Updates: Windows Autopatch for Windows 365 Cloud PCs

Overview

Windows 365 Cloud PCs need a consistent approach for keeping Windows and Microsoft applications secure and up to date. Microsoft provides two deployment choices:

  • Windows Autopatch — recommended deployment option. A cloud-native service in Microsoft Intune that automates update deployment while retaining customer controls.
  • Configuration Manager with Windows Server Update Services (WSUS) — for traditional or specialized requirements. A customer-managed, on-premises approach for organizations with requirements that Windows Autopatch can't meet.

At a glance: Windows Autopatch provides automated, cloud-based update management with lower operational overhead. Configuration Manager with WSUS provides greater reliance on existing on-premises processes but requires more infrastructure and administration. Choose Windows Autopatch for new Cloud PC deployments unless a validated legacy or specialized requirement prevents its use.

It is recommended to start with Windows Autopatch with Autopatch groups when deploying Cloud PCs, for a cloud-native approach to updates that requires minimal administration.

Windows Autopatch is a cloud service that automates much of the update process. Microsoft manages deployment and rollback, with updates flowing through an intelligent ring-based deployment that you configure at setup (for example, Test → Ring 1 → Ring 2+ → Last). It works with Windows 11 hotpatch, which is enabled by default and delivers quality updates without a restart where supported.

Why Microsoft recommends Windows Autopatch

  • No customer-built update infrastructure — Microsoft owns patch orchestration and ring assignment, with the option to take manual control if needed. Admins don't build or maintain update infrastructure.
  • Ring-based deployment — phased rollout across rings catches issues before they reach the wider estate, and once you set the percentage of devices you want in each ring, Autopatch maintains that as the number of Cloud PCs increases.
  • Hotpatch support on Windows 11 — quality updates are applied without restarting the Cloud PC as often, reducing user disruption.
  • Unified reporting in Intune — one dashboard for update status, compliance, and rollback actions, with integrated alerting.

Configuration Manager: traditional approach

Configuration Manager and Windows Server Update Services provide a traditional, customer-managed approach to Windows update management. This model allows organizations to retain existing operational processes, infrastructure, approval workflows, and update controls already established for physical devices.

If you choose a traditional approach, your team owns the update lifecycle. Configuration Manager results in significant operational trade-offs compared to Windows Autopatch.

When should you consider it?

Configuration Manager and Windows Server Update Services should only be considered where a documented business, technical, security, regulatory, or operational requirement can't be met through Windows Autopatch. Examples may include:

  • Existing enterprise update management processes built around Configuration Manager.
  • Regulatory or change-management requirements requiring highly controlled update approval processes.
  • Transitional migration scenarios where organizations are moving toward a cloud-native operating model but haven't yet modernized update management.

Trade-offs and considerations

  • Windows Server Update Services (WSUS) standalone role is deprecated, though it remains supported until 2034. Configuration Manager's own software update point capability isn't deprecated, so organizations already invested in Configuration Manager can continue using it for on-premises devices. For Cloud PCs specifically, evaluate Windows Autopatch as the preferred update management approach given its cloud-native, lower-overhead model.
  • On-premises infrastructure and Configuration Manager client required. This means your update management isn't cloud-native and can introduce significant complexity and overhead.

Important

Where Configuration Manager may be required, limit it to the affected users or scenarios. Document the workloads involved, the requirement being met, the trade-offs accepted, and the plan to move to the cloud-native model later. Keeping exceptions narrow lets the rest of the deployment retain the benefits of a cloud-native, Zero Trust approach.

Comparison

Capability or requirement Windows Autopatch Configuration Manager and Windows Server Update Services (WSUS)
Recommended use case Recommended Only for specific use cases
Service model Microsoft Managed, with controls Customer managed
Patch orchestration Microsoft Managed Customer managed
Ring-based deployment Microsoft Manage with Autopatch group Customer managed
Reporting Intune reporting Customer managed
Hotpatch (no-reboot updates) on Windows 11 Enabled by default Not supported
Support status Supported Configuration Manager supported; WSUS standalone role deprecated (supported through 2034)

Adoption path

Adopting Windows Autopatch with Windows 365 requires minimal configuration and allows you to retire traditional update infrastructure progressively.

  1. Start with Microsoft gallery images and Windows 11. Gallery images are refreshed monthly by Microsoft and already include Teams optimizations, multimedia redirection, and optional Microsoft 365 Apps. There's no custom image to rebuild every Patch Tuesday. See Images: gallery images for Cloud PCs.
  2. Enroll your Cloud PCs into Windows Autopatch. Assign your Cloud PCs to an Autopatch group (this can be the same group as your physical devices) and let Microsoft handle ring placement. An option exists in the provisioning policy to enable Windows Autopatch for all Cloud PC types (except Windows 365 Flex Cloud PCs in Shared mode and Windows 365 Cloud Apps). However, this adds all Cloud PCs to a single ring (the ring before Last), so we recommend instead allowing Autopatch to handle dynamic distribution by ensuring they're included in your Autopatch groups.
  3. Configure the number of update rings needed for gradual rollout of updates each month — for example, Test → Ring 1 → Ring 2 → Ring 3 → Last — and use dynamic group distribution. For each numbered ring (Ring 1, Ring 2, Ring 3), you can use dynamic group distribution by configuring the percentage of total devices that should be included in that ring, as well as optionally specific devices or device groups. The Test and Last rings can only include specific devices or device groups. Only consider additional Autopatch groups if your organization needs separate ring schedules for different business functions.
  4. Ensure Windows 11 hotpatch is enabled. Hotpatching is enabled by default in Windows Autopatch. Where Cloud PCs run a hotpatch-eligible Windows 11 build, quality updates require fewer restarts and allow for faster compliance. This reduces one of the most visible user disruptions caused by patching.
  5. Consider scheduling reprovisioning of Windows 365 Flex Cloud PCs in Shared mode instead of applying Windows updates. Although it's possible to include these Cloud PCs in Autopatch policies, this may result in an inconsistent experience for users as updates roll out. Scheduling reprovisioning allows the latest gallery image to be applied with the newest Windows quality or feature updates already installed, at a time when users typically aren't using these Cloud PCs in larger numbers.
  6. Keep applications updated through Intune. Deploy updated Win32 apps as needed, so they're versioned and updated independently of the OS baseline.
  7. Monitor through the unified Intune dashboard. Use the Autopatch reports in Intune for compliance, rollout progress, and rollback decisions.

Next steps

With updates automated, establish Microsoft Intune as the management plane for configuration, compliance, and application delivery.