Business Premium got Autopatch in April 2025. Most organizations still do not know they have it.
Feature activation was removed and the service opened up to Business Premium and A3 or above. What you get is automated updating across Windows, the Office applications, Edge and Teams, delivered through rings that run one after another. And Hotpatch, which puts monthly security updates onto machines without asking anybody to restart.

- Business PremiumIncluded since April 2025
- 95%Target for devices on the latest quality update
- No restartHotpatch monthly security updates
- Four productsWindows, M365 Apps, Edge, and Teams
April 2025 changed who can use this, and the announcement did not travel.
In April 2025 feature activation was removed and the capabilities became available to Business Premium and A3 or above. In a market where Business Premium is what most small and mid-size businesses actually buy, that is a very substantial widening, and remarkably few people seem to have heard about it.
- Prior to that point this was an enterprise capability in practice. Since then, the published tables list role-based access control, update rings, groups, quality and feature updates, Hotpatch, driver and firmware handling, updates for the Office applications, Edge and Teams, and all the reporting, as included at Business Premium, A3 and above, E3 and above, and F3 alike.
- Exactly one thing sits above that line: raising support requests with the Autopatch Service Engineering Team, restricted to E3 and above or F3. For a large enterprise that distinction carries weight. For a two hundred person company it almost never decides anything.
- The rollout was noted as taking several weeks, with the caveat that anybody whose experience differed from the documentation might simply not have received it yet. That was well over a year ago so it is long finished, but verify against your own tenant rather than taking our word or anyone else's.
- Which brings you to the practical point. There is a strong chance a capability you assumed needed an enterprise agreement is sitting unused inside the subscription you are already paying for every month. Confirming that takes a few minutes and it is the first thing worth doing.
Eight capabilities, and one of them removes the restart.
Hotpatch, which installs security updates without a restart
Monthly security updates land on the machine and no restart is required to complete them. Think about what actually blocks patching in your organization. It is rarely policy and almost always that people will not reboot, or genuinely cannot mid-shift. Remove that and the whole calculation changes. This is also the capability that most reliably astonishes anybody who assumed the service was simply Windows Update with a schedule attached.
Published service level objectives, which most tools do not have
There are stated aims: ninety five percent of up to date devices carrying the latest quality update, and ninety percent of eligible devices on a supported Monthly Enterprise Channel version for the Office applications. Compare that with how patching success is normally assessed, which is that nobody has complained recently. Having an actual number published by the vendor to report against is a fundamentally different proposition.
Autopatch groups, which are more than device groups
The construct is a logical container binding several directory groups together with the software update policies that govern them, covering both ring policies and feature update policies. The consequence is that your audience and your update behavior become a single object. That single design choice is what prevents the drift everybody suffers otherwise, where the group a machine sits in and the policy that actually reaches it slowly stop corresponding.
Driver and firmware updates, including ones nothing else could reach
Take them automatically or manage the deployment yourself, direct the flow of everything toward a group or toward individual rings inside it, and govern one specific driver or firmware package across the whole tenant through an approval. There is also the ability to approve and deploy drivers and firmware that simply could not be centrally managed before, which quietly closes a gap organizations have been working around for years.
Feature updates with multi-phase release policies
Nobody worries much about a monthly quality update. It is the annual feature release that keeps people awake, because when one goes wrong it goes wrong for everybody simultaneously. Multi-phase release policies let a feature update deployment run through several phases across the groups you already have, so the rollout takes the shape of your business rather than a default cadence somebody accepted during setup and never revisited.
Microsoft 365 Apps, Edge, and Teams, all in the same service
The Office applications are held on a supported Monthly Enterprise Channel version, eligible machines are configured to benefit from progressive Edge rollouts on the Stable channel, and Teams is allowed to use its standard automatic update channel. Ask yourself how those three are handled in your organization today. The honest answer is usually separately, poorly, or not at all, and consolidating them costs nothing extra.
Reporting that identifies what to fix
Beyond the standard reports there is a dedicated Hotpatch view giving per-policy status for every machine receiving those updates, plus enhanced quality and feature update reports carrying device alerts, framed as monitoring and remediating hardware that has fallen behind. The alerts are where the value sits, because a percentage tells you how you are doing while a list of devices tells you what to actually do on Monday.
