Skip to main content

G2 Names Nerdio a Leader Across Fall 2026 Reports for Desktop as a Service Read the blog

Blog

Microsoft Intune patch management: how to automate Windows updates at scale

Learn how Intune patch management automates Windows updates, Cloud PCs, app patching, and Azure Virtual Desktop images across 1,000+ endpoints.

Patch Tuesday lands, and by Saturday your team is still rebuilding host pools by hand. A scalable Windows patch management process should prevent that cycle. The 2026 Verizon DBIR ranked vulnerability exploitation as the top initial access vector at 31%, which turns the gap between an update shipping and its verified install into a real exposure window. Physical endpoints, Windows 365 Cloud PCs, and Azure Virtual Desktop session hosts each carry different Microsoft Intune policy surfaces.

This guide is for Intune and cloud desktop platform owners running 1,000 or more endpoints across Windows 365 and Azure Virtual Desktop session hosts.

Native Intune automation covers physical endpoints and Cloud PCs directly. Pooled Azure Virtual Desktop session hosts run on a separate image pipeline that native update policies and reports don't reach, so a mixed estate ends up running two servicing workflows that no single native surface can audit together.

How Intune manages Windows patching through policy

Microsoft Intune manages patch policy, while Windows Update distributes approved update packages. WSUS and Configuration Manager once handled both jobs from a local distribution point, pulling update binaries down and pushing them out to devices.

Intune stores your policy assignments and, per Microsoft's documentation, "sends configuration details to Windows Autopatch, which determines which updates are approved for deployment. Devices download approved updates directly from Windows Update."

The native Windows patch management toolkit includes the following policy types:

  • Update rings control client update behavior, with quality update deferrals of 0 to 30 days, feature update deferrals of 0 to 365 days, plus installation deadline and restart grace period settings.
  • Feature update policies lock devices to a specific Windows release, or target an upgrade while preventing devices from moving past it.
  • Quality update policies cover standard monthly rollout, expedited installation that bypasses deferrals for zero-day response, and hotpatch.
  • Driver update policies operate in automatic or manual mode. In automatic mode, they approve recommended drivers after a configurable 0-to-30-day delay. In manual mode, nothing installs until you approve it.

Devices must be Microsoft Entra ID joined or hybrid joined. Microsoft Entra ID registered devices fall outside feature, quality, and driver update policies. You need a Windows license that includes the Autopatch entitlement. Intune also has third-party patching boundaries, and its update ring policies target supported Windows client editions.

Microsoft is pushing organizations off the Configuration Manager push model toward Intune-based Windows Update control, and co-management keeps both models running during a transition. Once those policy objects exist, the next decision is who operates them.

Windows Autopatch or your team runs the update schedule

Windows Autopatch runs the policies as a service. Manual update rings keep the schedule with your team. Which model fits each estate segment depends on how much scheduling control your team needs to keep.

How Windows Autopatch runs the schedule for you

Microsoft describes Windows Autopatch as a cloud service that automates updates for Windows, Microsoft 365 Apps for enterprise, Microsoft Edge, and Microsoft Teams. Since September 17, 2024, Microsoft folded the former Windows Update for Business deployment service into Autopatch, so the backend behind Intune's update policies is now the Autopatch service either way.

An Autopatch group bundles Microsoft Entra ID groups and update policies into one unit. Autopatch then automates three operational tasks. It distributes devices into groups and configures each content type's approval strategy. It also sets each ring's rollout schedule. You assign devices to Autopatch deployment rings, but per a Microsoft Q&A response, you "don't have control over when updates are pushed to devices, or when they move from one ring to another."

Autopatch group and ring limits

Autopatch supports up to 300 Autopatch groups with up to 15 deployment rings each. Ring membership requires explicitly included static Entra ID groups, and dynamic and filtered groups aren't supported. Pause and resume operate at the ring level only, and per-device control doesn't exist.

When manual update rings still fit

With manual update rings, every configuration and policy assignment becomes your team's standing work. A workable enterprise pattern uses three rings. IT sits at zero-day deferral, then a pilot ring at 10 days. Broad production sits at 30 days, which gives you a full change window to catch a bad update before it reaches the bulk of the estate.

Autopatch fits segments that prioritize standardization over schedule control, and manual rings fit the ones with a committed maintenance window. Either model now inherits a Microsoft default that changed underneath it.

Hotpatch is now on by default, and your quality update policies decide who gets it

Starting with the May 2026 update, Windows Autopatch enables hotpatch by default for all eligible devices, while a tenant-level opt-out has been available in the Intune admin center since April 1, 2026. Devices outside any quality update policy inherit that default, while devices inside one keep their configured behavior. For platform teams, eligibility now determines whether restart planning follows the hotpatch cadence or the standard quality update path.

