A new quality update policy article describes Hotpatch security updates that take effect without a restart.
Hotpatch and expedited quality updates get their own operational playbooks
The Windows update documentation is further decomposed into focused guides for Hotpatch, expedited quality updates, driver-update policy, reporting, and quality-update management. The day also substantially refreshes the Defender for Endpoint–Intune compliance integration guidance.
- Hotpatch guidance is separated from general quality-update policy
Intune · Device updates
A new guide presents Hotpatch as a distinct quality-update capability and groups its eligibility, deployment, and monitoring guidance with the Windows quality-update policy rather than leaving it embedded in broader update documentation.
- Expedited Windows quality updates receive dedicated guidance
Intune · Device updates
The new expedite guide separates urgent quality-update deployment from normal servicing, making the policy’s scope, prerequisites, targeting, and reporting easier to use when responding to a security incident or out-of-band release.
- Defender for Endpoint compliance integration documentation is substantially revised
Intune · Device security
The refreshed integration guide consolidates how Intune uses the Defender for Endpoint connection for device-compliance evaluation and device onboarding, giving security and endpoint teams a single reference to validate their connector and policy design.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
60 updates
Microsoft Intune
58 updatesDriver Updates Policy
UpdatedThe driver policy guidance now asks administrators to plan how driver and firmware releases are evaluated, approved, and deployed to reduce risk before creating policies.
The Hotpatch guidance now explains that Windows quality update policies can install eligible security updates without requiring an immediate device restart.
Quality Updates
UpdatedDevices without a Windows quality updates policy continue receiving monthly quality updates through Windows Update; update rings and Windows Update client policies still control deferrals, deadlines, restarts, and notifications.
Quality update policies are described as a cloud-orchestrated policy surface that supports direct Intune management or Autopatch, expedited deployments for urgent security needs, and Hotpatch for eligible devices without immediate restart.
When a vulnerability recommendation starts with Expedite at CVSS 9.0 or higher, the remediation agent now directs administrators to the expedite section of the Windows quality update policy guidance.
Recommendations marked Expedite for CVSS 9.0 or higher now direct administrators to the dedicated expedited quality updates guidance.
A new article explains Hotpatch updates and managing them through Windows quality update policies in Intune.
Driver update policy guidance is dated January 13, 2026 and streamlines the initial navigation to Devices, Windows, Manage updates, Windows updates, Driver updates, then Create profile.
The dedicated article is titled Expedite Windows quality updates instead of Windows quality updates policy.
The Hotpatch guidance gains a Hotpatch quality updates report section for monitoring deployment status and errors.
Driver Updates
UpdatedThe architecture explanation states that Intune sends identities, policy, approvals, and pause commands; Autopatch configures Windows Update; devices provide diagnostic data and receive approved driver updates.
Windows Update rings policy
UpdatedThe article title is now Windows Update rings policy and its description covers creating and managing update ring policies; Intune Plan 1 is linked as the core requirement.
Quality Updates
UpdatedQuality update policies are positioned for advanced deployments such as Hotpatch or Windows Autopatch-managed workflows rather than ordinary monthly servicing.
Feature Updates Policy
UpdatedFeature update policy guidance directs administrators to the Accessing feature updates reports location when confirming that devices reached OfferReady before proceeding.
The article is retitled Manage Windows feature updates and describes using Intune policies to manage Windows feature updates.
Driver Updates
UpdatedThe driver update requirements now include the shared cloud prerequisite content.
Feature Updates
UpdatedFeature update guidance recommends setting Feature update deferral period to 0 so an update-ring deferral does not delay the feature update policy.
Feature Updates
UpdatedFeature update policy requirements now include shared cloud environment guidance.
Feature Updates Windows 10
UpdatedThe Windows 10 guidance directs administrators to the feature update policy explanation of multiple policies targeting a device.
Quality Updates
UpdatedQuality update policy requirements now include shared cloud environment guidance.
Quality Updates
UpdatedA separator is removed as Hotpatch reporting guidance is moved into dedicated Hotpatch content.
Quality Updates Policy
UpdatedThe quality update policy section is named Expedite Windows quality updates, keeping the same workflow in the consolidated policy guidance.
Update Rings
UpdatedThe Update rings guidance now displays the current update-rings image asset.
The feature update policy description shifts from creating releases to managing Windows feature update policies in Intune.
Quality Updates
UpdatedThe quality update overview no longer includes the Hotpatch monitoring and reporting section that described deployment status and errors.
Quality Updates Policy
RemovedRemoved Microsoft Intune documentation in intune/device-updates/windows/quality-updates-policy.md.
