{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-266-include-the-arm64-chpe-change-in-a-windows-hotpatch-readiness-review/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-266-include-the-arm64-chpe-change-in-a-windows-hotpatch-readiness-review/",
        "slug": "dse-20260909-266-include-the-arm64-chpe-change-in-a-windows-hotpatch-readiness-review",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-266-include-the-arm64-chpe-change-in-a-windows-hotpatch-readiness-review/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-266-include-the-arm64-chpe-change-in-a-windows-hotpatch-readiness-review.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-266-include-the-arm64-chpe-change-in-a-windows-hotpatch-readiness-review/"
        },
        "title": "Include the Arm64 CHPE change in a Windows hotpatch readiness review",
        "summary": "What Arm64-specific preparation is required before relying on Windows hotpatch?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "managed-it",
            "label": "Managed IT operations",
            "alt": "A controlled technology lifecycle progressing from assessment to approved production.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/managed-it-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/managed-it-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:27:30+00:00",
        "modified_at": "2026-09-10T01:23:48+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 1,
        "word_count": 197,
        "potentially_affected": "Review Arm64 Windows clients proposed for Intune-managed hotpatch. This architecture-specific check supplements, rather than replaces, the current quality-update eligibility and baseline requirements.",
        "dse_recommendation": "Separate Arm64 preparation from the AMD/Intel device plan.",
        "primary_source": {
            "name": "Use Hotpatch With Windows Quality Updates - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/device-updates/windows/configure-hotpatch",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft requires Arm64 devices using hotpatch to disable compiled hybrid PE usage and restart. Hotpatch cannot service CHPE operating-system binaries. This CHPE step does not apply to AMD or Intel processors. Re-enabling CHPE after leaving hotpatch also requires a restart. VBS must also be enabled for a device to receive hotpatch offers. <a href=\"https://learn.microsoft.com/en-us/intune/device-updates/windows/configure-hotpatch\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Review Arm64 Windows clients proposed for Intune-managed hotpatch. This architecture-specific check supplements, rather than replaces, the current quality-update eligibility and baseline requirements.</p>\n<h2>DSE recommendation</h2>\n<p>Separate Arm64 preparation from the AMD/Intel device plan. Have the endpoint owner review the documented CHPE flag and schedule its restart before claiming readiness. Record the intended state if the device later leaves hotpatch, so the return path is not reduced to changing a cloud-policy toggle.</p>\n<h2>Verification</h2>\n<p>Use a representative Arm64 test device and inspect architecture, VBS state, CHPE configuration, and the completed restart. Then confirm the offered and installed update against the approved servicing plan. Preserve actual device evidence without treating a policy assignment as proof that every prerequisite is active. Review application behavior after the preparation change before extending it to more devices.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/device-updates/windows/configure-hotpatch\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Use Hotpatch With Windows Quality Updates</a>.</p>",
        "content_text": "Source facts\nMicrosoft requires Arm64 devices using hotpatch to disable compiled hybrid PE usage and restart. Hotpatch cannot service CHPE operating-system binaries. This CHPE step does not apply to AMD or Intel processors. Re-enabling CHPE after leaving hotpatch also requires a restart. VBS must also be enabled for a device to receive hotpatch offers. Microsoft Learn.\nApplicability\nReview Arm64 Windows clients proposed for Intune-managed hotpatch. This architecture-specific check supplements, rather than replaces, the current quality-update eligibility and baseline requirements.\nDSE recommendation\nSeparate Arm64 preparation from the AMD/Intel device plan. Have the endpoint owner review the documented CHPE flag and schedule its restart before claiming readiness. Record the intended state if the device later leaves hotpatch, so the return path is not reduced to changing a cloud-policy toggle.\nVerification\nUse a representative Arm64 test device and inspect architecture, VBS state, CHPE configuration, and the completed restart. Then confirm the offered and installed update against the approved servicing plan. Preserve actual device evidence without treating a policy assignment as proof that every prerequisite is active. Review application behavior after the preparation change before extending it to more devices.\nOfficial references\nMicrosoft Learn: Use Hotpatch With Windows Quality Updates.",
