# Include the Arm64 CHPE change in a Windows hotpatch readiness review

> What Arm64-specific preparation is required before relying on Windows hotpatch?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-266-include-the-arm64-chpe-change-in-a-windows-hotpatch-readiness-review/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:27:30+00:00
- Modified: 2026-09-10T01:23:48+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 1 minutes

## What you need to know

What Arm64-specific preparation is required before relying on Windows hotpatch?

## Potentially affected

Review Arm64 Windows clients proposed for Intune-managed hotpatch. This architecture-specific check supplements, rather than replaces, the current quality-update eligibility and baseline requirements.

## DSE recommendation

Separate Arm64 preparation from the AMD/Intel device plan.

## Article

## Source facts

Microsoft requires Arm64 devices using hotpatch to disable compiled hybrid PE usage and restart. Hotpatch cannot service CHPE operating-system binaries. This CHPE step does not apply to AMD or Intel processors. Re-enabling CHPE after leaving hotpatch also requires a restart. VBS must also be enabled for a device to receive hotpatch offers. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-updates/windows/configure-hotpatch).

## Applicability

Review Arm64 Windows clients proposed for Intune-managed hotpatch. This architecture-specific check supplements, rather than replaces, the current quality-update eligibility and baseline requirements.

## DSE recommendation

Separate Arm64 preparation from the AMD/Intel device plan. Have the endpoint owner review the documented CHPE flag and schedule its restart before claiming readiness. Record the intended state if the device later leaves hotpatch, so the return path is not reduced to changing a cloud-policy toggle.

## Verification

Use a representative Arm64 test device and inspect architecture, VBS state, CHPE configuration, and the completed restart. Then confirm the offered and installed update against the approved servicing plan. Preserve actual device evidence without treating a policy assignment as proof that every prerequisite is active. Review application behavior after the preparation change before extending it to more devices.

## Official references

[Microsoft Learn: Use Hotpatch With Windows Quality Updates](https://learn.microsoft.com/en-us/intune/device-updates/windows/configure-hotpatch).

## Primary reference

- Name: Use Hotpatch With Windows Quality Updates - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/device-updates/windows/configure-hotpatch
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Include the Arm64 CHPE change in a Windows hotpatch readiness review,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-266-include-the-arm64-chpe-change-in-a-windows-hotpatch-readiness-review/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
