Windows Autopatch Will Finally Let Admins Pause Problematic Updates
Windows Autopatch is getting new controls that let IT administrators decide how Windows quality updates, supported .NET Framework updates, and recovery fixes reach managed devices.
Microsoft is expanding Windows Autopatch starting September 1, 2026, with the rollout expected to reach all tenants by October 15.
The changes give administrators more control over update approvals, deferrals, pauses, and deployment monitoring.
Autopatch adds automatic and manual update approvals
Windows Autopatch will support both automatic and manual approval for monthly Windows security updates.
The same approval options apply to monthly non-security preview releases, out-of-band updates, and supported .NET Framework updates.
Microsoft recommends automatically approving security updates while using manual approval for optional releases. This approach lets administrators deploy critical fixes quickly while testing less urgent updates before broader deployment.
Admins can defer updates for up to 30 days
Administrators can configure deferral periods between zero and 30 days for automatically approved updates.
Organizations can use these deferrals to stagger deployments across different device groups instead of installing an update everywhere at the same time.
Admins can also override an existing deferral and immediately approve a release when necessary.
Problematic updates can be paused
Windows Autopatch will also let administrators pause individual updates when a release starts causing problems.
Pausing an update stops additional managed devices from receiving it. However, Autopatch will not roll back devices that already installed the release.
Administrators can resume deployment by approving the update again. Microsoft says pause and resume instructions can take up to eight hours to reach managed devices.
Quick machine recovery gets the same controls
The expanded controls also cover Quick machine recovery.
Quick machine recovery can apply Microsoft-provided fixes through the Windows Recovery Environment when a PC fails to boot twice consecutively.
Administrators can choose automatic or manual approval for these recovery updates. They can also defer them, approve them immediately, or pause a recovery update if it causes problems.
Microsoft adds a Quality update status report
Microsoft is also introducing a per-device Quality update status report for Autopatch-managed systems.
The report can show whether a device is up to date, currently installing an update, or has missed its update deadline.
Administrators can view target and installed releases, assigned policies, Windows build numbers, readiness details, and alerts. Optional information can also include the latest Intune check-in time and Windows Update error codes.
The report supports search, filtering, sorting, and CSV exports. Microsoft says the underlying data refreshes every four hours.
The Autopatch changes arrive as Microsoft continues adjusting how Windows 11 updates and security protections work. The company will automatically enable memory integrity on Windows 11 on eligible systems, while future updates will require only one monthly restart.
Via Neowin
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages