Check Windows Autopatch prerequisites before registering production devices

Windows Autopatch eligibility depends on licensing, Intune enrollment, corporate ownership, join and co-management state, recent check-in, Microsoft endpoints, diagnostic data, edition, and update channel.

Executive summary

What you need to know

Windows Autopatch eligibility depends on licensing, Intune enrollment, corporate ownership, join and co-management state, recent check-in, Microsoft endpoints, diagnostic data, edition, and update channel.

Potentially affected

Organizations considering Windows Autopatch for supported corporate-owned Windows 10 or Windows 11 devices managed by Microsoft Intune or supported co-management.

DSE recommendation

Validate tenant and device prerequisites, network and privacy requirements, update authorities, representative pilot readiness, reporting, support ownership, and rollback before registering a production population.

Source fact: what Microsoft documents

Microsoft documents Windows Autopatch availability with Microsoft 365 Business Premium, supported Windows 10 or 11 Education A3/A5 and Enterprise E3/E5 entitlements, eligible Microsoft 365 F3/E3/E5 suites, and Windows Enterprise VDA. Feature and support entitlements differ by subscription. Microsoft Entra ID P1 or P2 and Microsoft Intune are required.

Devices must already be enrolled in Intune before Autopatch registration, or use supported Configuration Manager co-management. Intune must be the mobile-device-management authority, and the Windows Update policies and Device configuration workloads must be assigned to Intune or Pilot Intune for targeted devices. Configuration Manager-only devices are not supported.

Microsoft requires corporate-owned devices; Windows bring-your-own devices are blocked during prerequisite checks. A device must have communicated with Intune within the previous 28 days, have internet connectivity, and reach required Microsoft service endpoints. Tailored deployment protections require diagnostic data at the documented level. Supported Windows client editions use the General Availability Channel. Supported LTSC devices can receive quality-update management, but Autopatch does not offer LTSC feature updates.

Applicability and cautions

Windows edition, architecture, build, channel, licensing, device ownership, Entra join, Intune enrollment, co-management workloads, proxy and firewall configuration, diagnostic-data policy, WSUS scan source, and recent check-in all affect eligibility. Windows 10 support status and individual LTSC lifecycle must be checked. Hotpatching has separate prerequisites. Autopatch automates supported update management; it does not remove the need for application testing, incident ownership, recovery, or business validation.

DSE recommendation: production-safe operational steps

  1. Confirm tenant subscriptions, Entra and Intune entitlements, Autopatch feature coverage, and support rights with current Microsoft product terms.
  2. Export device edition, version, architecture, channel, ownership, join state, Intune enrollment, last check-in, management authority, co-management workloads, and existing update policies.
  3. Identify unsupported BYOD, Configuration Manager-only, stale, LTSC, end-of-support, virtual, kiosk, or specialized devices and define a separate servicing plan.
  4. Validate required Microsoft endpoints through the real proxy, firewall, VPN, DNS, TLS inspection, and branch paths. Record the test and exception owner.
  5. Obtain the required privacy and security approval for diagnostic data and document what features change if the required level is unavailable.
  6. Reconcile WSUS, scan-source, update-ring, feature, quality, driver, firmware, and Configuration Manager settings before registration.
  7. Register a representative pilot, review readiness and update reports, validate business applications and recovery, and expand only after defined exit criteria pass.

DSE recommends preserving the pre-registration configuration and assigning an operator who can pause, correct, or remove a failed pilot. Registration success is not production acceptance; verify actual update installation, restart, application health, endpoint security, and user support outcomes.

Official reference

Windows Autopatch prerequisites — licensing, feature entitlement, Intune and Entra requirements, connectivity, ownership, diagnostic data, editions, channels, and co-management.

Primary reference

Review the official source

Microsoft Learn: Windows Autopatch prerequisites · Published February 27, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE