Updated Microsoft Intune documentation in intune/intune-service/protect/security-baseline-settings-mdm-all.md.
Windows Autopatch hotpatching defaults change in May; Intune opt-out opens today
The most consequential notice is a planned Windows Autopatch behavior change: hotpatch updates will be enabled by default for eligible devices starting with the May 2026 Windows security update, while an Intune opt-out becomes available on April 1. The period also clarifies the RHEL 8 support deadline and documents supported macOS LAPS enrollment and Windows expedite-policy behavior. Several remaining edits are mechanical link, punctuation, or formatting changes.
- Hotpatch becomes the Windows Autopatch default in May
Intune · Apple
The updated Intune What's new entry says hotpatch updates will be enabled by default for all eligible devices managed through Windows Autopatch starting with the May 2026 Windows security update. A tenant-level opt-out is available in the Intune admin center on April 1, 2026. Alternatively, a quality update policy can control hotpatch behavior for a specific device group, and that policy overrides the tenant-level setting.
- RHEL 8 support is stated to end in July 2026
Intune · Windows
The What's new text changes the status from “Support for RHEL 8 LTS has ended” to “Support for RHEL 8 LTS will end in July 2026.” Devices already enrolled on RHEL 8 remain enrolled. Administrators can find them under Devices > All devices by filtering OS to Linux and adding OS version columns; Intune supports RHEL 9 LTS and RHEL 10 LTS.
- macOS LAPS enrollment guidance distinguishes initial setup from re-enrollment
Intune · Device enrollment
The macOS LAPS page now states that ADE enrollments occurring during the initial device setup experience are supported. ADE enrollment scenarios re-initiated from an existing macOS installation, such as using the `profiles renew` command, aren't supported. This is a documentation clarification of the supported enrollment path, not a newly announced LAPS capability.
- Expedite Policy documentation clarifies which updates appear in the selector
Intune · Device updates
The updated guidance says the drop-down displays the two most recent security updates, including out-of-band security updates. Non-security updates appear only when no newer security update exists; when eligible, the list includes the latest non-security update and the previous non-security update only if that previous release was out of band. This documents selection logic rather than announcing a new policy feature.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
9 updates
Microsoft Intune
9 updatesUpdated Microsoft Intune documentation in intune/intune-service/protect/security-baseline-settings-mdm-all.md.
Whats New
UpdatedUpdated Microsoft Intune documentation in intune/intune-service/fundamentals/whats-new.md.
In Development
UpdatedUpdated Microsoft Intune documentation in intune/intune-service/fundamentals/in-development.md.
Whats New
UpdatedUpdated Microsoft Intune documentation in intune/intune-service/fundamentals/whats-new.md.
Updated Microsoft Intune documentation in intune/intune-service/enrollment/macos-laps.md.
Expedite Policy
UpdatedUpdated Microsoft Intune documentation in intune/device-updates/windows/expedite-policy.md.
Scope Tags
UpdatedUpdated Microsoft Intune documentation in intune/intune-service/fundamentals/scope-tags.md.
Whats New
UpdatedUpdated Microsoft Intune documentation in intune/intune-service/fundamentals/whats-new.md.