. Ask how the last three are handled where you work. Separately, inconsistently, or not at all is the usual answer, and the version drift that produces generates a steady trickle of tickets nobody ever traces back to the actual cause.

Possibly, and the whole service is built around managing that risk: updates go out through sequential rings and the rollout reacts to reliability and compatibility signals as it proceeds. None of which eliminates the possibility entirely. Which is exactly why the composition of your first ring matters so much. You want people who will report a problem clearly, not people who will silently work around it for three weeks.

You do, and we would rather be blunt about it than let anybody adopt this under a misapprehension. The routine work goes away; the accountability does not. Device alerts and reports exist precisely because some machines will always be behind, usually because they are rarely online or have a specific fault. Somebody has to work that list. It is a far smaller job than the one being replaced, but it is not nobody job.

The names are unhelpfully similar and they do entirely separate jobs. One provisions a new machine, carrying it from a sealed box to a configured and enrolled state with nobody imaging anything. The other keeps that same machine current for the rest of its working life. Most organizations end up wanting both, and each is configured on its own terms.

They carry over. Rings for Windows 10 and later can be managed through the service, and ring policies are among the update policies a group binds together. So whatever you have already designed is a starting point rather than something to throw away. That said, a migration is a perfectly good excuse to ask whether those rings still describe how your business works, because they were probably drawn up years ago.

Two channels. The reporting side gives you enhanced quality and feature update reports carrying device alerts, so you can monitor and remediate machines that have fallen behind, plus a dedicated per-policy view for anything receiving restart-free updates. Separately, service communications covering planned maintenance and current status land in the Message center, which is worth making sure somebody actually reads.

Most organizations reach a working state in two to four weeks. Enabling the service and registering machines takes almost no time at all. The time goes on designing groups so the rings genuinely reflect how the business operates, settling the driver and firmware approach, and then waiting through one full monthly cycle in the early rings before widening. Skip that last part and a perfectly good service takes the blame for a bad week that was entirely avoidable.

Quoted per engagement, and honestly this ranks among our smaller pieces of work because the service itself does the heavy lifting. The first conversation costs you nothing and establishes whether your existing licensing already covers this, which since April 2025 it very frequently does. That answer on its own tends to change the entire shape of what follows.
Before adopting

Fifteen questions worth answering first.

Group one settles what you are entitled to and whether you are ready. Group two decides how updates should move through the organization. Group three deals with the operational reality, which is that this service takes the work off your team without taking the accountability with it.

Entitlement and readiness

  • Which licenses do you actually hold?
    Business Premium and A3 and above are included since April 2025.
  • Are devices already managed by Intune?
    Registration happens through the Intune admin center.
  • Do you need Service Engineering Team support?
    That is the E3 and above or F3 difference.
  • Are you currently using update rings already?
    They can be managed within Autopatch.
  • Who monitors the Message center?
    Service communications arrive there.

How updates should flow

  • What Autopatch groups reflect your business?
    They group Entra groups with update policies.
  • Who should be in the earliest ring?
    People who will report a problem clearly.
  • How should annual feature updates be phased?
    Multi-phase release policies exist for this.
  • Automatic or self-managed drivers and firmware?
    Both are supported, per group or tenant-wide.
  • Is Hotpatch appropriate for your estate?
    It removes the restart from monthly security updates.

Operations

  • Who reviews device alerts?
    They identify devices that are not up to date.
  • What is your target, and do you report it?
    Microsoft publishes 95 percent and 90 percent aims.
  • How are Microsoft 365 Apps updated today?
    Usually inconsistently, or not at all.
  • Do you have devices that are rarely online?
    They will be the persistent exceptions.
  • Does anybody currently own patching?
    Autopatch removes the work, not the accountability.
Related reading

The pages around this one.

Windows Autopilot

The provisioning half of the same story: getting a device from the box to configured without anybody imaging it.

Learn more

Microsoft Intune

The platform Autopatch is administered from, covering enrollment, configuration, and application deployment.

Learn more

Defender Vulnerability Management

The other side of patching: knowing what is exposed, prioritized by what is actually being exploited.

Learn more
Next step

Check whether Autopatch is already in your subscription.

Since April 2025 it has been included with Business Premium and A3 or above, and a large share of US small and mid-size organizations are on exactly those licenses and have never enabled it. The check takes minutes and it frequently ends the procurement conversation before it starts.

Book an update management reviewSee what it covers

Related Services

Explore more solutions that work great with this service

Microsoft Intune

Device management and endpoint security

Learn more

Managed IT Services

Complete outsourced IT department

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA