Windows Autopatch used to be the service that approved monthly updates for you; in 2026 it has become the control plane where you decide, per update type, whether approval is automatic or manual, how long to defer, and when to pause. Between 1 September and 15 October 2026 Microsoft is rolling out that expanded experience, which also covers supported .NET Framework updates and quick machine recovery fixes. In this post I'll walk through how Autopatch groups and quality update policies fit together, how to configure the new controls, where the reports are, and what to think about if you're coming from plain update rings.
How it works#
Two objects do the work:
- Autopatch groups (Tenant administration › Windows Autopatch › Autopatch groups) are containers that take your device-based Microsoft Entra groups, split them into up to 15 deployment rings (Test and Last are always present) and create the update ring, feature update, driver, Microsoft 365 Apps and Microsoft Edge update policies for each ring on your behalf. They register devices with the service and need app-only authentication turned on; user-based groups aren't supported, and overlapping device memberships cause conflicts.
- Windows quality update policies (Devices › Manage updates › Windows updates › Quality updates) decide which quality updates are approved and when they become available. Devices targeted by one are enrolled in Autopatch for quality updates automatically; if a device drops out of every quality update policy it stays enrolled for 24 hours and then falls back to plain Windows Update behaviour.
The new experience lets a single quality update policy carry a separate approval method for each of four update types: monthly security updates (default automatic), monthly non-security preview updates, out-of-band security updates and out-of-band non-security updates (all default manual). Each setting applies to both the Windows cumulative update and the matching .NET Framework release. Automatic approvals take a Make updates available after deferral of 0–30 days counted from Microsoft's release date; manual approvals wait until you approve a specific release. Microsoft's recommendation is automatic for security updates and manual for the optional ones.
Watch out: the approval method can't be changed after a policy is created. If you pick automatic where you meant manual (or the other way round), you have to create a new policy and move the devices. Decide the model before you select Create.
Prerequisites#
- Licensing: Microsoft 365 Business Premium, Windows 10/11 Education A3 or A5 (in Microsoft 365 A3/A5), Windows 10/11 Enterprise E3 or E5 (in Microsoft 365 F3, E3 or E5) or Enterprise E3/E5 VDA. Features are the same across these except that support requests aren't included with Business Premium or A3+.
- Identity and management: Microsoft Entra ID P1 or P2 plus Intune; devices must be corporate-owned, Microsoft Entra joined or hybrid joined, enrolled in Intune (or co-managed with the Windows Update and Device configuration workloads on Intune) and must have checked in within the last 28 days.
- Diagnostic data at least at the Required level, which the reports depend on.
- Quick machine recovery needs Windows 11 24H2 build 26100.4700 or later and a working recovery environment; only wired and WPA/WPA2 password-protected Wi-Fi networks are supported in WinRE.
Step-by-step#
1. Create the quality update policy#
- Go to Devices › Manage updates › Windows updates › Quality updates › Create › Windows quality update policy and name it.
- On Settings, choose automatic or manual for security, non-security and out-of-band updates. For automatic, set Make updates available after in days.
- In the same policy, set the approval method and deferral for quick machine recovery updates (default manual) and decide whether to enable hotpatch updates.
- Add scope tags, assign the device groups (use the same groups as your Autopatch group rings), review and create.
Create one policy per ring if you want different deferrals: for example 0 days for the test ring, 3 days for the first broad ring and 7 days for the rest. If several quality update policies hit the same device, the one that approves the latest release wins.
2. Approve, review or pause a release#
Open Quality updates › Manage updates. The Manage quality updates blade lists each release (Windows OS and supported .NET Framework updates, and quick machine recovery fixes) with an Approved policies count; select the X of Y link to see which policies are approved and which are marked Needs review, select a release name to read its severity and included KBs, then select the policies and choose Approve or Pause. You can also approve a single policy from the ellipsis next to a release on the policy's page, and you can override an automatic deferral by approving early.
Pausing revokes the approval, so no new devices get that release; devices that already installed it aren't rolled back. Only the selected release is paused (an OS pause doesn't pause a .NET release and vice versa), and to resume you re-approve. Expect up to eight hours for devices to pick up a pause or resume, because the instruction travels through normal Intune check-in.
3. Understand the precedence rules#
| Device is in… | What applies |
|---|---|
| Update ring + quality update policy | The quality update policy controls approval and deferral; the ring's deadline, grace period and restart settings still apply |
| Several quality update policies | The policy approving the latest release wins |
| Quality update policy + legacy hotpatch-only policy | The quality update policy wins; security updates wait for its approval |
| Quality update policy + settings catalog or CSP quick machine recovery settings | Cloud approval wins; the device isn't offered a recovery fix until you approve it |
Verify#
In the admin center#
- Reports › Windows Autopatch › Windows quality updates › Reports › Quality update status: one row per device with Update status (Up to date, In progress, Not up to date), Target compliance date, Target and Installed release, Autopatch group, update ring and quality update policy names, hotpatch readiness, build number, readiness and alerts. Optional columns add the Intune last check-in time and the Windows Update hex error code. Data refreshes every four hours and can be exported to CSV.
- The quick machine recovery update status report shows affected devices, remediation status, the applicable fix version, release date, assigned quality update policy and OS version.
- Devices › Windows updates › Monitor › Autopatch management status is the denominator check: every Intune-managed Windows device, whether it's covered by cloud policies, update rings or nothing at all.
Target compliance is calculated as release date + deferral + client deadline for automatic approvals, and approval date + client deadline for manual ones, so a device showing Not up to date has genuinely missed the window you defined.
On a device#
Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 5 HotFixID, InstalledOn
[System.Environment]::OSVersion.Version
reagentc /infoThe build number should match the Installed release in the report, and reagentc /info should show Windows RE enabled, which quick machine recovery depends on. Settings › Windows Update › Advanced options › Configured update policies still lists the deadline and grace values coming from the ring.
Update rings versus Autopatch, and moving over#
An update ring is a client-side instruction: defer by so many days, enforce a deadline, restart in this window, and whatever Windows Update offers after the deferral gets installed. A quality update policy is service-side: Autopatch decides which release a device may see, and its deferral overrides the ring's deferral and any CSP deferral. So migration is additive rather than a swap: keep the rings (or let Autopatch groups create them) for deadlines and restart behaviour, add quality update policies for approval control, and don't duplicate deferral settings. A manual-approval policy holds security updates until someone approves them, so decide who owns that monthly task before you assign it. Remember that .NET Framework 3.5 updates and Windows Insider devices aren't managed by these policies, and Windows 10 ESU devices still take .NET updates from client-side settings.
Tips & gotchas#
- With hotpatch enabled, approved non-security preview updates aren't installed, because they'd take the device off the hotpatch path.
- Pause is not uninstall. Have a remediation or rollback plan for devices that already installed a bad release.
- The feature is still reaching tenants until mid-October 2026; if your Settings page shows fewer approval options than described here, your tenant hasn't received it yet.