Windows quality updates policy
Doc updateA new quality update policy article describes Hotpatch security updates that take effect without a restart.
Windows update guidance is the period’s substantive center. New and revised Intune articles distinguish routine monthly servicing through Windows Update and update rings from targeted expedite policies and Hotpatch, while adding concrete prerequisites and eligibility limits. The evidence indicates documentation restructuring rather than a new general-availability announcement; the Quality Updates Policy page is marked removed, while Defender for Endpoint guidance is clarified around risk-based compliance.
Revised Quality Updates guidance says devices without a Windows quality updates policy continue receiving monthly quality updates through standard Windows Update behavior. Update rings and Windows Update client policies still control deferrals, deadlines, restarts, and notifications. Create the policy for cloud-based orchestration, Windows Autopatch-managed deployments, Hotpatch, or policy-based reporting; an expedite policy can be used without creating one. This is a documentation clarification of policy scope,not
The article formerly titled Windows quality updates policy is now Expedite Windows quality updates. It defines expedite policies as accelerating one specific supported Windows security update, bypassing deferrals and normal deployment timing without pausing or editing monthly policies. The guidance describes the path as targeted and time-bound, with no change to future quality-update deployment.
The new Hotpatch article documents eligible Monthly B security updates taking effect without an immediate restart through Windows Autopatch. It states that VBS must be enabled for a device to be offered Hotpatch updates and explicitly identifies Arm64 device support as public preview. The article also points administrators to Hotpatch quality update reporting.
Driver Updates Policy guidance now asks administrators to assign approval ownership, stage deployments through test groups, align driver and firmware cadences, and ensure each device is targeted by only one driver update policy. It also spells out automatic approval behavior: new recommended drivers are approved and deployed automatically, the prior recommended version moves to the other drivers list, previously approved drivers remain approved, and Windows Update installs only the latest approved version newerกว่า
The revised integration article is retitled Integrate Microsoft Defender for Endpoint with Intune for Device Compliance and explicitly frames Defender as a Mobile Threat Defense solution. It describes real-time device-risk assessment, with compromised high-risk devices automatically marked noncompliant and blocked from corporate resources. The guidance also requires sufficient Intune permissions, citing Endpoint Security Manager as an example; this is clarified integration guidance rather than a launch announcement
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
A new quality update policy article describes Hotpatch security updates that take effect without a restart.
The driver policy guidance now asks administrators to plan how driver and firmware releases are evaluated, approved, and deployed to reduce risk before creating policies.
The Hotpatch guidance now explains that Windows quality update policies can install eligible security updates without requiring an immediate device restart.
Devices without a Windows quality updates policy continue receiving monthly quality updates through Windows Update; update rings and Windows Update client policies still control deferrals, deadlines, restarts, and notifications.
Quality update policies are described as a cloud-orchestrated policy surface that supports direct Intune management or Autopatch, expedited deployments for urgent security needs, and Hotpatch for eligible devices without immediate restart.
When a vulnerability recommendation starts with Expedite at CVSS 9.0 or higher, the remediation agent now directs administrators to the expedite section of the Windows quality update policy guidance.
Recommendations marked Expedite for CVSS 9.0 or higher now direct administrators to the dedicated expedited quality updates guidance.
A new article explains Hotpatch updates and managing them through Windows quality update policies in Intune.
Driver update policy guidance is dated January 13, 2026 and streamlines the initial navigation to Devices, Windows, Manage updates, Windows updates, Driver updates, then Create profile.
The dedicated article is titled Expedite Windows quality updates instead of Windows quality updates policy.
The Hotpatch guidance gains a Hotpatch quality updates report section for monitoring deployment status and errors.
The architecture explanation states that Intune sends identities, policy, approvals, and pause commands; Autopatch configures Windows Update; devices provide diagnostic data and receive approved driver updates.
The article title is now Windows Update rings policy and its description covers creating and managing update ring policies; Intune Plan 1 is linked as the core requirement.
Quality update policies are positioned for advanced deployments such as Hotpatch or Windows Autopatch-managed workflows rather than ordinary monthly servicing.
Feature update policy guidance directs administrators to the Accessing feature updates reports location when confirming that devices reached OfferReady before proceeding.
The article is retitled Manage Windows feature updates and describes using Intune policies to manage Windows feature updates.
The driver update requirements now include the shared cloud prerequisite content.
Feature update guidance recommends setting Feature update deferral period to 0 so an update-ring deferral does not delay the feature update policy.
