Feature Update vs. Cumulative Update vs. Hotpatch, Explained
Windows Update uses several names that sound as though they describe the same thing:
- Feature update
- Quality update
- Cumulative update
- Security update
- Preview update
- Hotpatch
- Baseline update
- Out-of-band update
They all change Windows, but they differ substantially in purpose, size, timing and whether the computer needs to restart.
The simplest distinction is:
- A feature update moves the PC to a newer Windows release and begins a new support lifecycle.
- A cumulative update services the Windows release already installed, adding security fixes, reliability improvements and earlier fixes.
- A hotpatch update applies eligible monthly Windows security fixes without requiring an immediate restart—but only on supported, properly managed devices.
Hotpatch does not replace feature updates or cumulative updates completely. It changes how some monthly security updates are applied between scheduled baseline updates.
The At-a-Glance Comparison
Update type | Main purpose | Typical frequency | Changes Windows version? | Restart normally required? |
Feature update | Introduces a new Windows release, features and platform changes | Usually annually | Yes | Yes—often several restarts |
Cumulative update | Adds security and reliability fixes to the current release | Monthly | No | Usually |
Hotpatch update | Applies eligible monthly security fixes to running Windows code | During eligible hotpatch months | No | No for the hotpatch itself |
Baseline update | Establishes the foundation required for later hotpatches | Normally quarterly | No | Yes |
Windows 11 normally receives one annual feature update in the second half of the calendar year. Monthly security updates are generally released on the second Tuesday of each month and are cumulative.
What Is a Feature Update?
A feature update moves Windows from one release to another.
For example:
Windows 11 24H2 → Windows 11 25H2
The name identifies the release period:
- 24H2 means the second half of 2024.
- 25H2 means the second half of 2025.
- 26H1 means the first half of 2026.
A feature update can introduce or change:
- Windows security capabilities
- User-interface features
- Management options
- Hardware support
- Accessibility features
- Servicing components
- Built-in applications
- Drivers
- Recovery tools
- Platform requirements
It also starts a new support lifecycle for that release. Microsoft provides 24 months of support for Windows 11 Home and Pro releases and 36 months for Enterprise and Education releases.
Feature updates are larger migrations
A feature update does more than replace a few files.
Windows Setup may need to migrate:
- User accounts
- Applications
- Drivers
- Security settings
- Windows services
- Device configuration
- Recovery partitions
- Boot files
That is why feature updates take longer and may restart the computer several times.
The process normally includes:
- Compatibility assessment
- Download and preparation
- Offline installation
- Driver and application migration
- User-data migration
- Final setup
- Cleanup of the previous release
Windows usually retains rollback information temporarily so it can restore the previous version if installation fails.
A higher version number is not always an upgrade for every PC
Microsoft’s current Windows 11 version 26H1 is an important example.
Although its number is higher than 25H2, Microsoft says 26H1 is intended for new devices released in early 2026. It is not designed as an in-place feature update for existing 24H2 or 25H2 computers.
Therefore, an existing PC remaining on 25H2 is not necessarily missing an update.
Always check whether the particular release is intended for your device and deployment path.
How to Recognise a Feature Update
Open:
Settings > Windows Update > Update history
Look under:
Feature Updates
You might see an entry such as:
Feature update to Windows 11, version 25H2
You can confirm the installed version by pressing:
Windows key + R
and running:
winver
A successful feature update normally changes both:
- The version, such as 24H2 to 25H2
- The main OS build family
What Is a Cumulative Update?
A cumulative update services the Windows version already installed.
It may include:
- Security vulnerability fixes
- Reliability improvements
- Bug fixes
- Previously released changes
- Servicing-stack improvements
- Selected Windows feature enhancements
The word cumulative is important.
Each update incorporates the fixes from earlier updates for the same Windows release. Installing the latest applicable cumulative update generally brings the device up to date without requiring every previous monthly package to be installed individually.
For example:
January update:
Fixes A, B and C
February update:
Fixes A, B, C, D and E
March update:
Fixes A, B, C, D, E and F
Installing March’s applicable cumulative update gives the device the earlier fixes as well.
The Monthly Security Update
Microsoft calls its regular second-Tuesday update the monthly security update release, sometimes informally called the B release because it appears during the second week of the month.
It contains:
- New security fixes
- Previous security fixes
- Relevant reliability improvements
- Applicable non-security changes released earlier
Microsoft normally publishes this release on the second Tuesday of each month.
An entry might look like:
2026-07 Cumulative Update for Windows 11 Version 25H2
(KB50xxxxx)
Installing it normally increases the complete OS build revision while leaving the Windows version unchanged.
For example:
Before:
Version 25H2
OS Build 26200.7000
After:
Version 25H2
OS Build 26200.8117
The device remains on 25H2, but its servicing level has changed.
Does a Cumulative Update Require a Restart?
Normally, yes.
