Blog
Microsoft Intune patch management: how to automate Windows updates at scale
Learn how Intune patch management automates Windows updates, Cloud PCs, app patching, and Azure Virtual Desktop images across 1,000+ endpoints.
G2 Names Nerdio a Leader Across Fall 2026 Reports for Desktop as a Service Read the blog
Blog
Learn how Intune patch management automates Windows updates, Cloud PCs, app patching, and Azure Virtual Desktop images across 1,000+ endpoints.
Table of Contents
Patch Tuesday lands, and by Saturday your team is still rebuilding host pools by hand. A scalable Windows patch management process should prevent that cycle. The 2026 Verizon DBIR ranked vulnerability exploitation as the top initial access vector at 31%, which turns the gap between an update shipping and its verified install into a real exposure window. Physical endpoints, Windows 365 Cloud PCs, and Azure Virtual Desktop session hosts each carry different Microsoft Intune policy surfaces.
This guide is for Intune and cloud desktop platform owners running 1,000 or more endpoints across Windows 365 and Azure Virtual Desktop session hosts.
Native Intune automation covers physical endpoints and Cloud PCs directly. Pooled Azure Virtual Desktop session hosts run on a separate image pipeline that native update policies and reports don't reach, so a mixed estate ends up running two servicing workflows that no single native surface can audit together.
Microsoft Intune manages patch policy, while Windows Update distributes approved update packages. WSUS and Configuration Manager once handled both jobs from a local distribution point, pulling update binaries down and pushing them out to devices.
Intune stores your policy assignments and, per Microsoft's documentation, "sends configuration details to Windows Autopatch, which determines which updates are approved for deployment. Devices download approved updates directly from Windows Update."
The native Windows patch management toolkit includes the following policy types:
Devices must be Microsoft Entra ID joined or hybrid joined. Microsoft Entra ID registered devices fall outside feature, quality, and driver update policies. You need a Windows license that includes the Autopatch entitlement. Intune also has third-party patching boundaries, and its update ring policies target supported Windows client editions.
Microsoft is pushing organizations off the Configuration Manager push model toward Intune-based Windows Update control, and co-management keeps both models running during a transition. Once those policy objects exist, the next decision is who operates them.
Windows Autopatch runs the policies as a service. Manual update rings keep the schedule with your team. Which model fits each estate segment depends on how much scheduling control your team needs to keep.
Microsoft describes Windows Autopatch as a cloud service that automates updates for Windows, Microsoft 365 Apps for enterprise, Microsoft Edge, and Microsoft Teams. Since September 17, 2024, Microsoft folded the former Windows Update for Business deployment service into Autopatch, so the backend behind Intune's update policies is now the Autopatch service either way.
An Autopatch group bundles Microsoft Entra ID groups and update policies into one unit. Autopatch then automates three operational tasks. It distributes devices into groups and configures each content type's approval strategy. It also sets each ring's rollout schedule. You assign devices to Autopatch deployment rings, but per a Microsoft Q&A response, you "don't have control over when updates are pushed to devices, or when they move from one ring to another."
Autopatch supports up to 300 Autopatch groups with up to 15 deployment rings each. Ring membership requires explicitly included static Entra ID groups, and dynamic and filtered groups aren't supported. Pause and resume operate at the ring level only, and per-device control doesn't exist.
With manual update rings, every configuration and policy assignment becomes your team's standing work. A workable enterprise pattern uses three rings. IT sits at zero-day deferral, then a pilot ring at 10 days. Broad production sits at 30 days, which gives you a full change window to catch a bad update before it reaches the bulk of the estate.
Autopatch fits segments that prioritize standardization over schedule control, and manual rings fit the ones with a committed maintenance window. Either model now inherits a Microsoft default that changed underneath it.
Starting with the May 2026 update, Windows Autopatch enables hotpatch by default for all eligible devices, while a tenant-level opt-out has been available in the Intune admin center since April 1, 2026. Devices outside any quality update policy inherit that default, while devices inside one keep their configured behavior. For platform teams, eligibility now determines whether restart planning follows the hotpatch cadence or the standard quality update path.
Hotpatch updates apply monthly security fixes to the in-memory code of running processes, so devices take the update without a restart; hotpatch reached general availability on Windows 11 Enterprise, version 24H2 for x64 devices on April 2, 2025. Baseline updates that require a restart ship quarterly, with restart-free hotpatch updates in the intervening months, though Microsoft's 2026 calendar deviates from that quarterly pattern in some months and lists no hotpatch for version 26H1.
