Endpoint management
Autopatch
Windows Autopatch
Windows Autopatch is a Microsoft-managed service, included with Windows 11 Enterprise E3/E5 and equivalent Microsoft 365 licensing. It automates the testing and rollout of Windows quality updates, feature updates, Microsoft 365 Apps updates, and Microsoft Edge updates across an organisation's device estate.
Why Autopatch matters in a Microsoft estate
Autopatch matters for endpoint teams because device, app, compliance, update, and troubleshooting signals often sit across several Microsoft admin areas. Linking these terms back to Intune and device-reporting routes helps readers move from definition to action.
How Autopatch shows up in practice
This removes most of the manual scheduling and ring management that update rings otherwise require an admin to configure and monitor by hand. Once a tenant is registered and devices are enrolled, Autopatch automatically organises devices into a sequence of deployment rings, Test, First, Fast, and Broad by default. It progresses each update through them on a managed cadence, watching for update-related health signals, failed installs, boot failures, and other indicators of a problematic release. It can automatically pause or roll back a deployment ring if it detects a spike in failures before the update reaches the broader device population. This is functionally the same problem Windows update rings solve: staged rollout to catch bad updates before they hit everyone.
Autopatch takes the ring design, sequencing, and go/no-go monitoring decisions off the admin's plate, though, which is the trade-off organisations are actually buying: less manual control over exact ring composition and timing, in exchange for less day-to-day update administration overhead. Enrolment prerequisites are stricter than they first appear, and are a common cause of stalled rollouts. Devices need to be Entra ID joined or hybrid joined, co-managed or cloud-managed through Intune, running a supported Windows 11 or Windows 10 Enterprise edition, and meeting specific network and update-source requirements. Autopatch's own readiness checks will flag devices that fail prerequisites like missing update source configuration or conflicting Group Policy settings that override Autopatch's own policies. This conflict is a frequent troubleshooting scenario in estates migrating from a Group Policy or WSUS-managed patching model.
Autopatch does not replace the need for endpoint security policies or compliance policies covering non-Windows-update patching such as third-party application updates. Organisations sometimes assume enrolling in Autopatch means "patching is handled" more broadly than the service actually covers. In reality it is scoped specifically to Windows, Microsoft 365 Apps, Edge, and driver/firmware updates through the optional driver and firmware update policies, leaving third-party software patching a separate responsibility. Because Autopatch pulls its device population directly from Intune-managed groups, the same device hygiene issues that affect Intune generally, stale device records, devices that have left the estate without being retired, duplicate enrolments, directly affect Autopatch ring assignment accuracy and reporting. This means the update compliance dashboards are only as trustworthy as the underlying Intune device inventory feeding them.