Thursday, April 3rd 2025

Forget Reboots, Live Patches are Coming to Windows 11 Enterprise Clients

Microsoft is introducing live patch updates for Windows 11 Enterprise, version 24H2, that allow critical security fixes to be applied without interrupting users. These updates, known as hotpatches, are available for x64 devices running on AMD or Intel CPUs. Hotpatch updates are designed to install quickly and take effect immediately. Unlike standard monthly security updates that require a system restart, hotpatch updates provide instant protection against vulnerabilities while allowing users to continue working. This new process can reduce the number of restarts from twelve per year to just four. The update schedule follows a quarterly cycle. In January, April, July, and October, devices install a complete security update with new features and fixes that do require a restart. In the two months that follow each of these baseline updates, devices receive hotpatch updates that only include security fixes and do not need a reboot. This approach ensures that essential protections are applied quickly without impacting daily work.

To use hotpatch updates, organizations need a Microsoft subscription that includes Windows 11 Enterprise (or Windows 365 Enterprise) and devices running build 26100.2033 or later. These devices must also be managed using Microsoft Intune, where IT administrators can set up a hotpatch-enabled quality update policy. The Intune admin center automatically detects eligible devices and manages the update process. Hotpatch updates are currently available on Intel and AMD-powered devices. For Arm64 devices, hotpatch updates are still in public preview and require an extra configuration step: disabling CHPE support via a registry key or the upcoming DisableCHPE CSP. This update system represents a more efficient way to secure Windows client devices. By minimizing the need for restarts and delivering updates in a predictable, quarterly cycle, Microsoft aims to help organizations protect their systems with minimal disruption. We expect these live patches to trickle down to more Windows 11 versions, like Home and Pro editions.
Source: Windows IT Pro Blog
Add your own comment

28 Comments on Forget Reboots, Live Patches are Coming to Windows 11 Enterprise Clients

#26
blinnbanir
NoLoihiStandard advice is: Have you tried a clean clean install? Where you nuke your disk before installing? Very weird. Are these alll the same models of computers, or various? There’s a mechanism to install drivers from your UEFI, if that is the cause, that’d be rad. I don’t think it’s malware.
I actually took a drive out of another PC and formatted it. I can confirm it is Win11 as I went all the way back to 10 and there was no issue until we got to 24H2. I think it might have to do with telemetry.
Posted on Reply
#27
Easo
blinnbanirI actually took a drive out of another PC and formatted it. I can confirm it is Win11 as I went all the way back to 10 and there was no issue until we got to 24H2. I think it might have to do with telemetry.
So you think the telemetry causes all those mega strange issues you have...? Really?
Posted on Reply
#28
NoLoihi
blinnbanirI actually took a drive out of another PC and formatted it. I can confirm it is Win11 as I went all the way back to 10 and there was no issue until we got to 24H2. I think it might have to do with telemetry.
I, too, doubt it's the telemetry, but if you wanted to take a dig at that, maybe take a look at those “debloated“ or “telemetry removed” installation images people are offering? (No warranties on my part, neither explizit or implied, not even partaining to gross negligence. :rolleyes: )
Posted on Reply
Add your own comment
May 3rd, 2025 17:07 EDT change timezone

New Forum Posts

Popular Reviews

Controversial News Posts