        "content_markdown": "## Source facts\n\nMicrosoft requires Arm64 devices using hotpatch to disable compiled hybrid PE usage and restart. Hotpatch cannot service CHPE operating-system binaries. This CHPE step does not apply to AMD or Intel processors. Re-enabling CHPE after leaving hotpatch also requires a restart. VBS must also be enabled for a device to receive hotpatch offers. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-updates/windows/configure-hotpatch).\n\n## Applicability\n\nReview Arm64 Windows clients proposed for Intune-managed hotpatch. This architecture-specific check supplements, rather than replaces, the current quality-update eligibility and baseline requirements.\n\n## DSE recommendation\n\nSeparate Arm64 preparation from the AMD/Intel device plan. Have the endpoint owner review the documented CHPE flag and schedule its restart before claiming readiness. Record the intended state if the device later leaves hotpatch, so the return path is not reduced to changing a cloud-policy toggle.\n\n## Verification\n\nUse a representative Arm64 test device and inspect architecture, VBS state, CHPE configuration, and the completed restart. Then confirm the offered and installed update against the approved servicing plan. Preserve actual device evidence without treating a policy assignment as proof that every prerequisite is active. Review application behavior after the preparation change before extending it to more devices.\n\n## Official references\n\n[Microsoft Learn: Use Hotpatch With Windows Quality Updates](https://learn.microsoft.com/en-us/intune/device-updates/windows/configure-hotpatch)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-266-include-the-arm64-chpe-change-in-a-windows-hotpatch-readiness-review/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-266-include-the-arm64-chpe-change-in-a-windows-hotpatch-readiness-review/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-266-include-the-arm64-chpe-change-in-a-windows-hotpatch-readiness-review/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Include the Arm64 CHPE change in a Windows hotpatch readiness review",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-266-include-the-arm64-chpe-change-in-a-windows-hotpatch-readiness-review/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-266-include-the-arm64-chpe-change-in-a-windows-hotpatch-readiness-review/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-266-include-the-arm64-chpe-change-in-a-windows-hotpatch-readiness-review/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-266-include-the-arm64-chpe-change-in-a-windows-hotpatch-readiness-review/",
                "headline": "Include the Arm64 CHPE change in a Windows hotpatch readiness review",
                "description": "What Arm64-specific preparation is required before relying on Windows hotpatch?",
                "abstract": "What Arm64-specific preparation is required before relying on Windows hotpatch?",
                "articleBody": "Source facts\nMicrosoft requires Arm64 devices using hotpatch to disable compiled hybrid PE usage and restart. Hotpatch cannot service CHPE operating-system binaries. This CHPE step does not apply to AMD or Intel processors. Re-enabling CHPE after leaving hotpatch also requires a restart. VBS must also be enabled for a device to receive hotpatch offers. Microsoft Learn.\nApplicability\nReview Arm64 Windows clients proposed for Intune-managed hotpatch. This architecture-specific check supplements, rather than replaces, the current quality-update eligibility and baseline requirements.\nDSE recommendation\nSeparate Arm64 preparation from the AMD/Intel device plan. Have the endpoint owner review the documented CHPE flag and schedule its restart before claiming readiness. Record the intended state if the device later leaves hotpatch, so the return path is not reduced to changing a cloud-policy toggle.\nVerification\nUse a representative Arm64 test device and inspect architecture, VBS state, CHPE configuration, and the completed restart. Then confirm the offered and installed update against the approved servicing plan. Preserve actual device evidence without treating a policy assignment as proof that every prerequisite is active. Review application behavior after the preparation change before extending it to more devices.\nOfficial references\nMicrosoft Learn: Use Hotpatch With Windows Quality Updates.",
                "datePublished": "2026-09-10T00:27:30+00:00",
                "dateModified": "2026-09-10T01:23:48+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-266-include-the-arm64-chpe-change-in-a-windows-hotpatch-readiness-review/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-266-include-the-arm64-chpe-change-in-a-windows-hotpatch-readiness-review/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Include the Arm64 CHPE change in a Windows hotpatch readiness review"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 197,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Use Hotpatch With Windows Quality Updates - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/device-updates/windows/configure-hotpatch"
                }
            }
        ]
    }
}