Hotpatch updates apply monthly security fixes to the in-memory code of running processes, so devices take the update without a restart; hotpatch reached general availability on Windows 11 Enterprise, version 24H2 for x64 devices on April 2, 2025. Baseline updates that require a restart ship quarterly, with restart-free hotpatch updates in the intervening months, though Microsoft's 2026 calendar deviates from that quarterly pattern in some months and lists no hotpatch for version 26H1.

Eligible devices must meet these hotpatch requirements.

  • Windows 11, version 24H2 or later, on the current baseline release, starting at Build 26100.2033 on x64 (AMD or Intel) hardware; Arm64 devices must disable compiled hybrid PE (CHPE)
  • Virtualization-based Security (VBS) enabled and running
  • A hotpatch-enabled Windows quality update policy in Intune
  • A qualifying license: Windows 11 Enterprise E3 or E5, Microsoft 365 F3 or Business Premium, Windows 11 Education A3 or A5, or Windows 365 Enterprise

That default changes the restart profile of your Windows fleet. Hotpatch does nothing for the applications sitting on top of Windows.

Where Intune's third-party app patching stops

Intune covers non-Microsoft application updates through three separate routes, and no universal policy spans them. None of the routes updates apps installed on a device outside Intune.

Three routes cover non-Microsoft apps

Microsoft Store apps update automatically once you deploy them through the Store integration. Self-packaged Win32 apps update through Win32 supersedence, capped at 10 nodes in a supersedence relationship. The Enterprise App Management catalog covers a Microsoft-maintained set of prepackaged Win32 apps, installed through the Intune management extension rather than WinGet.

Enterprise App Management auto-update has no rollback or phased rollout

Auto-update for catalog apps applies only to Required assignments. Microsoft's Intune Enterprise App Management guidance states that when a new version publishes, "it goes out to all targeted devices at the same time rather than through phased deployment groups." The feature shipped in service release 2606 the week of June 29, 2026. Intune caches catalog data for up to one hour, so a version revoked for a security issue can stay exposed that long.

Apps outside the catalog need repackaging every version

Apps outside the catalog still need repackaging for every new version. Per Microsoft's own guidance, "if you manually installed the apps instead of deploying them via Intune, you cannot update them via Intune." That leaves a standing repackaging queue covering whichever line-of-business apps your users actually depend on.

The Microsoft Intune Suite and, from July 1, 2026, Microsoft 365 E5 include Enterprise App Management. Outside those bundles, as of July 2026, Enterprise App Management carries a US list price of $2.00 per user per month paid yearly, on top of an Intune Plan 1 or Plan 2 base license. Nerdio Manager for Enterprise extends catalog coverage with WinGet-based deployment and updates.

All three routes assume a device Intune can target directly. Cloud desktops require different targeting and servicing workflows on each path.

Windows 365 and Azure Virtual Desktop patch on different paths

Cloud PCs patch through native Intune and Windows Autopatch. Pooled Azure Virtual Desktop multi-session hosts patch through image replacement because most Intune update policies don't apply to them.

Cloud PCs stay on the native Intune and Autopatch path

Every Cloud PC enrolls in Intune automatically at provisioning, and Windows Autopatch supports Cloud PCs with no feature difference from physical devices. Windows 365 Enterprise is also a hotpatch-eligible license. The Cloud PC side still carries the full Intune update and application workload for every provisioned desktop.

Pooled multi-session hosts move servicing into the image

Administrators can manage Azure Virtual Desktop through the Azure Portal, PowerShell, and Microsoft Intune, although multi-session update policy support remains limited. For pooled multi-session environments, Microsoft recommends making the image the servicing unit.

Update ring policies aren't supported on Windows Enterprise multi-session, and unsupported policies report as "Not applicable." Only a short list of Settings Catalog quality update settings remains. Windows Update for Business reports have a known issue and display no data for multi-session devices, while Microsoft doesn't support in-place OS version upgrades for pooled host pools at all. Those constraints center pooled-host patching on image replacement.

Microsoft recommends image-based replacement in four steps.

  1. Patch and capture a golden image that includes your applications and FSLogix configuration on the target Windows version.
  2. Add new session hosts from the updated image to the existing host pool.
  3. Set the existing session hosts to drain mode.
  4. Remove the old VMs and deallocate them.

Handling updates through a golden image "ensures absolute consistency, eliminates configuration drift, and prevents performance degradation caused by background update processes while users are working."

The Session Host Update feature, now generally available, batches that replacement across a host pool that uses a session host configuration, and Microsoft Marketplace multi-session images refresh monthly after the Windows Servicing and Delivery security patch release. Azure Virtual Desktop custom image templates use Azure Image Builder to create custom images, and Nerdio Manager adds scheduled image patching and versioning.

A mixed estate runs both pipelines at once

A mixed estate pairs policy-driven servicing for physical endpoints and Cloud PCs with an image pipeline for multi-session hosts. Many enterprises run Windows 365 and Azure Virtual Desktop together, so both pipelines run at once. Neither one shows up cleanly in the same report.