Eligible devices must meet these hotpatch requirements.
That default changes the restart profile of your Windows fleet. Hotpatch does nothing for the applications sitting on top of Windows.
Intune covers non-Microsoft application updates through three separate routes, and no universal policy spans them. None of the routes updates apps installed on a device outside Intune.
Microsoft Store apps update automatically once you deploy them through the Store integration. Self-packaged Win32 apps update through Win32 supersedence, capped at 10 nodes in a supersedence relationship. The Enterprise App Management catalog covers a Microsoft-maintained set of prepackaged Win32 apps, installed through the Intune management extension rather than WinGet.
Auto-update for catalog apps applies only to Required assignments. Microsoft's Intune Enterprise App Management guidance states that when a new version publishes, "it goes out to all targeted devices at the same time rather than through phased deployment groups." The feature shipped in service release 2606 the week of June 29, 2026. Intune caches catalog data for up to one hour, so a version revoked for a security issue can stay exposed that long.
Apps outside the catalog still need repackaging for every new version. Per Microsoft's own guidance, "if you manually installed the apps instead of deploying them via Intune, you cannot update them via Intune." That leaves a standing repackaging queue covering whichever line-of-business apps your users actually depend on.
The Microsoft Intune Suite and, from July 1, 2026, Microsoft 365 E5 include Enterprise App Management. Outside those bundles, as of July 2026, Enterprise App Management carries a US list price of $2.00 per user per month paid yearly, on top of an Intune Plan 1 or Plan 2 base license. Nerdio Manager for Enterprise extends catalog coverage with WinGet-based deployment and updates.
All three routes assume a device Intune can target directly. Cloud desktops require different targeting and servicing workflows on each path.
Cloud PCs patch through native Intune and Windows Autopatch. Pooled Azure Virtual Desktop multi-session hosts patch through image replacement because most Intune update policies don't apply to them.
Every Cloud PC enrolls in Intune automatically at provisioning, and Windows Autopatch supports Cloud PCs with no feature difference from physical devices. Windows 365 Enterprise is also a hotpatch-eligible license. The Cloud PC side still carries the full Intune update and application workload for every provisioned desktop.
Administrators can manage Azure Virtual Desktop through the Azure Portal, PowerShell, and Microsoft Intune, although multi-session update policy support remains limited. For pooled multi-session environments, Microsoft recommends making the image the servicing unit.
Update ring policies aren't supported on Windows Enterprise multi-session, and unsupported policies report as "Not applicable." Only a short list of Settings Catalog quality update settings remains. Windows Update for Business reports have a known issue and display no data for multi-session devices, while Microsoft doesn't support in-place OS version upgrades for pooled host pools at all. Those constraints center pooled-host patching on image replacement.
Microsoft recommends image-based replacement in four steps.
Handling updates through a golden image "ensures absolute consistency, eliminates configuration drift, and prevents performance degradation caused by background update processes while users are working."
The Session Host Update feature, now generally available, batches that replacement across a host pool that uses a session host configuration, and Microsoft Marketplace multi-session images refresh monthly after the Windows Servicing and Delivery security patch release. Azure Virtual Desktop custom image templates use Azure Image Builder to create custom images, and Nerdio Manager adds scheduled image patching and versioning.
A mixed estate pairs policy-driven servicing for physical endpoints and Cloud PCs with an image pipeline for multi-session hosts. Many enterprises run Windows 365 and Azure Virtual Desktop together, so both pipelines run at once. Neither one shows up cleanly in the same report.
Native update reporting runs on Windows diagnostic data that uploads roughly once per day and processes in batches: "The maximum end-to-end latency is approximately 52 hours" per Microsoft. So if a change advisory board asks on Wednesday morning whether Tuesday night's update actually landed, the report cannot answer yet.
Feature update reports fully represent only devices enrolled in an Autopatch feature update policy, while devices managed by update rings "may not appear in the Autopatch feature update status report, which makes the device count look lower." A July 2026 case documented 96.5% of devices showing the July update installed in the deployment drill-down while the security update summary widgets showed zero devices up to date. A Microsoft moderator attributed the gap to reporting classification rather than a failed deployment.
NIST SP 800-40 Rev. 4 treats verifying that an update actually installed as part of the patching cycle, the step a 52-hour reporting delay and a multi-session blind spot both undermine. Automated patch tooling supports the requirements of CIS Control 7, which names authorized automated patch management software as an input for assessing its safeguards.
