TipsMake
Newest

Microsoft: Windows Autopatch is the safest way to upgrade business PCs to Windows 11

A few hours ago, Microsoft published guidance for IT admins explaining how to use Intune to upgrade Windows 10 devices to Windows 11, as well as migrate from Active Directory (AD) to a cloud-native system like Entra ID. The company also published a similar guide, but switched to the Windows Autopatch tool, claiming that this is the fastest and safest way to update business computers to Windows 11.

 

For those who don't know, Windows Autopatch is a way to automate updates and empower system administrators to ensure endpoints stay stable and compliant through ring-based, staggered deployments. Administrators also have the ability to easily roll back updates if something goes wrong.

In the current scenario of upgrading business computers to Windows 11 using Autopatch, Microsoft has outlined a 4-step process:

  1. Assessment: Check organization-wide Windows 11 readiness, assign Entra ID groups to devices, and then map these groups to rollout rings in Autopatch.
  2. Grouping: Administrators segment devices into Windows Autopatch groups and define phased deployment policies that are controlled through deployment rings. At a basic level, there are two groups:
    1. The device meets the criteria for Windows 11 and needs to be upgraded to it.
    2. Windows 10 hardware that does not meet the criteria will receive Extended Security Updates (ESUs).
      Devices should be allocated appropriately across different rings, with each group having its own update policy.
  3. Control Pace: Determine how quickly updates are rolled out in phases. This can be managed through the Intune admin center, which lets you control sequencing, pace, and deferrals.
  4. Monitoring: Administrators monitor the Windows 11 update rollout through the Windows Autopatch feature update reporting module. This includes update status on devices, trends in historical views, and troubleshooting guidance.

Microsoft believes that a combination of the Windows Autopatch and Intune teams is the best way to upgrade to Windows 11. Therefore, administrators should start immediately because support for Windows 10 ends on October 14, 2025.

Discover more
Micah Soto
Share by Micah Soto
Update 01 August 2025