Posted by: kurtsh | November 21, 2025

RELEASE: Windows Autopatch available for GCC

UPDATE 1/7/26:
For GCC customers using M365 G3 or G5, Windows Autopatch doesn’t appear automatically in the suite. To enable Autopatch, customers need to activate their Windows Enterprise entitlement using the $0 Windows Enterprise (OLS) activation SKU.

After the customer’s admin orders the $0 activation SKU from their licensing vendor, they will receive a service activation email confirming that the Windows Enterprise license has been provisioned on the tenant. From there, the admin can assign the licenses to users using multiple methods (i.e., group‑based, seat‑level).

This step ensures the correct Windows service plans, including Autopatch, are provisioned in the tenant and aligns with the typical approach for most Windows Enterprise value in M365 G3/G5 for GCC customers. Once the activation SKU is applied and licenses are assigned, Autopatch will become available and no additional purchase is required.

For step-by-step guidance on how to assign and activate Windows Enterprise licenses, please follow the instructions in this Microsoft Learn article: https://learn.microsoft.com/en-us/windows/deployment/deploy-enterprise-licenses?pivots=windows-11

ORIGINAL POST: 11/21/25
Keep devices at your government organization secure and productive with minimal disruption to users with Windows Autopatch!

MANAGED SERVICE FOR WINDOWS 10/11 PATCHING AT NO ADDITIONAL COST
If you have a Microsoft 365 GCC cloud instance, you will be able to enroll in a true managed service, operated from the Microsoft cloud, fully funded by your Microsoft 365 licensing without any additional cost.

Windows Autopatch provides a rich set of automated patching/update services, driven by Microsoft Intune, that rolls out patches gradually via IT-defined “update rings” to ensure installation is safe, while providing telemetry around machines that do have problems so you can eliminate similar machines from your rollout. Updates can include OS version releases, quality updates, feature updates and drive/firmware updates with comprehensive reporting.

Watch the following introduction to Windows Autopatch through Microsoft Mechanics:

Windows Autopatch includes the following:

  • Windows Autopatch provides control over which content is approved for deployment to which devices through Windows Update.
  • Windows Autopatch groups help you automate a safe rollout process. You can distribute devices into rings and recommend release schedules, leaving you with the final say.
  • Get secure faster with hotpatching: apply security patches without waiting for a restart.
  • Pause or expedite monthly quality updates or drivers for groups of devices in your environment.
  • Simplify update compliance reporting. Windows Autopatch reporting tracks which devices have the latest updates installed with less than 4-hour latency.
  • Manage policy and see reporting through the Microsoft Intune admin center.

DEPLOY WITH FASTTRACK FOR MICROSOFT 365 AT NO ADDITIONAL COST
FastTrack for Microsoft 365 will provide customers both remote planning & guidance for the deployment of both Microsoft Intune & Windows Autopatch through a Deployment Engineer at no additional cost. Contact your Account team for details.

Watch this video from the Windows Autopatch team about how FastTrack for Microsoft 365 can help you get the service deployed:

Resources:

Read more at the announcement post:


Categories