Windows Autopatch Will Finally Let Admins Pause Problematic Updates


ShieldBreak windows 11 zero day
Image credit: Microsoft

Windows Autopatch is getting new controls that let IT administrators decide how Windows quality updates, supported .NET Framework updates, and recovery fixes reach managed devices.

Microsoft is expanding Windows Autopatch starting September 1, 2026, with the rollout expected to reach all tenants by October 15.

The changes give administrators more control over update approvals, deferrals, pauses, and deployment monitoring.

Autopatch adds automatic and manual update approvals

Windows Autopatch will support both automatic and manual approval for monthly Windows security updates.

The same approval options apply to monthly non-security preview releases, out-of-band updates, and supported .NET Framework updates.

Microsoft recommends automatically approving security updates while using manual approval for optional releases. This approach lets administrators deploy critical fixes quickly while testing less urgent updates before broader deployment.

Admins can defer updates for up to 30 days

Administrators can configure deferral periods between zero and 30 days for automatically approved updates.

Organizations can use these deferrals to stagger deployments across different device groups instead of installing an update everywhere at the same time.

Admins can also override an existing deferral and immediately approve a release when necessary.

Problematic updates can be paused

Windows Autopatch will also let administrators pause individual updates when a release starts causing problems.

Pausing an update stops additional managed devices from receiving it. However, Autopatch will not roll back devices that already installed the release.

Administrators can resume deployment by approving the update again. Microsoft says pause and resume instructions can take up to eight hours to reach managed devices.

Quick machine recovery gets the same controls

The expanded controls also cover Quick machine recovery.

Quick machine recovery can apply Microsoft-provided fixes through the Windows Recovery Environment when a PC fails to boot twice consecutively.

Administrators can choose automatic or manual approval for these recovery updates. They can also defer them, approve them immediately, or pause a recovery update if it causes problems.

Microsoft adds a Quality update status report

Microsoft is also introducing a per-device Quality update status report for Autopatch-managed systems.

The report can show whether a device is up to date, currently installing an update, or has missed its update deadline.

Administrators can view target and installed releases, assigned policies, Windows build numbers, readiness details, and alerts. Optional information can also include the latest Intune check-in time and Windows Update error codes.

The report supports search, filtering, sorting, and CSV exports. Microsoft says the underlying data refreshes every four hours.

The Autopatch changes arrive as Microsoft continues adjusting how Windows 11 updates and security protections work. The company will automatically enable memory integrity on Windows 11 on eligible systems, while future updates will require only one monthly restart.

Via Neowin

More about the topics: microsoft, Windows, Windows Update

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages