Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Quick machine recovery is a feature designed to automatically repair Windows devices that become unbootable due to critical large-scale failures or mass outages. If a device fails to boot into the main operating system twice in a row, it attempts recovery through Windows Recovery Environment (WinRE). When this event occurs, Windows enters the Windows Recovery Environment. If Microsoft provides a Quick machine recovery remediation for the outage, Windows downloads and applies it to restore the affected devices.
Windows Autopatch enables administrators to manage and deploy Quick machine recovery updates. You can choose automatic approval of these updates or require manual review and approval before deployment, giving you control over the rollout process.
To learn more about Quick machine recovery, visit Microsoft Learn Quick machine recovery docs.
Default setting
To customize how you want to manage Quick machine recovery updates, set the approval method and deferral period within your Quality update policy. When you create a new Quality update policy, by default, the approval method is set to manual. Available Quick machine recovery fixes are offered to the devices in the policy based on approval method and applicability.
Note
Some devices have Quick machine recovery updates configured both through a Quality update policy (for approval settings) and via CSP or Settings catalog policy (for remote remediation settings). In this case, the devices aren't offered Quick machine recovery until you approve the update. Approvals via cloud policies take precedence over client-side settings.
Manage Quick machine recovery updates
- Go to the Microsoft Intune admin center.
- Navigate to Windows Updates.
- Select Devices > Manage updates > Windows updates > Quality updates.
- Select Create and select Windows quality update policy.
- Under the Basics section, enter a name for your new policy and select Next.
- Under Settings, choose your approval method for Quick machine recovery updates.
- If you choose automatic approval, select Make updates available after days to specify number days to wait before offering updates to devices.
- Select the appropriate Scope tags or leave as Default. Then, select Next.
- Assign the devices to the policy and select Next.
- Review the policy and select Create.
Note
The appoval method cannot be changed in an existing policy. If you need to use a different approval method, you must create a new policy.
Approve and deploy Quick machine recovery updates
- Go to the Microsoft Intune admin center.
- Navigate to Devices > Manage updates > Windows updates > Quality updates.
- Select Manage updates.
- On the Manage quality updates blade, locate the available Quick Machine recovery update under Release column.
- Select a Release name to see details, such as included KBs. Use this information to review the payload before manual approval. Approved policies column displays the number of polices that are approved and those policies that require manual approval.
- Select the X of Y under Approved policies to see which policies are approved or not (marked as Needs review).
- Select the desired policies and select Approve.
You can also manually approve a single policy:
- Navigate to Devices > Manage updates > Windows updates > Quality updates.
- Select an individual policy.
- Select the horizontal ellipses (...) across a Release.
- Select Approve.
Note
If a policy is set to automatic approval with a deferral period, you can manually override the deferral period and approve the update immediately, whenever needed.
Pause a release
You can pause an approved Quick machine recovery update at any time. When paused, Windows Autopatch revokes the approval of the update, and no new devices receive it. Devices that already installed the update aren't rolled back (that is, pausing doesn't uninstall the update). To resume deployment, simply re-approve the update. Windows Autopatch then offers it again to devices that still need it, and offers it again as a newly approved update.
Important
Devices can take up to eight hours to apply new update pause settings.
To pause a cloud-based Quality update deployment:
- Go to the Microsoft Intune admin center.
- Navigate to Devices > Manage updates > Windows updates > Quality updates.
- Select Manage updates.
- On the Manage quality updates blade, select a Release name to manage it. It contains details such as severity and included KBs. Use this information to review the payload before manual approval. The Approved policies column displays the number of polices that have been approved and those that require manual approval.
- Select the X of Y under Approved policies to see which policies are approved.
- Select the policies you want to pause.
- Select Pause.
Consult frequently asked questions about Quick machine recovery in Windows quality updates and .NET Framework updates.