# Windows Server 2025 Hotpatch: Azure Arc Setup and Baselines

Source: https://srvscripts.com/guides/windows-server-2025-hotpatch/
Updated: 2026-10-06
Publisher: srvScripts (https://srvscripts.com/)

**Short answer:** Hotpatch lets Windows Server 2025 Standard and Datacenter install most monthly security updates without a restart. On-premises and other-cloud servers need to be connected to Azure Arc, run build 26100.1742 or later, boot with UEFI and Secure Boot, and have Virtualization-Based Security running; then you enable Hotpatch on the machine in the Azure Arc portal. Microsoft now lists Arc-enabled Hotpatch for Windows Server 2025 as available at no extra cost. You still restart for baseline cumulative updates, planned in the first month of each quarter, plus any unplanned baselines.

Commands checked against the official documentation (linked below) on 6 October 2026; not yet run on our lab servers.

## How Hotpatch works

Hotpatch patches the in-memory code of running processes, so the security fix takes effect without restarting the server or its applications. It runs on a quarterly cycle:

- **Baseline month** (planned for January, April, July and October): a normal cumulative update that requires a restart.

- **Hotpatch months**: the two months after each baseline receive hotpatch-only security updates with no restart.

- **Unplanned baselines**: when a fix cannot ship as a hotpatch (for example an urgent zero-day), Microsoft replaces that month’s hotpatch with a baseline, which needs a restart.

That last point matters for planning. Microsoft’s Windows Server hotpatch calendar for 2026 shows baselines (restart) in January, April, June, July, September and October, with hotpatch-only months in February, March, May and August, so this year had two unplanned baselines on top of the four planned ones. Check the calendar each month rather than assuming a fixed pattern.

What Hotpatch does not cover, according to Microsoft: non-security Windows updates, .NET updates, and non-Windows updates such as drivers and firmware. Those still need a restart when you install them. Hotpatches also cannot be rolled back automatically: to back one out you uninstall it and reinstall the last good baseline, which requires a restart.

## Requirements and cost

| Requirement | Detail |
| --- | --- |
| Edition | Windows Server 2025 Standard or Datacenter (Desktop Experience or Server Core). Datacenter: Azure Edition has Hotpatch on by default and does not need Arc. |
| Build | 26100.1742 or later. Insider and preview builds are not supported. |
| Firmware | UEFI with Secure Boot enabled. On Hyper-V that means a generation 2 VM. |
| Virtualization-Based Security | VBS (Virtual Secure Mode) must be running. |
| Azure | An Azure subscription and the Azure Connected Machine agent (the server is “Arc-enabled”), with network access per the agent prerequisites. |
| Cost | Microsoft’s Hotpatch documentation states that Arc-enabled Hotpatch for Windows Server 2025 is now available at no extra cost. It was previously a paid subscription. Other Arc services you enable on the same machine may still be billed, so check Azure Cost Management. |

Windows Server 2022 Hotpatch is limited to specific Azure and Azure Local images (Datacenter: Azure Edition); it is not available through Arc for on-premises 2022 servers.

## Step 1: check build and VBS on the server

Check the OS build:

```
$cv = Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion'
"{0} build {1}.{2}" -f $cv.ProductName, $cv.CurrentBuildNumber, $cv.UBR
Confirm-SecureBootUEFI
```

The build must be 26100 with UBR 1742 or higher, and `Confirm-SecureBootUEFI` must return `True`. Then check whether VBS is running, using Microsoft’s command:

```
Get-CimInstance -Namespace 'root/Microsoft/Windows/DeviceGuard' -ClassName 'win32_deviceGuard' | Select-Object -ExpandProperty 'VirtualizationBasedSecurityStatus'
```

`2` means VBS is configured and running. Anything else means it needs enabling. VBS may already be on if you use Credential Guard (on by default for domain-joined Server 2025 machines that are not DCs) or HVCI.

### Enable VBS if needed

Turning on VBS changes how the hypervisor loads and needs a restart. Test on one server per hardware model or VM template first: some older drivers and some virtualization platforms need extra settings (for example, VMware requires VBS to be enabled on the VM itself).

```
New-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\DeviceGuard' -Name 'EnableVirtualizationBasedSecurity' -PropertyType 'Dword' -Value 1 -Force
```

Restart, then rerun the `win32_deviceGuard` query. If it still does not return `2`, the physical or virtual hardware requirements for VBS are not met; check the hardware or hypervisor vendor’s documentation. Group Policy can enable VBS fleet-wide through Credential Guard or HVCI settings instead of the registry.