Because multi-session hosts are missing from those reports, an Azure Virtual Desktop-heavy estate can't be assessed from that surface alone. With up to 52 hours of latency, Intune reports alone cannot verify your current patch state.
Nerdio Manager extends the native Microsoft stack, so policies stay native Intune policies with automation on top. The capabilities below bring patching workflows for both Windows 365 and Azure Virtual Desktop paths into one console.
Cloud PC lifecycle management handles restarts and resizing for Windows 365 Enterprise Cloud PCs. A configuration policy change or an SSO profile change applies to a Cloud PC without a full reprovision, so fixing a misconfiguration doesn't cost the user their desktop.
Nerdio Manager provides daily Intune policy backups, retains those backups for 30 days, and supports manual point-in-time backups before a risky change. You can compare two policy versions side by side, then restore the policy, its assignments, or both. Microsoft does not provide built-in backup and restore for Intune policies, so restoring a bad edit to a quality update policy requires an external backup and restore workflow.
An optional RBAC approval workflow gates policy creation and assignment. Windows driver approvals run from the same console.
Unified Application Management automates app deployment and updates using WinGet repositories alongside Intune, including the third-party software outside Microsoft's catalog. Deployments initialize through the Microsoft Intune agent, so app policies apply on the agent refresh cycle.
For Windows 365 Cloud PCs, Unified Application Management can deploy applications in about 30 seconds, compared with up to three hours through native Intune delivery. Assignments support an automatic sync mode that updates an app whenever a new version is available, and Shell Apps handle large or complex installers through PowerShell in device system context.
Because Intune enrolls Cloud PCs during provisioning, the same automatic sync path covers them and physical endpoints, without supersedence chains running against the 10-node ceiling.
Nerdio Manager's desktop orchestration automates golden image patching and versioning for session hosts, including personal desktops. Scheduled golden image updates build and distribute in the background. New hosts roll into the pool while old hosts move through drain mode and deallocation.
An independent Dr. Tritsch benchmark found updating a custom image took 37 seconds and 13 clicks in Nerdio Manager versus 5 minutes 9 seconds and 146 clicks natively. The benchmark measures both admin time and manual inputs. Fewer manual inputs means fewer chances for one host to drift from the image the rest of the pool is running.
That unified console keeps policy and update state from living in separate surfaces. You define and manage the Intune policy and image-replacement workflows in one console across desktop types. What you can automate natively, though, now depends on which bundle your users sit in.
For annual subscriptions at US list price, Microsoft raised Microsoft 365 E3 by $3 to $39 per user per month and E5 by $3 to $60, effective July 1, 2026. E5 now includes the advanced Intune Suite capabilities, including the Enterprise App Management entitlement covered earlier, while E3 gains Intune Plan 2, Remote Help, and Advanced Analytics.
Three checks belong on the next review cycle.
The interval between an update shipping and its installation being verified everywhere is the exposure window your patching design either shrinks or leaves open, and it is what keeps a team rebuilding host pools on a Saturday.
Across a 1,000-endpoint estate, patching still splits across the Intune admin center, a hand-run image pipeline, and a manual exception list for many teams. Get a demo to see how Nerdio Manager works across your Windows 365 and Azure Virtual Desktop environment, or try it free in your Azure tenant.
Yes, for Windows updates. Intune manages quality, feature, and driver updates through policy, and devices download approved updates directly from Windows Update. Third-party coverage is narrower, and Intune's Windows update policies target supported Windows client editions rather than Windows Server.
For Windows update policy controls, both use Intune update policies; the difference is who operates them. Windows Autopatch also automates updates for Microsoft 365 Apps for enterprise, Microsoft Edge, and Microsoft Teams, creates and maintains update policies, distributes devices into deployment rings, and controls rollout timing as a service. With manually managed update rings, you keep scheduling control.
No, not for multi-session hosts. Update ring policies aren't supported on Windows Enterprise multi-session, unsupported policies report as "Not applicable," and only a limited set of Settings Catalog quality update settings apply. Microsoft recommends patching the golden image and replacing session hosts.
Teams can largely automate Windows updates and supported catalog applications, but the full estate still spans separate workflows. Windows Autopatch automates Windows, Microsoft 365 Apps for enterprise, Microsoft Edge, and Microsoft Teams updates. Hotpatch lets eligible devices on the current baseline apply qualifying updates without a restart, and Enterprise App Management auto-update covers catalog apps. Custom image creation is available through Azure Virtual Desktop custom image templates, but golden-image lifecycle management and applications outside the catalog remain separate native workflows that Nerdio Manager can automate.
Learn more about Nerdio Manager