# Check Windows Autopatch prerequisites before registering production devices

> Windows Autopatch eligibility depends on licensing, Intune enrollment, corporate ownership, join and co-management state, recent check-in, Microsoft endpoints, diagnostic data, edition, and update channel.

- Canonical URL: https://update.dsesecurity.com/updates/windows-autopatch-production-prerequisites/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-07-19T21:28:15+00:00
- Modified: 2026-07-19T21:28:15+00:00
- Last reviewed by DSE: 2026-07-19
- Resource type: Checklist
- DSE priority: Advisory
- Topics: Cybersecurity, IT, Microsoft 365 & Identity
- Reading time: 2 minutes

## What you need to know

Windows Autopatch eligibility depends on licensing, Intune enrollment, corporate ownership, join and co-management state, recent check-in, Microsoft endpoints, diagnostic data, edition, and update channel.

## Potentially affected

Organizations considering Windows Autopatch for supported corporate-owned Windows 10 or Windows 11 devices managed by Microsoft Intune or supported co-management.

## DSE recommendation

Validate tenant and device prerequisites, network and privacy requirements, update authorities, representative pilot readiness, reporting, support ownership, and rollback before registering a production population.

## Article

## Source fact: what Microsoft documents

Microsoft documents Windows Autopatch availability with Microsoft 365 Business Premium, supported Windows 10 or 11 Education A3/A5 and Enterprise E3/E5 entitlements, eligible Microsoft 365 F3/E3/E5 suites, and Windows Enterprise VDA. Feature and support entitlements differ by subscription. Microsoft Entra ID P1 or P2 and Microsoft Intune are required.

Devices must already be enrolled in Intune before Autopatch registration, or use supported Configuration Manager co-management. Intune must be the mobile-device-management authority, and the Windows Update policies and Device configuration workloads must be assigned to Intune or Pilot Intune for targeted devices. Configuration Manager-only devices are not supported.

Microsoft requires corporate-owned devices; Windows bring-your-own devices are blocked during prerequisite checks. A device must have communicated with Intune within the previous 28 days, have internet connectivity, and reach required Microsoft service endpoints. Tailored deployment protections require diagnostic data at the documented level. Supported Windows client editions use the General Availability Channel. Supported LTSC devices can receive quality-update management, but Autopatch does not offer LTSC feature updates.

## Applicability and cautions

Windows edition, architecture, build, channel, licensing, device ownership, Entra join, Intune enrollment, co-management workloads, proxy and firewall configuration, diagnostic-data policy, WSUS scan source, and recent check-in all affect eligibility. Windows 10 support status and individual LTSC lifecycle must be checked. Hotpatching has separate prerequisites. Autopatch automates supported update management; it does not remove the need for application testing, incident ownership, recovery, or business validation.

## DSE recommendation: production-safe operational steps

- Confirm tenant subscriptions, Entra and Intune entitlements, Autopatch feature coverage, and support rights with current Microsoft product terms.

- Export device edition, version, architecture, channel, ownership, join state, Intune enrollment, last check-in, management authority, co-management workloads, and existing update policies.

- Identify unsupported BYOD, Configuration Manager-only, stale, LTSC, end-of-support, virtual, kiosk, or specialized devices and define a separate servicing plan.

- Validate required Microsoft endpoints through the real proxy, firewall, VPN, DNS, TLS inspection, and branch paths. Record the test and exception owner.

- Obtain the required privacy and security approval for diagnostic data and document what features change if the required level is unavailable.

- Reconcile WSUS, scan-source, update-ring, feature, quality, driver, firmware, and Configuration Manager settings before registration.

- Register a representative pilot, review readiness and update reports, validate business applications and recovery, and expand only after defined exit criteria pass.

DSE recommends preserving the pre-registration configuration and assigning an operator who can pause, correct, or remove a failed pilot. Registration success is not production acceptance; verify actual update installation, restart, application health, endpoint security, and user support outcomes.

## Official reference

[Windows Autopatch prerequisites](https://learn.microsoft.com/en-us/windows/deployment/windows-autopatch/prepare/windows-autopatch-prerequisites) — licensing, feature entitlement, Intune and Entra requirements, connectivity, ownership, diagnostic data, editions, channels, and co-management.

## Primary reference

- Name: Microsoft Learn: Windows Autopatch prerequisites
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows/deployment/windows-autopatch/prepare/windows-autopatch-prerequisites
- Source publication date: 2026-02-27

## Citation and use

Preferred citation: “Check Windows Autopatch prerequisites before registering production devices,” DSE Security, https://update.dsesecurity.com/updates/windows-autopatch-production-prerequisites/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
