Business Premium got Autopatch in April 2025. Most organisations here still do not know they have it.
Microsoft removed feature activation and made Windows Autopatch available to Business Premium and A3 or above licences. It automates Windows, Microsoft 365 Apps, Edge and Teams updates through sequential deployment rings, and Hotpatch installs monthly security updates without a restart.

- Business PremiumIncluded since April 2025
- 95%Target for devices on the latest quality update
- No restartHotpatch monthly security updates
- Four productsWindows, M365 Apps, Edge and Teams
April 2025 changed who can use this, and the announcement did not travel.
Microsoft states that in April 2025 Windows Autopatch removed feature activation and made its features available to Business Premium and A3 or above licences. That is a significant widening in a market where Business Premium is the dominant subscription.
- Before that change, Autopatch was effectively an enterprise capability. Afterwards, the published feature tables list role-based access control, update rings, Autopatch groups, Windows quality and feature updates, Hotpatch, driver and firmware updates, Microsoft 365 Apps, Edge and Teams updates, and the reporting, all as included with Business Premium, A3 and above, E3 and above, and F3.
- The only capability the published tables gate above that level is submitting support requests to the Windows Autopatch Service Engineering Team, which is listed as E3 and above or F3 only. That is a meaningful difference for a large enterprise and rarely the deciding factor for a smaller one.
- Microsoft also noted the changes were rolling out over several weeks and that if your experience looks different from the documentation you may not have received them yet. Given the date, that rollout is long complete, but it is worth verifying against your own tenant rather than assuming.
- The practical consequence for most organisations here is that a capability they assumed required an enterprise agreement is sitting unused in the subscription they already have. Checking takes minutes and is the first thing worth doing.
Eight capabilities, and one of them removes the restart.
Hotpatch, which installs security updates without a restart
Microsoft describes Hotpatch as installing monthly B release security updates without requiring the device to be restarted. For any organisation where the real obstacle to patching is that people will not reboot, or cannot reboot during a shift, this changes the arithmetic entirely. It is also the capability that most reliably surprises people who assumed Autopatch was just automated Windows Update.
Published service level objectives, which most tools do not have
Microsoft states Autopatch aims to keep at least ninety five percent of up to date devices on the latest quality update, and at least ninety percent of eligible devices on a supported version of the Monthly Enterprise Channel for Microsoft 365 Apps. Having a stated target you can report against is a materially different proposition from a patching process whose success is measured by nobody complaining.
Autopatch groups, which are more than device groups
Microsoft describes an Autopatch group as a logical container grouping several Microsoft Entra groups together with software update policies, including update ring policies and feature update policies. That means the audience and the update behaviour are managed as one object, which is what stops the usual drift between which group a device is in and which policy actually applies to it.
Driver and firmware updates, including ones nothing else could reach
You can choose to receive driver and firmware updates automatically or self-manage the deployment, control the flow of all drivers to an Autopatch group or to rings within it, control a specific driver or firmware across the entire tenant through approvals, and approve and deploy other drivers and firmware that previously could not be centrally managed. That last point closes a genuine long-standing gap.
Feature updates with multi-phase release policies
Annual Windows feature updates are the ones organisations dread, because a bad one affects everybody at once. Multi-phase release policies allow customisable feature update deployments using multiple phases across your existing Autopatch groups, so the rollout can be shaped to your business rather than to a default schedule somebody chose once.
Microsoft 365 Apps, Edge and Teams, all in the same service
Autopatch keeps Microsoft 365 Apps on a supported Monthly Enterprise Channel version, configures eligible devices to benefit from Edge progressive rollouts on the Stable channel, and allows eligible devices to use the standard automatic update channel for Teams. Most organisations manage these three separately, badly, or not at all, and this consolidates them.
Reporting that identifies what to fix
Alongside Intune reports there is a Hotpatch quality update report giving a per policy view of update status for every device receiving Hotpatch updates, and enhanced quality and feature update reports with device alerts, which Microsoft frames as monitoring and remediating devices that are not up to date. The alerts are the useful part, because they turn a percentage into a list of devices.
