Microsoft's August 2026 Windows 11 servicing calendar identifies a hotpatch release for eligible 24H2 and 25H2 devices. Hotpatch can apply security updates without an immediate restart between quarterly baseline updates. That can reduce disruption, but it does not make patch management automatic or risk-free.
Understand the servicing rhythm
Eligible devices receive a cumulative baseline update periodically, and that baseline requires a restart. Hotpatch updates can then deliver security fixes during the intervening months without the usual restart.
Microsoft's published prerequisites include an eligible licence, a supported Windows 11 version, the current baseline, Microsoft Intune policy and required device configuration. Ineligible devices continue on the standard update path.
This creates a mixed estate: some devices hotpatch, some require the conventional monthly update and some may be outside policy because of version, architecture, configuration or health.
Keep an accurate device inventory
Start with OS version, build, architecture, ownership, location, business criticality and management status. Identify unsupported versions and devices that have stopped reporting.
A deployment percentage without an accurate denominator is misleading. The target is not “95% of visible devices”; it is every in-scope device, with a named and time-limited exception for the rest.
Use rings and evidence
Deploy to a representative pilot ring before broad rollout. Include the applications, security tools, drivers and user roles that carry the most operational risk. Define the observation period and the evidence required to proceed.
For urgent vulnerabilities, the risk owner may approve a faster rollout. Record that decision rather than quietly bypassing the process.
Manage the baseline restarts
Hotpatch reduces restart frequency; it does not eliminate baseline restarts. Communicate the quarterly rhythm, give users a clear deadline and enforce the restart after a reasonable window. Monitor devices that miss the baseline because they may become ineligible for later hotpatches.
Coordinate Microsoft and third-party patching
Attackers do not limit themselves to Windows. Browsers, PDF tools, collaboration clients, Java runtimes and remote-access software need coverage too. Coordinate Microsoft servicing with third-party application patching so that one dashboard does not create a false sense of completeness.
N-able N-central provides device inventory, monitoring, automation and patch-management capabilities across managed estates. Microsoft Intune remains part of the published Windows hotpatch deployment path; N-central can complement it with broader operational visibility and third-party management. The exact division of responsibility should be designed and tested for the organisation.
Measure outcomes
Report:
- percentage of in-scope devices current on the required baseline;
- hotpatch eligibility and deployment success;
- critical security updates outside the target window;
- devices not reporting to management tools;
- third-party application exposure; and
- exceptions by owner and expiry date.
Hotpatch is useful because it can reduce disruption while maintaining security coverage. Its value depends on governance: accurate inventory, correct eligibility, controlled rollout, baseline compliance and exception ownership.
Sources
- Microsoft Windows 11 release information and hotpatch calendar, accessed 20 August 2026.
- Microsoft Windows Autopatch FAQ, accessed 20 August 2026.
Build a measurable patch and endpoint-management programme with OAS N-able N-central services.
