惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
Y
Y Combinator Blog
I
InfoQ
Recent Announcements
Recent Announcements
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园 - Franky
IT之家
IT之家
H
Help Net Security
月光博客
月光博客
S
SegmentFault 最新的问题
B
Blog
aimingoo的专栏
aimingoo的专栏
GbyAI
GbyAI
P
Proofpoint News Feed
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
G
Google Developers Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
U
Unit 42
Vercel News
Vercel News
博客园 - 叶小钗
Microsoft Security Blog
Microsoft Security Blog
腾讯CDC
Jina AI
Jina AI
T
The Blog of Author Tim Ferriss

The Register - Software: OSes

Fedora: Microsoft is all aboard, but Deepin is dumped Microsoft promises to do better, but it has a long way to go First big Microsoft update after vow to 'win back fans' Who needs ghost train scares when Windows is such a fright? Microsoft boss tells investors the company is working to 'win back fans' Microsoft boss says company is working to 'win back fans' Linux cryptographic code flaw offers fast route to root Fedora 44 is out – countless versions of it Microsoft sets its sights on the past with 86-DOS and PC-DOS Microsoft updates the Windows Update Experience Windows second-chance setup hurts IT, productivity Ubuntu Resolute Raccoon drops Xorg, keeps X11 apps alive More ancient Linux device support facing the ax WSL9x hacks Linux into ancient Windows 9x systems UK tribunal sends £2B claim accusing Microsoft of overcharging for licensing to trial Zorin OS 18.1 released - and the Lite edition reappears Task Manager's CPU%: an obituary for the recent past Linux 7.1 will have an optional new NTFS driver Microsoft releases Windows Server update to fix April update 20-year-old Enlightenment E16 bug finally gets patched 20-year-old Enlightenment E16 bug finally gets patched Raspberry Pi OS ends open-door policy for sudo Firefox Nightly adds Web Serial after years of saying no Windows Update: Torture chamber for seldom-used PCs Windows Update: Torture chamber for seldom-used PCs Notepad loses Copilot icon as Microsoft gives subtlety a try Notepad loses Copilot icon as Microsoft gives subtlety a try Microsoft attempts to untangle Windows Insider program Adobe finally patches PDF pest after months of abuse NHS pays £46K to prep next Microsoft licensing round
Hotpatching goes default in Windows Autopatch
Richard Speed Richard Speed · 2026-03-11 · via The Register - Software: OSes

OSes

Hotpatching goes default in Windows Autopatch whether you like it or not

Microsoft insists rebootless updates are 'the quickest way to get secure'

From the department of "what could possibly go wrong?" comes news that Windows Autopatch is enabling hotpatch security updates by default.

The change starts with the May 2026 Windows security update, and controls to opt out will be available from April 1.

According to Microsoft, the company has "changed the game" with the launch of hotpatch updates. The feature installs security updates without requiring a restart, meaning changes take effect immediately. The process does require one baseline update with a restart to kick things off. However, after that, hotpatch updates install silently, with no reboot needed. That said, every quarterly baseline update still demands a restart.

Windows Autopatch manages the rollout of updates across an organization. It uses "testing rings" – sample device groups – to roll out updates progressively and halt or reverse them if problems emerge.

Enabling hotpatch by default from May 2026 won't override existing policies. Microsoft states that "Windows Autopatch respects your configuration of quality update policies," meaning update deferrals and ring settings still apply.

However, on any device that meets the prerequisites (running Windows 11 24H2 or later, using an eligible license, and with the April 2026 security update installed), hotpatch updates will start rolling in automatically.

Microsoft's recommendation is, unsurprisingly, to leave hotpatch updates enabled. It argues that "hotpatch updates are the quickest way to get secure."

Administrators who need more time before the change happens (less than two months isn't a lot of notice) or want to stick to the previous patching method can opt out at the tenant level or via a policy for a group of devices.

Microsoft has had a rocky start to the year on the update front. Its ring-based deployment strategy does not limit the blast radius when something goes wrong, and making hotpatching the default adds another variable that could produce unexpected consequences.

Administrators who prize tight control over their environments won't love this change, which makes the tenant-level and policy-level opt-outs genuinely welcome additions. The compressed timeline is harder to defend. ®