The one thing that still needs E3 or F3
Microsoft lists the ability to submit support requests to the Windows Autopatch Service Engineering Team under features included with E3 and above or F3 licences only. Everything else in the published feature tables is available at Business Premium and A3 or above. If you are on Business Premium, you get the service and handle support through your usual channel.
Four things that make Autopatch worth adopting properly.
We check entitlement before anybody discusses buying anything
Since April 2025 the published feature tables include Business Premium and A3 or above, which covers a large proportion of organisations in this market. The most common outcome of the first conversation is establishing that the capability is already available, which turns a procurement discussion into a configuration one.
We design Autopatch groups around the business, not the org chart
An Autopatch group binds Entra groups to update policies, so the grouping decides who gets an update first and how long the safety margin is. The right first ring is people who will notice a problem and report it clearly, and the right last ring is whoever cannot afford a bad week. That is a business question, not a directory one.
We evaluate Hotpatch seriously rather than as a footnote
Installing monthly security updates without requiring a restart addresses the single most common reason patching fails in practice, which is that people do not reboot. For shift-based operations, shared machines and anybody whose users leave everything open for weeks, this is the capability worth building the case around.
We set up the reporting so somebody acts on it
Microsoft publishes aims of ninety five percent on the latest quality update and ninety percent of eligible devices on a supported Microsoft 365 Apps channel. Those give you a target to report against. Device alerts turn the gap into a list. Without somebody owning that list, Autopatch quietly does most of the work and the remaining ten percent stays broken indefinitely.
Six UAE situations where Autopatch solves a real problem.
Shift operations where nobody reboots
Retail, hospitality, healthcare, logistics and manufacturing, where a machine is in use across shifts and a restart prompt gets dismissed indefinitely. Hotpatch installing monthly security updates without requiring a restart is aimed precisely at this, and it is the strongest single argument for adopting the service in these environments.
A regulated firm asked to evidence patch currency
Where a regulator, an auditor, an insurer or a client asks what proportion of devices are current and how quickly security updates are applied, the published service level objectives plus the update reports answer it with numbers. A statement that updates are applied monthly answers it with an assertion, which is increasingly not accepted.
A small IT team spending days on updates
Microsoft frames one of the benefits as optimising IT administrator resources by automating routine endpoint updates. For a two or three person team, patch management is a recurring cost with no visible output when it goes well and a great deal of visibility when it does not. Removing it is a genuine return of capacity.
An organisation nervous about annual feature updates
The Windows feature update is the change that affects everybody and occasionally breaks something important. Multi-phase release policies allow a customisable, phased deployment across your Autopatch groups, which converts an event people dread into a controlled sequence with a stopping point.
An estate where drivers and firmware are simply never updated
Which is most of them, because there was no good central way to do it. Autopatch lets you take driver and firmware updates automatically or self-manage them, control the flow to specific groups or rings, approve a specific driver tenant-wide, and reach drivers and firmware that previously could not be centrally managed at all.
A business where Microsoft 365 Apps versions are all over the place
Different people on different builds, some years behind, producing intermittent problems nobody can reproduce. Autopatch aiming to keep at least ninety percent of eligible devices on a supported Monthly Enterprise Channel version quietly resolves a category of support tickets that were never recognised as version problems.
How Windows updates are actually managed in UAE organisations.
| Feature | Autopatch in use | Update rings, unmanaged | Windows Update defaults |
|---|---|---|---|
Windows quality updates managed | Yes | Yes | Partly |
Security updates without a restart | Yes, via Hotpatch | No | No |
Feature updates phased deliberately | Yes | Sometimes | No |
Drivers and firmware managed centrally | Yes | Rarely | No |
Microsoft 365 Apps kept current | Yes | No | Inconsistently |
Edge and Teams updates managed | Yes | No | Inconsistently |
A stated target to report against | Yes | No | No |
Alerts identifying devices to fix | Yes | Partly | No |
Rollout responds to reliability signals | Yes | No | No |
Frequency in the UAE market | Uncommon | Common | Common in SMEs |
Four products, and what Autopatch does with each.
| Product | What Autopatch does | |
|---|---|---|
| Windows quality updates | Aims to keep at least 95 percent of up to date devices on the latest quality update | |
| Hotpatch updates | Installs monthly B release security updates without requiring a device restart | |
| Windows feature updates | Controlled annual rollout, with multi-phase release policies across Autopatch groups | |
| Drivers and firmware | Automatic or self-managed, with tenant-wide approvals for specific drivers | |
| Microsoft 365 Apps | Aims to keep at least 90 percent of eligible devices on a supported Monthly Enterprise Channel version | |
| Microsoft Edge | Configures eligible devices for progressive rollouts on the Stable channel | |
| Microsoft Teams | Allows eligible devices to use the standard automatic update channel | |
| Reporting | Intune reports, Hotpatch quality update report, and device alerts for devices not up to date |
Five steps, and it is quicker than most Intune work.