## Step 2: connect the server to Azure Arc

In the Azure portal go to **Azure Arc > Machines > Add/Create**, choose a single server or at-scale onboarding, pick the subscription, resource group and region, and download the generated script. Run it on the server as administrator; it installs the Azure Connected Machine agent and registers the machine. Check the agent afterwards:

```
azcmagent show
```

The output should show the agent status as connected. If your servers reach the internet through a proxy, configure it in the agent before connecting, and allow the endpoints listed in the Connected Machine agent network requirements.

## Step 3: enable Hotpatch

- In the Azure portal open **Azure Arc > Machines** and select the server.

- Select **Hotpatch**, then **Confirm**.

- Wait about 10 minutes. The portal checks that VSM/VBS is running; if it is not, enabling fails.

- If the status stays **Pending**, follow the Azure Arc agent troubleshooting guidance.

From then on, Windows Update offers hotpatch packages in hotpatch months and normal cumulative updates in baseline months. You can keep using Windows Update with Group Policy, SConfig on Server Core, or Azure Update Manager to schedule installs. If you use WSUS today, test how your approval process handles hotpatch packages before relying on it; Microsoft lists Azure Update Manager, Group Policy, SConfig and non-Microsoft tools as supported options.

## Plan restarts around baselines

- Keep your normal maintenance window, but expect to use it at least four times a year instead of twelve, plus any unplanned baselines.

- Stay on the exact update levels Microsoft lists. In late 2025 Microsoft warned that installing a particular October out-of-band update moved servers off the hotpatch track until the next baseline. Installing an off-track update means monthly restarts until the next baseline.

- Still restart for .NET, driver and firmware updates. Hotpatch does not remove the need for those windows.

- Track the calendar on the Windows Server release information page each month.

## Check that it worked

```
Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 5 HotFixID, Description, InstalledOn
(Get-CimInstance Win32_OperatingSystem).LastBootUpTime
```

- The Arc machine page in the portal shows Hotpatch enabled.

- In a hotpatch month, the security update KB from the hotpatch calendar installs and `LastBootUpTime` does not change.

- In Azure Update Manager, the machine shows as compliant for that month’s update.

## Common problems

- **Enabling Hotpatch fails in the portal.** VBS is not running (query returns something other than 2), or the machine is not on build 26100.1742 or later.

- **Server keeps getting full cumulative updates in hotpatch months.** It is on an update level that is not the current baseline (for example an out-of-band update), or Hotpatch is not actually enabled. It returns to hotpatches after the next baseline.

- **Status stuck on Pending.** Connected Machine agent connectivity; run `azcmagent check` and review the agent troubleshooting article.

- **VM will not start VBS.** Generation 1 Hyper-V VM, Secure Boot off, or nested virtualization not exposed where required.

**Official documentation:** [Hotpatch for Windows Server](https://learn.microsoft.com/en-us/windows-server/get-started/hotpatch) · [Enable Hotpatch for Azure Arc-enabled servers](https://learn.microsoft.com/en-us/windows-server/get-started/enable-hotpatch-azure-arc-enabled-servers) · [Windows Server hotpatch calendar](https://learn.microsoft.com/en-us/windows/release-health/windows-server-release-info#windows-server-hotpatch-calendar)

**Related:** [WSUS Windows Server 2025: Reliable Install and Configuration](/guides/wsus-windows-server-2025/) · [Windows Update Group Policy: 7 Settings for Windows 11](/guides/windows-update-group-policy/) · [Windows Server 2025 In-Place Upgrade: Safe Steps from 2012 R2 to 2022](/guides/windows-server-2025-in-place-upgrade/) · [KernelCare Setup on cPanel and DirectAdmin: Reliable Patching](/guides/kernelcare-setup-cpanel-directadmin/) · [A basic RMM monitoring policy for small-business endpoints: disk, patching and antivirus](/guides/rmm-monitoring-policy-endpoints/)

**See also:** [Windows 10 ESU After October 2026: Year 2 Options for IT](/guides/windows-10-esu-after-october-2026/)

## Frequently asked questions

### Does Hotpatch mean I never restart Windows Server 2025?

No. Baseline months need a restart, planned once a quarter, and unplanned baselines add more. .NET, driver and firmware updates still need restarts too.

### Is Hotpatch free for on-premises Windows Server 2025?

Microsoft’s documentation now states that Azure Arc-enabled Hotpatch for Windows Server 2025 is available at no extra cost. The server still has to be connected to Azure Arc.

### Can I use Hotpatch without Azure Arc?

Only on Windows Server Datacenter: Azure Edition, where it is built in. Standard and Datacenter editions on-premises need Azure Arc.

### Does Hotpatch work on Windows Server 2022 on-premises?

No. Hotpatch for 2022 is limited to specific Azure Edition images on Azure and Azure Local.

### Can I uninstall a hotpatch?

There is no automatic rollback. Uninstall the update and install the last working baseline, which requires a restart.
