‹ Back to list
Stay InformedMC1465692

More control for Windows Autopatch updates: quality updates, .NET Framework, and quick machine recovery

Services: Windows· Published: 2026-09-01· MS modified: 2026-09-01
Admin impact

Microsoft announcement

What and why: 
Windows Autopatch is expanding to provide a streamlined experience for managing Windows quality updates, supported .NET Framework updates, and quick machine recovery updates. These capabilities give you more control over update approvals and rollout timing, along with device-level reporting to monitor approved releases, deployments, and remediation status.  
 
Rollout schedule: 
Rollout begins September 1, 2026, and is expected to reach all tenants by October 15, 2026. 
 
Impact on your organization: 
With this change, you can use Windows Autopatch quality update policies to manage approvals for Windows OS quality updates, supported .NET Framework updates, and quick machine recovery updates. The updated experience includes the following capabilities: 
  • Configure automatic or manual approval by update type for monthly security updates, monthly non-security preview updates, out-of-band security updates, and out-of-band non-security updates. Approval settings for each category apply to both Windows OS quality updates and supported .NET Framework releases. 
  • Use automatic approvals with a configured deferral period to support gradual deployments or require manual review before an update is offered. Windows Autopatch recommends automatic approval for security updates and manual approval for optional updates. 
  • Configure quick machine recovery approval and deferral settings in the same quality update policy. Quick machine recovery helps restore applicable Windows devices that become unbootable after a critical large-scale issue. You can automatically approve fixes or review and approve them manually. 
  • Review, approve, and pause individual Windows quality updates, supported .NET Framework, and quick machine recovery updates from the Manage quality updates experience. Pausing a release prevents new devices from receiving it but does not roll back devices that have already installed it. 
  • Use the quality update status report for a per-device view, target compliance, target and installed updates, assigned policies, readiness, alerts, and hotpatch update information. Use the new quick machine recovery update status report to view affected devices, remediation status, applicable fix version, release date, assigned quality update policy, and OS version. 

Action required/recommendations: 
Learn more about these new capabilities in the Microsoft Intune admin center and review your current update management processes.  

Determine which update types you desire to approve automatically or manually. Then plan a gradual rollout cadence for your tenant using approval settings and appropriate deferral periods. 

Change history