Windows Autopatch Now Supports Microsoft Business Premium
Summary:
Microsoft's April 2025 Windows Autopatch update is now live for Business Premium tenants at no extra cost. It delivers hotpatching that installs security updates without forcing a restart, a least-privileged access model that applies updates without granting elevated local rights, and security reporting latency cut from roughly 12–14 hours down to under 4 hours. Eligible devices must be corporate-owned, checked into Intune within the last 28 days, and identity-managed through Microsoft Entra ID.
|
What you'll Learn |
|
|
Benefits for MSPs |
|
|
Required Next Steps |
|
For years, Windows Autopatch was a perk reserved for Enterprise E3 customers — out of reach for the small and mid-sized businesses that make up most MSP customer bases. That changed with Microsoft's April 2025 update: Autopatch is now built into Microsoft Business Premium at no extra cost, and it arrived with real improvements, not just a licensing change.
Hotpatching, least-privileged updates, and dramatically faster reporting are already live for eligible Business Premium tenants. Here's what that actually means for the devices you manage.
- Update rolled out: April 2025
- Originally launched (Enterprise E3 only): 2022
- Included with: Microsoft Business Premium
- Reporting latency improvement: ~12–14 hrs → under 4 hrs
- Identity requirement: Microsoft Entra ID (or synced via latest Entra Connect)
Scope and Limitation Statement
Autopatch, via Business Premium, automates OS, Edge, Teams, and M365 Enterprise Apps updates for Intune-enrolled Windows devices under a Least Privileged Access model. It does not cover BYOD or personal devices, devices that haven't checked into Intune in the last 28 days, or non-Windows endpoints such as macOS and mobile, and it doesn't replace third-party patch management for non-Microsoft applications.
Autopatch, Microsoft’s Cloud-based update service for Windows, has just received its April 2025 update – introducing official support for Microsoft Business Premium licenses.
We break down what Autopatch is, what it does, and why this new update is excellent news for users of both Microsoft Business Premium and Inforcer.
What is Windows Autopatch?
Introduced in 2022, Autopatch is Microsoft’s Cloud-based, automated update service for Windows, Microsoft Edge, Microsoft Teams and Microsoft 365 Enterprise Apps. By automating patch testing, deployment schedules, device updates and live conflict monitoring, Autopatch helps IT administrators to significantly streamline their update management.
Crucially, Autopatch doesn’t take authority away from the end user or administrator; managers can still control which devices are enrolled, schedule their own update cadence, and determine their own best practice deployment settings. Essentially: you schedule, Microsoft deploys.
The service – which is offered at no extra cost for Enterprise E3 subscribers – now officially supports Microsoft Business Premium with the arrival of the April update.
Autopatch benefits
That Microsoft has seen fit to bring this premium service to a comparatively mid-range license is commendable - and the key features of this April update suggest they’re committed to helping businesses standardize their protections.
- Hotpatching. While this has been a key feature of Windows Server since 2022, Autopatch’s April update brings Hotpatching client side. Now, users can expect far more security updates without the need for timely system restarts. This alone is a huge productivity boost for end-users.
- A Least Privileged Access model. With Autopatch, Intune now only runs updates that match the permissions of the current signed-in user. Previously, Intune would run at the highest system level – which didn’t always align with users’ zero trust policies.
- Support for all Intune-managed Windows devices, with much faster latency for security reports. Microsoft anticipates a drastic decrease - from 12-14 hours to less than 4 – with the April update.
- Smarter Autopatch group management, which allows administrators to target updates to different departments or groups, each with bespoke update policies.
You can explore these features in greater detail on Microsoft’s IT Pro Blog.
A quick-start guide to Autopatch
A detailed guide on Autopatch, including licensing, infrastructure, and permission requirements, can be found in this Windows Learn article.
In the meantime, some of your key infrastructure requirements include:
- Corporate-owned devices only - BYOD devices are blocked
- Devices must have been in communication with Microsoft Intune in the last 28 days
- Serial Numbers, Models, and Manufacturers of any physical and virtual devices must be specified in Intune
- Network configuration must allow connectivity to Microsoft services
- Microsoft Entra ID must either be the source of authority for all user accounts, or user accounts must be synchronized from on-premises Active Directory using the latest supported version of Microsoft Entra Connect
Scaling Autopatch for inforcer
inforcer is already optimized for Business Premium - so combined with Autopatch, our users can now take advantage of a powerful policy management combination, including:
Wider coverage
inforcer already supports Microsoft update rings, which are used for the phased deployment of Autopatch updates. Now, administrators can standardize deployment schedules and, with inforcer, deploy them to more of their customers than ever before.
Improved security posture
Autopatch’s Least Privileged Access model is consistent with inforcer’s own best practice security policies, so your Microsoft updates are delivered with the high security standards you expect.
Reduced configuration drift
With inforcer managing your policies, and Microsoft managing your update schedule, you have a rigid set of security standards and a regular cadence of updates – making it easier than ever to track the when and why of any policy drifts.
With inforcer, Microsoft partners have effective multi-tenant policy management, helping them to deliver security, productization, and continuity across their customer base. To find out more, book a demo below.
FAQs
Does Windows Autopatch work with Microsoft Business Premium now?
Yes — as of the April 2025 update, Windows Autopatch officially supports Microsoft Business Premium at no additional cost, extending a capability that was previously exclusive to Enterprise E3 subscribers.
What changed in the April 2025 Windows Autopatch update?
The update added client-side hotpatching (security updates without requiring an immediate restart), a Least Privileged Access model where updates run at the user's actual permission level rather than full system privileges, support for all Intune-managed Windows devices, and faster security reporting — cutting latency from roughly 12–14 hours to under 4 hours.
What is hotpatching and does it require a restart?
Hotpatching applies security updates directly on the client without requiring a timely system restart, closing the window where a patched vulnerability sits unapplied simply because a device hasn't rebooted.
What devices are eligible for Windows Autopatch?
Devices must be corporate-owned (BYOD isn't supported), must have checked in with Microsoft Intune within the last 28 days, and need serial number, model, and manufacturer specified in Intune, with network connectivity to Microsoft services and Microsoft Entra ID — or synced on-prem AD via the latest Entra Connect — as the identity source.
Do I need Enterprise E3 to use Autopatch, or does Business Premium work?
Business Premium now works on its own — Autopatch is no longer limited to Enterprise E3 tenants, so MSPs don't need to upsell customers into an Enterprise agreement just to get automated patching.
How does inforcer help MSPs roll out Autopatch across customers?
inforcer's 365 Manager is built to work with Business Premium and supports Microsoft's update rings, letting MSPs phase Autopatch deployment across tenants, target updates by department, and reduce configuration drift compared to managing each tenant's patch policy manually.
Share this
You may also like
These related stories

Microsoft OneDrive Security Update: What MSPs Need to Know

How to Win More Business by Becoming a Microsoft MSP
