Windows quality update policy
Doc updateA new article documents using the Windows quality update policy to deploy Hotpatch security updates through Autopatch, including benefits and prerequisites.
5 January was a documentation-led Windows update day with no Message Center item. Intune added guidance for deploying restart-free Hotpatch security updates through Autopatch and a consolidated Windows Driver update policy article. The Hotpatch guidance lists Windows 11 Enterprise 24H2 or later, the latest baseline, VBS, an Intune Hotpatch policy, and Autopatch and licensing prerequisites. Driver guidance now covers automatic recommended-driver approval, manual approval, and reporting requirements. Other changes mainly repaired links, clarified that each update policy has its own prerequisites, and retired older driver and quality update page names. Planned Android, Apple, Lenovo, and managed-app filter capabilities remain roadmap items; the supplied evidence does not establish general availability or a new tenant behavior change.
New Intune device-updates guidance says Hotpatch security updates are Monthly B release security updates that install and take effect without requiring a restart. It describes Hotpatch as an extension of Windows Update that requires Autopatch to create and deploy hotpatches, while existing update-ring configurations continue to be honored. The article lists Windows 11 Enterprise 24H2 or later, the latest baseline release, VBS, an Intune Windows quality update policy with Hotpatch enabled, and licensing requirements
The new Windows Driver update management article documents automatic approval and deployment of each new recommended driver version, plus a manual mode in which newer versions remain inactive until an administrator approves them. It also describes reviewing available updates and selectively approving, pausing, or declining them.
The reports guidance now says Windows diagnostic data must be enabled for Windows Driver update reports. The documented procedure is Microsoft Intune admin center > Tenant administration > Connectors and tokens > Windows data, then turn on Enable features that require Windows diagnostic data in processor configuration.
The former driver-updates-overview.md article was removed as part of the consolidation into driver-updates.md. Administrators should update saved links and internal references; the change is a documentation retirement, not evidence of changed driver-policy behavior.
The in-development page adds planned capabilities including a Lenovo Device Orchestration link in the Intune admin center for Windows 11, Android settings catalog filtering by Fully managed (COBO), Corporate-owned work profile (COPE), or Dedicated (COSU), Apple DDM assignment filters for iOS/iPadOS and macOS, and additional Device Management Type values for managed apps. These entries describe planned work, not current availability.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
A new article documents using the Windows quality update policy to deploy Hotpatch security updates through Autopatch, including benefits and prerequisites.
A new consolidated article documents driver update policies: automatic or manual approval, pausing and approving drivers, prerequisites, supported editions, GCC limitations, RBAC, deployment planning, and reporting.
The driver update overview replaced its telemetry guidance with the shared device-configuration requirements, including enrollment, Entra join state, required telemetry, the Sign-In Assistant service, and Windows Update and Autopatch endpoints.
The overview renamed the Windows Update client policy section and clarified that each update policy type has its own prerequisites, while feature, quality, driver, and Hotpatch use the same backend service as Autopatch.
The guidance for devices ineligible for Windows 11 now points administrators to the central feature update policy workflow for policy behavior, creation, and licensing requirements.
The driver policy article now links its prerequisite, deployment-planning, and FAQ reference to the renamed driver-updates article.
The Windows 10-to-Windows 11 upgrade link now directs to the separate feature-updates-windows-10 article rather than an anchor in the main article.
The Windows updates index changed its quality updates Learn more link from quality-updates-policy.md to the renamed quality-updates.md article.
The driver overview removed the Windows diagnostic-data reporting section and its steps to enable the Windows data setting in Intune.
The former driver-updates-overview.md article was removed as part of the documentation rename to the consolidated driver-updates.md article.
The article removed the Microsoft Entra registered-device limitations section and its next-steps links, leaving the core policy guidance in the main article.
The former quality-updates-policy.md article was removed as part of the documentation rename to quality-updates.md.
The driver reports article now states that Windows diagnostic data must be enabled and gives the Intune path: Tenant administration > Connectors and tokens > Windows data, then enable the processor-configuration setting.
The article removed duplicate device prerequisite text and corrected the organizational-report anchor from Windows 10 feature updates to Windows feature updates.
The archived What's New entry now links Windows driver update policy guidance to driver-updates.md instead of driver-updates-overview.md.
The app monitoring article refreshed its wording and clarified several Android AOSP line-of-business app error descriptions and administrator actions, including conflicts, network failures, size limits, and download validation.
The Company Portal article now tells administrators to use `winget install "Company Portal" --source msstore` to download the Windows Company Portal app and its dependencies.
The in-development entry changed the Android Intune settings catalog settings-list link to a relative documentation path.
The Windows diagnostic data page now links the Windows driver updates report to driver-updates.md rather than the retired overview article.
The in-development page added planned items: an Intune admin center link to Lenovo Device Orchestration for Windows 11, Android settings catalog filtering by management mode, DDM assignment filters for Apple software updates, expanded managed-app device-management filter values, and Zimperium certificate inventory sync.
The co-management Windows Update workload guidance now links to the Windows software updates index rather than the former configure page.