Feature update policy requirements now include shared cloud environment guidance.
The Windows 10 guidance directs administrators to the feature update policy explanation of multiple policies targeting a device.
Quality update policy requirements now include shared cloud environment guidance.
A separator is removed as Hotpatch reporting guidance is moved into dedicated Hotpatch content.
The quality update policy section is named Expedite Windows quality updates, keeping the same workflow in the consolidated policy guidance.
The Update rings guidance now displays the current update-rings image asset.
The feature update policy description shifts from creating releases to managing Windows feature update policies in Intune.
The quality update overview no longer includes the Hotpatch monitoring and reporting section that described deployment status and errors.
Removed Microsoft Intune documentation in intune/device-updates/windows/quality-updates-policy.md.
The Update Ring policy settings content removes an extra blank separator.
The distribution report is described as a sequence of organizational reports and consistently refers to quality updates when presenting device counts for the selected scope.
Feature update reporting guidance now describes integrated deployment-status reports without repeating data-collection prerequisites, report-only data scope, or latency material.
The driver reporting guidance adds an Accessing driver updates reports section while retaining the statement that its data is used only by driver update reports.
The drill-down report description now refers to Windows feature versions and clarifies that Windows Insider or other releases are grouped when they do not match a generally available Windows feature release and documented quality-update level.
Data retention is promoted to its own section; driver update data remains available for six months after the last event and older versions disappear after no device requires them.
Driver reporting guidance presents Driver updates summary, Driver updates, and Update failures as tabbed views; the driver view continues to show applicable policies for a selected driver across policies.
Feature update reporting content includes the shared Intune admin center link definition used by its navigation guidance.
Report access now starts at Devices > Windows, then Manage updates > Windows updates, before selecting Update rings.
Archive links for feature update reports and expedited quality updates now point to their current report and quality update guidance locations.
Driver report prerequisites now direct administrators to Manage Windows driver updates for the required environment conditions.
The Update rings report illustration now points to the current update-rings image asset.
The quality update reports guidance no longer contains the additional Hotpatch report section.
The iOS/iPadOS purchased-app guidance removes the link for organizations not yet migrated to Apple Business Manager or Apple School Manager.
Tier1 for Intune provides mobile customer relationship management, including client details, interaction history, opportunities, call reports, tasks, meetings, and files through Intune-protected access.
Clarity Express for Intune provides Android and iOS access to work items, progress tracking, and Clarity data while using Intune app protection policies.
Qlik Analytics provides Android and iOS access to cloud analytics, dashboards, offline downloaded analytics, metric alerts, and insight sharing while using Intune app protection policies.
Jump AI supports Android and iOS meeting recording, uploaded recordings, structured notes, meeting review, and recorded-content management under Intune app protection policies.
The Intus scheduling app listing now includes the Android app alongside iOS and describes access to work schedules, availability, hours, shift management, and notifications.
Datadog provides Android and iOS access to alerts, incidents, dashboards, logs, monitor state, and performance metrics while using Intune app protection policies.
Microsoft Defender for Endpoint integration guidance now emphasizes Mobile Threat Defense device compliance and preventing security breaches.
The integration guidance identifies the Microsoft Defender XDR portal for subscription access and threat reports, while retaining the high-risk device flow that lets Intune remove corporate-resource access.
The prerequisites clarify that the administrator needs an Intune role able to configure the settings and cite Endpoint Security Manager as an example.
The onboarding guidance is titled Configure Microsoft Defender for Endpoint with Intune and Onboard Devices.
Updated Microsoft Intune documentation in intune/intune-service/protect/microsoft-defender-with-intune.md.
Updated Microsoft Intune documentation in intune/intune-service/protect/microsoft-defender-with-intune.md.
Updated Microsoft Intune documentation in intune/intune-service/protect/microsoft-tunnel-prerequisites.md.
Windows client planning guidance replaces expedited updates policy references with quality updates policy references.
The Government service description now directs expedited update information to Windows quality updates guidance.
Settings Catalog guidance now links user or device scope to its explanation, retains OS Edition examples, and removes the earlier inclusive multi-management-mode explanation and Android filter tip.
The Settings Catalog note explaining that Edge, Office, and OneDrive settings do not follow Windows OS version or edition filtering is indented beneath the relevant guidance.
The known issue for devices not receiving quality updates during Hybrid Entra joined deployments is removed, and the page date advances to January 13, 2026.
Configuration Manager version 2509 guidance announces that AdminService rejects NTLM authentication.