Update Rings Policy Settings
UpdatedThe Update Ring policy settings content removes an extra blank separator.
**QU distribution**
UpdatedThe distribution report is described as a sequence of organizational reports and consistently refers to quality updates when presenting device counts for the selected scope.
Feature update reporting guidance now describes integrated deployment-status reports without repeating data-collection prerequisites, report-only data scope, or latency material.
**Driver updates summary**
UpdatedThe driver reporting guidance adds an Accessing driver updates reports section while retaining the statement that its data is used only by driver update reports.
The drill-down report description now refers to Windows feature versions and clarifies that Windows Insider or other releases are grouped when they do not match a generally available Windows feature release and documented quality-update level.
**Update failures**
UpdatedData retention is promoted to its own section; driver update data remains available for six months after the last event and older versions disappear after no device requires them.
**Driver updates summary**
UpdatedDriver reporting guidance presents Driver updates summary, Driver updates, and Update failures as tabbed views; the driver view continues to show applicable policies for a selected driver across policies.
Feature Updates Reports
UpdatedFeature update reporting content includes the shared Intune admin center link definition used by its navigation guidance.
Update Rings Reports
UpdatedReport access now starts at Devices > Windows, then Manage updates > Windows updates, before selecting Update rings.
Whats New Archive
UpdatedArchive links for feature update reports and expedited quality updates now point to their current report and quality update guidance locations.
Driver Updates Reports
UpdatedDriver report prerequisites now direct administrators to Manage Windows driver updates for the required environment conditions.
Update Rings Reports
UpdatedThe Update rings report illustration now points to the current update-rings image asset.
Quality Updates Reports
UpdatedThe quality update reports guidance no longer contains the additional Hotpatch report section.
Vpp Apps Ios
UpdatedThe iOS/iPadOS purchased-app guidance removes the link for organizations not yet migrated to Apple Business Manager or Apple School Manager.
Tier1 for Intune provides mobile customer relationship management, including client details, interaction history, opportunities, call reports, tasks, meetings, and files through Intune-protected access.
Apps Supported Intune Apps
UpdatedClarity Express for Intune provides Android and iOS access to work items, progress tracking, and Clarity data while using Intune app protection policies.
Apps Supported Intune Apps
UpdatedQlik Analytics provides Android and iOS access to cloud analytics, dashboards, offline downloaded analytics, metric alerts, and insight sharing while using Intune app protection policies.
Apps Supported Intune Apps
UpdatedJump AI supports Android and iOS meeting recording, uploaded recordings, structured notes, meeting review, and recorded-content management under Intune app protection policies.
Apps Supported Intune Apps
UpdatedThe Intus scheduling app listing now includes the Android app alongside iOS and describes access to work schedules, availability, hours, shift management, and notifications.
Apps Supported Intune Apps
UpdatedDatadog provides Android and iOS access to alerts, incidents, dashboards, logs, monitor state, and performance metrics while using Intune app protection policies.
Microsoft Defender for Endpoint integration guidance now emphasizes Mobile Threat Defense device compliance and preventing security breaches.
The integration guidance identifies the Microsoft Defender XDR portal for subscription access and threat reports, while retaining the high-risk device flow that lets Intune remove corporate-resource access.
The prerequisites clarify that the administrator needs an Intune role able to configure the settings and cite Endpoint Security Manager as an example.
The onboarding guidance is titled Configure Microsoft Defender for Endpoint with Intune and Onboard Devices.
Updated Microsoft Intune documentation in intune/intune-service/protect/microsoft-defender-with-intune.md.
Updated Microsoft Intune documentation in intune/intune-service/protect/microsoft-defender-with-intune.md.
Updated Microsoft Intune documentation in intune/intune-service/protect/microsoft-tunnel-prerequisites.md.
Windows client planning guidance replaces expedited updates policy references with quality updates policy references.
The Government service description now directs expedited update information to Windows quality updates guidance.
Copilot
UpdatedSettings Catalog guidance now links user or device scope to its explanation, retains OS Edition examples, and removes the earlier inclusive multi-management-mode explanation and Android filter tip.
Settings Catalog
UpdatedThe Settings Catalog note explaining that Edge, Office, and OneDrive settings do not follow Windows OS version or edition filtering is indented beneath the relevant guidance.
Windows Autopilot
1 updateThe known issue for devices not receiving quality updates during Hybrid Entra joined deployments is removed, and the page date advances to January 13, 2026.
Microsoft Configuration Manager
1 updateWhats New In Version 2509
UpdatedConfiguration Manager version 2509 guidance announces that AdminService rejects NTLM authentication.