# Operate Windows Server 2025 Hotpatch without pretending reboots disappeared

> Windows Server 2025 Hotpatch can remove restarts from many monthly Windows update cycles, but planned and unplanned baselines, .NET, drivers, firmware, and other updates still need maintenance. Build the service around the complete reboot calendar.

- Canonical URL: https://update.dsesecurity.com/updates/operate-windows-server-2025-hotpatch-reboot-cadence/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-08-11T09:25:00+00:00
- Modified: 2026-08-11T14:12:11+00:00
- Last reviewed by DSE: 2026-08-11
- Resource type: Playbook
- DSE priority: Advisory
- Topics: Business Continuity, IT
- Reading time: 3 minutes

## What you need to know

Windows Server 2025 Hotpatch can remove restarts from many monthly Windows update cycles, but planned and unplanned baselines, .NET, drivers, firmware, and other updates still need maintenance. Build the service around the complete reboot calendar.

## Potentially affected

Windows Server 2025 Standard and Datacenter systems connected to Azure Arc; supported Windows Server Datacenter: Azure Edition virtual machines; Azure Update Manager; workloads with constrained maintenance windows.

## DSE recommendation

Inventory eligible servers, verify the documented platform prerequisites, enroll a representative pilot, map baseline and non-Hotpatch restart needs, and approve each cycle only after workload-level validation and recorded recovery evidence.

## Article

## Source facts: Hotpatch changes the cadence, not the operating responsibility

Microsoft describes [Hotpatch for Windows Server](https://learn.microsoft.com/en-us/windows-server/get-started/hotpatch) as a way to apply eligible Windows operating-system updates by patching in-memory code without restarting the server or its processes. For Azure Arc-connected machines, Microsoft currently lists Windows Server 2025 Standard and Datacenter as eligible editions after Hotpatch is enabled. Supported Windows Server Datacenter: Azure Edition images in Azure and Azure Local follow their documented image and orchestration requirements. Custom images, containers, and unlisted offer-and-SKU combinations are not automatically covered by the Azure image support table.

The servicing pattern is built around baselines. A planned baseline uses the current cumulative update and requires a restart. Microsoft describes a typical cycle as a baseline month followed by two Hotpatch months. An unplanned baseline can replace a Hotpatch release when an update cannot be delivered as a Hotpatch, and that baseline also requires a restart. Microsoft therefore presents Hotpatch as fewer restarts, not a restart-free server.

The boundary matters. Microsoft says Hotpatch covers the Windows update content included in its program, while nonsecurity Windows updates, .NET updates, drivers, firmware, and non-Windows updates are outside that Hotpatch scope and can still require conventional installation and restart handling. The documentation also states that Hotpatch updates do not provide automatic rollback; recovery from a problematic Hotpatch can require uninstalling it, installing the last functional baseline, and restarting.

As of this review, Microsoft states that Azure Arc-enabled Hotpatch for eligible Windows Server 2025 machines is available at no extra Hotpatch cost. Azure connectivity, Azure Arc requirements, supported build and edition, virtualization-based security prerequisites, management tooling, and any other Azure services used by the design still need to be confirmed for each environment.

## DSE recommendation: operate one calendar for every update class

Do not divide the server program into “Hotpatch machines” and “machines that need maintenance.” Keep a single maintenance register that shows the next planned baseline, any announced unplanned baseline, .NET servicing, application updates, agents, drivers, firmware, and vendor maintenance for every workload. Hotpatch is a scheduling input within that register.

- Prove eligibility. Record edition, build, installation type, physical or virtual platform, Azure Arc state, required agents, virtualization-based security state, update source, and orchestration owner. Treat portal enrollment as incomplete until the server reports the expected Hotpatch status.

- Use a representative pilot. Include each important application pattern, not merely an idle utility server. Exercise services, scheduled work, integrations, storage, printing, monitoring, backup agents, and any latency-sensitive role after the update.

- Publish a twelve-month restart forecast. Mark expected baseline months and the normal restart window. Reserve a path for unplanned baselines and out-of-band workload maintenance. A forecast is not a promise that a particular month will remain restart-free.

- Separate install success from service health. Capture update status and build, then test the business service through its normal client and dependency path. A successful Windows update record does not prove that the application completed its own recovery.

- Keep recovery executable. Confirm supported backup or recovery methods, application-specific shutdown requirements, the last functional baseline, console access, escalation contacts, and the authority to extend or reverse a change.

- Reconcile exceptions. Servers that miss a baseline, receive an out-of-band update, lose Arc connectivity, or drift from the approved build need an explicit disposition before the next Hotpatch cycle.

Measure the program by avoided workload interruptions, completed baselines, update currency, application test success, exception age, and recovery performance. Do not count “no reboot requested” as the sole success condition. A server can remain online while a dependent service is degraded, and an update outside the Hotpatch scope can still be waiting for a restart.

The durable benefit is predictable servicing: routine eligible months can have less disruption, while baseline and exceptional maintenance remain visible, rehearsed, and owned.

## Official references

- Microsoft Learn, [Hotpatch for Windows Server](https://learn.microsoft.com/en-us/windows-server/get-started/hotpatch), July 14, 2025; documentation reviewed August 11, 2026.

- Microsoft Learn, [Windows Server release information](https://learn.microsoft.com/en-us/windows/release-health/windows-server-release-info), including the current Hotpatch calendar.

## Primary reference

- Name: Microsoft Learn: Hotpatch for Windows Server
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/get-started/hotpatch
- Source publication date: 2025-07-14

## Citation and use

Preferred citation: “Operate Windows Server 2025 Hotpatch without pretending reboots disappeared,” DSE Security, https://update.dsesecurity.com/updates/operate-windows-server-2025-hotpatch-reboot-cadence/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