Patch reporting lags the estate it describes

Native update reporting runs on Windows diagnostic data that uploads roughly once per day and processes in batches: "The maximum end-to-end latency is approximately 52 hours" per Microsoft. So if a change advisory board asks on Wednesday morning whether Tuesday night's update actually landed, the report cannot answer yet.

Feature update reports fully represent only devices enrolled in an Autopatch feature update policy, while devices managed by update rings "may not appear in the Autopatch feature update status report, which makes the device count look lower." A July 2026 case documented 96.5% of devices showing the July update installed in the deployment drill-down while the security update summary widgets showed zero devices up to date. A Microsoft moderator attributed the gap to reporting classification rather than a failed deployment.

NIST SP 800-40 Rev. 4 treats verifying that an update actually installed as part of the patching cycle, the step a 52-hour reporting delay and a multi-session blind spot both undermine. Automated patch tooling supports the requirements of CIS Control 7, which names authorized automated patch management software as an input for assessing its safeguards.

Because multi-session hosts are missing from those reports, an Azure Virtual Desktop-heavy estate can't be assessed from that surface alone. With up to 52 hours of latency, Intune reports alone cannot verify your current patch state.

How Nerdio Manager automates patching across Windows 365, Intune, and Azure Virtual Desktop

Nerdio Manager extends the native Microsoft stack, so policies stay native Intune policies with automation on top. The capabilities below bring patching workflows for both Windows 365 and Azure Virtual Desktop paths into one console.

Cloud PC lifecycle management for Windows 365

Cloud PC lifecycle management handles restarts and resizing for Windows 365 Enterprise Cloud PCs. A configuration policy change or an SSO profile change applies to a Cloud PC without a full reprovision, so fixing a misconfiguration doesn't cost the user their desktop.

Intune policy backup, versioning, and approval control

Nerdio Manager provides daily Intune policy backups, retains those backups for 30 days, and supports manual point-in-time backups before a risky change. You can compare two policy versions side by side, then restore the policy, its assignments, or both. Microsoft does not provide built-in backup and restore for Intune policies, so restoring a bad edit to a quality update policy requires an external backup and restore workflow.

An optional RBAC approval workflow gates policy creation and assignment. Windows driver approvals run from the same console.

Third-party application patching through Unified Application Management

Unified Application Management automates app deployment and updates using WinGet repositories alongside Intune, including the third-party software outside Microsoft's catalog. Deployments initialize through the Microsoft Intune agent, so app policies apply on the agent refresh cycle.

For Windows 365 Cloud PCs, Unified Application Management can deploy applications in about 30 seconds, compared with up to three hours through native Intune delivery. Assignments support an automatic sync mode that updates an app whenever a new version is available, and Shell Apps handle large or complex installers through PowerShell in device system context.

Because Intune enrolls Cloud PCs during provisioning, the same automatic sync path covers them and physical endpoints, without supersedence chains running against the 10-node ceiling.

Desktop orchestration for Azure Virtual Desktop session hosts

Nerdio Manager's desktop orchestration automates golden image patching and versioning for session hosts, including personal desktops. Scheduled golden image updates build and distribute in the background. New hosts roll into the pool while old hosts move through drain mode and deallocation.

An independent Dr. Tritsch benchmark found updating a custom image took 37 seconds and 13 clicks in Nerdio Manager versus 5 minutes 9 seconds and 146 clicks natively. The benchmark measures both admin time and manual inputs. Fewer manual inputs means fewer chances for one host to drift from the image the rest of the pool is running.

That unified console keeps policy and update state from living in separate surfaces. You define and manage the Intune policy and image-replacement workflows in one console across desktop types. What you can automate natively, though, now depends on which bundle your users sit in.

What to re-check after the July 2026 licensing changes

For annual subscriptions at US list price, Microsoft raised Microsoft 365 E3 by $3 to $39 per user per month and E5 by $3 to $60, effective July 1, 2026. E5 now includes the advanced Intune Suite capabilities, including the Enterprise App Management entitlement covered earlier, while E3 gains Intune Plan 2, Remote Help, and Advanced Analytics.

Three checks belong on the next review cycle.

  • Which devices sit inside a quality update policy, and which inherited the May 2026 hotpatch default.
  • Whether Autopatch or manual rings still fits each estate segment, now that the defaults and the entitlements have moved.
  • The monthly hours your team spends on the Azure Virtual Desktop image pipeline, which is your automation business case.

The interval between an update shipping and its installation being verified everywhere is the exposure window your patching design either shrinks or leaves open, and it is what keeps a team rebuilding host pools on a Saturday.

Across a 1,000-endpoint estate, patching still splits across the Intune admin center, a hand-run image pipeline, and a manual exception list for many teams. Get a demo to see how Nerdio Manager works across your Windows 365 and Azure Virtual Desktop environment, or try it free in your Azure tenant.

Frequently asked questions about Intune patch management

Ready to get started?