Windows Server 2022 Hotpatching: What It Is and How to Enable It

Hotpatching lets Windows Server apply certain security updates directly into a running process’s memory without a reboot, dramatically reducing the number of restart-required patch cycles per year. The catch that trips people up: it currently requires Windows Server 2022 Datacenter: Azure Edition specifically, running as an Azure VM or on Azure Local. It’s not available […]

Windows Server 2022 Hotpatching: What It Is and How to Enable It

Hotpatching lets Windows Server apply certain security updates directly into a running process’s memory without a reboot, dramatically reducing the number of restart-required patch cycles per year. The catch that trips people up: it currently requires Windows Server 2022 Datacenter: Azure Edition specifically, running as an Azure VM or on Azure Local. It’s not available for a standard on-premises Windows Server 2022 install.

How the patch cadence actually works

Hotpatch releases follow a quarterly baseline model: every three months, a traditional cumulative update is released that DOES require a reboot and re-establishes the baseline. In between those quarterly baselines, monthly hotpatches apply security fixes without a reboot at all. So you go from potentially 12 reboot-required patch events a year down to roughly 4, with the months in between getting fully patched without any downtime.

Checking eligibility and enabling it

Hotpatching is enabled per-VM through the Azure portal (under the VM’s Updates blade) or via Azure Update Manager, and only appears as an option on eligible Azure Edition VMs. If you don’t see the option, confirm you’re actually running Windows Server 2022 Datacenter: Azure Edition rather than a standard Datacenter/Standard image migrated to Azure. They look similar in Server Manager but hotpatch eligibility depends on the specific Azure Edition SKU.

What it doesn’t cover

Hotpatching only covers OS-level security updates that Microsoft has specifically enabled for it. It doesn’t extend to driver updates, feature updates, or third-party software patches, which still follow their normal (potentially reboot-requiring) process. Treat it as a meaningful reduction in reboot frequency for core OS patching specifically, not a total elimination of planned maintenance windows.

For official guidance, see Microsoft’s Windows Server documentation.

🛠️

Gear We Recommend

Testing configs is easier with a dedicated admin machine set up right. Here’s the kit we use.

Browse our Windows Admin Toolkit picks on Amazon

As an Amazon Associate, TechyGeeksHome earns from qualifying purchases.


Discover more from TechyGeeksHome

Subscribe to get the latest posts sent to your email.

Andrew Armstrong

Andrew Armstrong is a UK-based IT professional with 26+ years of hands-on experience in Windows, Windows Server, SCCM/ConfigMgr, Intune, Active Directory, PowerShell and enterprise infrastructure.

He founded TechyGeeksHome in 2010 and has published 770+ practical guides to real-world IT problems. He also builds free Windows utilities, including Ultimate Settings Panel, which has been downloaded over 850,000 times.