- 1
Confirm entitlement and readiness
Which licences you hold, given that Business Premium and A3 or above have been included since April 2025, whether devices are already managed through Intune, and whether you need support requests to the Windows Autopatch Service Engineering Team, which is the E3 and above or F3 difference.
- 2
Design the Autopatch groups
Grouping Entra groups with the update policies that should apply to them, so the audience and the update behaviour are one object. The first ring should be people who will notice and report a problem clearly, and the last should be whoever can least afford disruption.
- 3
Decide the update behaviour per product
Quality updates and whether Hotpatch is appropriate, how annual feature updates should be phased using multi-phase release policies, whether drivers and firmware are taken automatically or self-managed, and confirming Microsoft 365 Apps, Edge and Teams are in scope, which they usually should be.
- 4
Register devices and watch the first cycle
Through the Intune admin center, then observe a full monthly cycle before widening. The early rings surface the compatibility issues that matter to your specific application estate, which is exactly what sequential deployment rings exist to do.
- 5
Set up reporting and assign the exceptions
The quality and feature update reports, the Hotpatch quality update report, and device alerts identifying devices that are not up to date. Then a named person who works that list, because the service handles the majority automatically and the remainder needs somebody to care about it.
What organisations ask about Windows Autopatch.
Fifteen questions worth answering first.
Entitlement and readiness
- Which licences do you actually hold?Business Premium and A3 and above are included since April 2025.
- Are devices already managed by Intune?Registration happens through the Intune admin center.
- Do you need Service Engineering Team support?That is the E3 and above or F3 difference.
- Are you currently using update rings already?They can be managed within Autopatch.
- Who monitors the Message center?Service communications arrive there.
How updates should flow
- What Autopatch groups reflect your business?They group Entra groups with update policies.
- Who should be in the earliest ring?People who will report a problem clearly.
- How should annual feature updates be phased?Multi-phase release policies exist for this.
- Automatic or self-managed drivers and firmware?Both are supported, per group or tenant-wide.
- Is Hotpatch appropriate for your estate?It removes the restart from monthly security updates.
Operations
- Who reviews device alerts?They identify devices that are not up to date.
- What is your target, and do you report it?Microsoft publishes 95 percent and 90 percent aims.
- How are Microsoft 365 Apps updated today?Usually inconsistently, or not at all.
- Do you have devices that are rarely online?They will be the persistent exceptions.
- Does anybody currently own patching?Autopatch removes the work, not the accountability.
The pages around this one.
Windows Autopilot
The provisioning half of the same story: getting a device from the box to configured without anybody imaging it.
Microsoft Intune
The platform Autopatch is administered from, covering enrolment, configuration and application deployment.
Defender Vulnerability Management
The other side of patching: knowing what is exposed, prioritised by what is actually being exploited.
Check whether Autopatch is already in your subscription.
Since April 2025 it has been included with Business Premium and A3 or above, and a large share of organisations in this market are on exactly those licences and have never enabled it. The check takes minutes and it frequently ends the procurement conversation before it starts.
Related Services
Explore more solutions that work great with this service
Enterprise App Management
Hundreds of prepared Win32 apps, and the limits of auto-update
Windows Autopilot Dubai
Zero-touch laptop deployment, supplier registration onward
Microsoft Intune
Device management and endpoint security
Defender Vulnerability Management
Certificates, browser extensions and firmware, not just patching
Intune Compliance Policies
The default that lets unassessed devices through Conditional Access
MDM Solutions Dubai
Device management across Windows, Apple and Android
Endpoint Security
Defender for Endpoint and Intune managed
IT Support Dubai
24/7 on-site and remote IT support