The one thing that still needs E3 or F3
One capability remains gated above the wider tier: raising support requests directly with the Autopatch Service Engineering Team, listed as E3 and above or F3 only. Every other entry in the published feature tables is available at Business Premium and A3 or above. So on Business Premium you get the service itself in full and route support through whichever channel you already use.
Four things that make Autopatch worth adopting properly.
We check entitlement before anybody discusses buying anything
The feature tables have included Business Premium and A3 or above since April 2025, which covers a very large share of American small and mid-size companies. So the usual outcome of our first conversation is discovering the capability is already sitting there, which converts what began as a purchasing discussion into a configuration exercise.
We design Autopatch groups around the business, not the org chart
Because a group ties directory membership to update policy, how you group people determines who meets an update first and how much cushion sits behind them. Your opening ring should be people who will spot something wrong and describe it clearly. Your final ring should be whoever genuinely cannot absorb a difficult week. Neither of those is a question your directory structure can answer.
We evaluate Hotpatch seriously rather than as a footnote
Getting monthly security updates installed without demanding a restart tackles the number one practical reason patching fails, which has always been that people simply do not reboot. Anywhere you run shifts, share machines between staff, or employ people who keep forty tabs and six documents open for a month at a time, this is the capability the entire business case should be built around.
We set up the reporting so somebody acts on it
Two published aims give you something concrete to report: ninety five percent carrying the latest quality update, ninety percent of eligible machines on a supported Office channel. Those same figures happen to answer the patch cadence question on every insurance application and SOC 2 audit you will face. Device alerts then convert the shortfall into an actual list. Give nobody ownership of that list and the service will quietly handle ninety percent of the problem while the final tenth stays broken forever.
Six US situations where Autopatch solves a real problem.
Shift operations where nobody reboots
Stores, hotels, hospitals, warehouses, production floors: places where one machine is used continuously across changing shifts and the restart prompt gets dismissed by every person who sees it. Delivering monthly security updates without needing that restart is aimed squarely at this population, and in these environments it is comfortably the strongest argument for adopting the service at all.
A firm asked to evidence patch currency
An auditor, an insurance carrier, a customer security questionnaire or an examiner working under the FTC Safeguards Rule or NYDFS Part 500 wants to know what share of your machines are current and how fast security updates actually reach them. The published objectives plus the update reports answer with figures. Saying that updates go out monthly answers with an assertion, and assertions are increasingly being sent back with follow-up questions attached.
A small IT team spending days on updates
One of the stated benefits is optimizing administrator capacity by automating routine endpoint updates, which is a polite way of describing something every small team recognizes. Patching is a recurring cost that produces no visible output whatsoever when it goes well, and enormous visibility when it does not. Taking it off a three person team gives you back genuine capacity rather than a line in a business case.
An organization nervous about annual feature updates
Feature releases reach everybody at once and occasionally break something the business depends on. Phased release policies let the deployment move through your groups in stages you define, which turns an annual event people brace for into a controlled sequence that has an obvious place to stop if the early phases report trouble.
An estate where drivers and firmware are simply never updated
Which describes almost every estate we have ever assessed, for the entirely reasonable reason that no good central mechanism existed. Now you can take them automatically or manage them yourself, direct the flow toward particular groups or rings, approve an individual driver across the whole tenant, and reach packages that were simply beyond central management before.
A business where Microsoft 365 Apps versions are all over the place
Colleagues sitting on wildly different builds, a few of them years adrift, generating intermittent faults nobody has ever managed to reproduce on demand. Holding ninety percent of eligible machines on a supported channel version quietly eliminates an entire category of tickets that your service desk never diagnosed as version problems in the first place.
How Windows updates are actually managed in US organizations.
| Feature | Autopatch in use | Update rings, unmanaged | Windows Update defaults |
|---|---|---|---|
Windows quality updates managed | Yes | Yes | Partly |
Security updates without a restart | Yes, via Hotpatch | No | No |
Feature updates phased deliberately | Yes | Sometimes | No |
Drivers and firmware managed centrally | Yes | Rarely | No |
Microsoft 365 Apps kept current | Yes | No | Inconsistently |
Edge and Teams updates managed | Yes | No | Inconsistently |
A stated target to report against | Yes | No | No |
Alerts identifying devices to fix | Yes | Partly | No |
Rollout responds to reliability signals | Yes | No | No |
Frequency in the US mid-market | Uncommon | Common | Common in small businesses |
Four products, and what Autopatch does with each.
