Back to Main Site
Technical Guide

Microsoft Autopatch: The A-to-Z Deployment

1. Prerequisites & Activation

Before beginning, ensure you have the correct licensing (M365 Business Premium, E3/E5). You need Global Administrator access for initial consent and Intune Administrator access to configure the service. Enable Delivery Optimization and diagnostic data collection under your Tenant Administration settings.

Navigate to Tenant administration → Windows Autopatch to activate the service. Once activated, the dashboard will confirm your status.

Autopatch Activation Screen

2. Installing the Client Broker

The Client Broker maintains your Autopatch service. Navigate to Tenant Management under the Autopatch menu, click Manage Client Broker, and select Install. The status will transition from "Not started" to "In progress."

3. Creating Deployment Rings

Planning your rings is critical. While default "First" and "Last" rings exist, you can create additional deployment groups. If using dynamic distribution, ensure your ring percentages sum to exactly 100%.

Autopatch Deployment Rings

4. Configuring Release Schedules

Define your update behavior by setting Deferral days, Deadline days, and Grace periods. For your Test ring, use 0 deferral days for immediate verification. For production rings, allow a 2-day buffer for compatibility signals.

5. Verification & User Experience

On your target devices, navigate to Settings → Accounts → Work or School → Info. Under Policies, you will see the applied Autopatch configurations. In Windows 11, verify these under Windows Update → Advanced options → Configured update policies.

Official References

Discussion & Q&A

Start a Discussion

Loading discussion...