A new article documents using the Windows quality update policy to deploy Hotpatch security updates through Autopatch, including benefits and prerequisites.
New driver and Hotpatch guidance sharpens Windows update planning
Windows update management dominates the day. New Intune guidance explains driver update approvals and a separate quality update policy introduces Hotpatch deployment requirements, while related update and co-management documentation was refreshed.
- Windows Driver Update Management policy guidance added
Intune · Device updates
The new guide describes automatic approval of recommended drivers, manual approval of every driver, and per-driver pause or reapproval. It also makes clear that only approved, newer drivers install and that the policy relies on Intune and Windows Autopatch.
- Windows quality update policy documents Hotpatch prerequisites
Intune · Device updates
The new policy guide positions Hotpatch as an Autopatch-enabled way to install monthly security updates without a restart. It documents the Windows 11 Enterprise 24H2 baseline, VBS, and Arm64 CHPE requirements, and notes that ineligible devices receive the normal cumulative update.
- Intune roadmap adds management and assignment-filter signals
Intune · Fundamentals
The in-development guidance adds a planned Lenovo Device Orchestration portal link, Android settings-catalog filtering by management mode, Apple declarative device management assignment filters, and more managed-app filter values for Android and iOS/iPadOS.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
21 updates
Microsoft Intune
20 updatesA new consolidated article documents driver update policies: automatic or manual approval, pausing and approving drivers, prerequisites, supported editions, GCC limitations, RBAC, deployment planning, and reporting.
Driver Updates Overview
UpdatedThe driver update overview replaced its telemetry guidance with the shared device-configuration requirements, including enrollment, Entra join state, required telemetry, the Sign-In Assistant service, and Windows Update and Autopatch endpoints.
Index
UpdatedThe overview renamed the Windows Update client policy section and clarified that each update policy type has its own prerequisites, while feature, quality, driver, and Hotpatch use the same backend service as Autopatch.
Feature Updates Windows 10
UpdatedThe guidance for devices ineligible for Windows 11 now points administrators to the central feature update policy workflow for policy behavior, creation, and licensing requirements.
Driver Updates Policy
UpdatedThe driver policy article now links its prerequisite, deployment-planning, and FAQ reference to the renamed driver-updates article.
Feature Updates
UpdatedThe Windows 10-to-Windows 11 upgrade link now directs to the separate feature-updates-windows-10 article rather than an anchor in the main article.
Index
UpdatedThe Windows updates index changed its quality updates Learn more link from quality-updates-policy.md to the renamed quality-updates.md article.
Driver Updates Overview
UpdatedThe driver overview removed the Windows diagnostic-data reporting section and its steps to enable the Windows data setting in Intune.
Driver Updates Overview
RemovedThe former driver-updates-overview.md article was removed as part of the documentation rename to the consolidated driver-updates.md article.
Feature Updates
UpdatedThe article removed the Microsoft Entra registered-device limitations section and its next-steps links, leaving the core policy guidance in the main article.
Quality Updates Policy
RemovedThe former quality-updates-policy.md article was removed as part of the documentation rename to quality-updates.md.
Driver Updates Reports
UpdatedThe driver reports article now states that Windows diagnostic data must be enabled and gives the Intune path: Tenant administration > Connectors and tokens > Windows data, then enable the processor-configuration setting.
Feature Updates Reports
UpdatedThe article removed duplicate device prerequisite text and corrected the organizational-report anchor from Windows 10 feature updates to Windows feature updates.
Whats New Archive
UpdatedThe archived What's New entry now links Windows driver update policy guidance to driver-updates.md instead of driver-updates-overview.md.
The app monitoring article refreshed its wording and clarified several Android AOSP line-of-business app error descriptions and administrator actions, including conflicts, network failures, size limits, and download validation.
The Company Portal article now tells administrators to use `winget install "Company Portal" --source msstore` to download the Windows Company Portal app and its dependencies.
In Development
UpdatedThe in-development entry changed the Android Intune settings catalog settings-list link to a relative documentation path.
Data Enable Windows Data
UpdatedThe Windows diagnostic data page now links the Windows driver updates report to driver-updates.md rather than the retired overview article.
In Development
UpdatedThe in-development page added planned items: an Intune admin center link to Lenovo Device Orchestration for Windows 11, Android settings catalog filtering by management mode, DDM assignment filters for Apple software updates, expanded managed-app device-management filter values, and Zimperium certificate inventory sync.
Microsoft Configuration Manager
1 updateWorkloads
UpdatedThe co-management Windows Update workload guidance now links to the Windows software updates index rather than the former configure page.