Product
Windows quality updates
- What Autopatch does
- Aims to keep at least 95 percent of up to date devices on the latest quality update
Product
Hotpatch updates
- What Autopatch does
- Installs monthly B release security updates without requiring a device restart
Product
Windows feature updates
- What Autopatch does
- Controlled annual rollout, with multi-phase release policies across Autopatch groups
Product
Drivers and firmware
- What Autopatch does
- Automatic or self-managed, with tenant-wide approvals for specific drivers
Product
Microsoft 365 Apps
- What Autopatch does
- Aims to keep at least 90 percent of eligible devices on a supported Monthly Enterprise Channel version
Product
Microsoft Edge
- What Autopatch does
- Configures eligible devices for progressive rollouts on the Stable channel
Product
Microsoft Teams
- What Autopatch does
- Allows eligible devices to use the standard automatic update channel
Product
Reporting
- What Autopatch does
- Intune reports, Hotpatch quality update report, and device alerts for devices not up to date
Five steps, and it is quicker than most Intune work.
- 1
Confirm entitlement and readiness
Three checks. What licensing you actually hold, bearing in mind Business Premium and A3 or above have qualified since April 2025. Whether your machines are already under Intune management. And whether direct support requests to the Service Engineering Team matter to you, since that is the one thing sitting above the wider tier.
- 2
Design the Autopatch groups
Directory groups get bound to the update policies that ought to govern them, so audience and behavior become a single thing to maintain. Populate the opening ring with people who will notice something wrong and describe it usefully. Populate the closing ring with whoever can least afford a difficult week.
- 3
Decide the update behavior per product
We work through quality updates and whether restart-free installation suits your estate, how the annual feature release should be phased, whether drivers and firmware come automatically or under your own control, and finally confirming the Office applications, Edge and Teams are all in scope. In our experience they should be, and in most tenants they are not.
- 4
Register devices and watch the first cycle
Registration happens in the Intune admin center, and then you wait and watch one complete monthly cycle before widening anything. Your early rings are where compatibility problems specific to your own application estate reveal themselves, which is the entire reason sequential rings exist rather than a formality to hurry through.
- 5
Set up reporting and assign the exceptions
The quality and feature reports go in, along with the dedicated Hotpatch view and the device alerts flagging machines that have fallen behind. Then, crucially, a named individual takes ownership of working that list. The service will handle the overwhelming majority without help. The remainder needs a person who actually cares whether it gets fixed.
What organizations ask about Windows Autopatch.
Fifteen questions worth answering first.
Entitlement and readiness
- Which licenses do you actually hold?Business Premium and A3 and above are included since April 2025.
- Are devices already managed by Intune?Registration happens through the Intune admin center.
- Do you need Service Engineering Team support?That is the E3 and above or F3 difference.
- Are you currently using update rings already?They can be managed within Autopatch.
- Who monitors the Message center?Service communications arrive there.
How updates should flow
- What Autopatch groups reflect your business?They group Entra groups with update policies.
- Who should be in the earliest ring?People who will report a problem clearly.
- How should annual feature updates be phased?Multi-phase release policies exist for this.
- Automatic or self-managed drivers and firmware?Both are supported, per group or tenant-wide.
- Is Hotpatch appropriate for your estate?It removes the restart from monthly security updates.
Operations
- Who reviews device alerts?They identify devices that are not up to date.
- What is your target, and do you report it?Microsoft publishes 95 percent and 90 percent aims.
- How are Microsoft 365 Apps updated today?Usually inconsistently, or not at all.
- Do you have devices that are rarely online?They will be the persistent exceptions.
- Does anybody currently own patching?Autopatch removes the work, not the accountability.
The pages around this one.
Windows Autopilot
The provisioning half of the same story: getting a device from the box to configured without anybody imaging it.
Microsoft Intune
The platform Autopatch is administered from, covering enrollment, configuration, and application deployment.
Defender Vulnerability Management
The other side of patching: knowing what is exposed, prioritized by what is actually being exploited.
Check whether Autopatch is already in your subscription.
Since April 2025 it has been included with Business Premium and A3 or above, and a large share of US small and mid-size organizations are on exactly those licenses and have never enabled it. The check takes minutes and it frequently ends the procurement conversation before it starts.
Related Services
Explore more solutions that work great with this service