A cumulative update replaces Windows components that may already be loaded into memory. Windows needs to restart so it can complete the replacement safely before those components begin running again.
The restart may also complete:
- Boot-component servicing
- Kernel changes
- Driver replacement
- Registry operations
- Servicing-stack work
- Pending file changes
Occasionally, an update may complete without a restart, but businesses should plan normal cumulative-update deployment around restart requirements.
What Is an Optional Preview Update?
Microsoft may release an optional non-security preview update, traditionally called a D release, around the fourth Tuesday of the month.
It provides early access to non-security fixes expected to be included in a later monthly security update.
You may see it under:
Settings > Windows Update > Advanced options > Optional updates
A preview update can be useful when:
- It fixes a problem currently affecting you.
- Your IT team needs to test next month’s changes.
- Microsoft specifically recommends it as a workaround.
It does not need to be installed simply because it appears.
For a stable business PC, waiting for those fixes to arrive through the normal monthly security update may be more appropriate.
What Is an Out-of-Band Update?
An out-of-band, or OOB, update is released outside Microsoft’s normal monthly schedule.
It may address:
- A severe security vulnerability
- A widespread printing problem
- An authentication failure
- A boot or recovery issue
- A significant regression caused by an earlier update
Microsoft releases OOB updates as required rather than on a fixed date.
An OOB package may also be cumulative, so its release notes should be checked before separately removing or installing earlier packages.
What Is a Checkpoint Cumulative Update?
Beginning with Windows 11 version 24H2, Microsoft introduced checkpoint cumulative updates.
A checkpoint acts as a newer servicing foundation. Updates released after it can contain smaller incremental differences measured from that checkpoint rather than from the original Windows release. This can reduce update size, installation time, network use and storage requirements.
For computers receiving updates through:
- Windows Update
- Windows Update for Business
- Windows Server Update Services
the required checkpoints are handled automatically.
Administrators manually downloading packages from the Microsoft Update Catalog may need to install preceding checkpoint packages in the correct order.
For an ordinary user, a checkpoint cumulative update is still part of normal monthly Windows servicing. It is not a separate Windows version.
What Is Hotpatch?
Hotpatch applies eligible Windows security fixes without requiring the device to restart.
Instead of waiting for the next boot to replace every active component, Windows can patch supported operating-system code as it is loaded or running in memory.
Microsoft defines Windows 11 hotpatch updates as monthly B-release security updates that install and take effect without requiring a restart. Hotpatch is an extension of Windows Update and is managed for Windows 11 through Windows Autopatch and Microsoft Intune.
The benefits include:
- Fewer disruptive restarts
- Faster security compliance
- Smaller update packages
- Reduced network bandwidth
- Shorter installation times
- Less interruption to users
Hotpatch is particularly useful for organisations where employees may postpone restarts or where interruptions affect productivity.
Hotpatch Does Not Mean “Never Restart Again”
Hotpatch relies on a normal cumulative baseline update.
The baseline installs the complete current servicing foundation and requires a restart. Later hotpatches apply security changes on top of that baseline without another restart.
Microsoft’s planned Windows hotpatch cycle is:
Quarter | Baseline month — restart required | Hotpatch months — no restart required |
Q1 | January | February and March |
Q2 | April | May and June |
Q3 | July | August and September |
Q4 | October | November and December |
Microsoft may occasionally release an additional baseline outside this schedule when security requirements make it necessary.
A business using hotpatch should therefore expect:
- At least four planned update restarts each year
- Restart-free eligible security updates in the intervening months
- Possible additional restart requirements when circumstances demand them
Users can still restart a hotpatched PC whenever they choose. Restarting does not remove the installed hotpatch.
What Does a Baseline Update Contain?
A baseline is a standard cumulative update containing:
- Current security fixes
- Cumulative non-security improvements
- Servicing enhancements
- The foundation required for the next hotpatch sequence
It requires a restart.
The hotpatches that follow contain eligible security content but do not carry the same full set of cumulative features and non-security changes.
This is why hotpatch supplements the standard servicing model rather than replacing it.
Who Can Receive Hotpatch?
Hotpatch is not a normal consumer switch available on every Windows 11 PC.
Microsoft’s current prerequisites include:
- An eligible business or education licence
- Windows 11 version 24H2 or later
- The latest applicable baseline update
- Microsoft Intune management
- A Windows quality-update policy with hotpatch enabled
- Virtualisation-based security running
Eligible licensing listed by Microsoft includes Windows 11 Enterprise E3 or E5, Microsoft 365 F3, Windows 11 Education A3 or A5, Microsoft 365 Business Premium and Windows 365 Enterprise.
Arm64 devices can also receive hotpatch, but they have additional compatibility requirements involving CHPE and legacy 32-bit x86 applications.
What Happens When a Device Is Not Eligible?
A device assigned to a hotpatch policy may temporarily or permanently fail one of the eligibility checks.
For example:
- VBS is not running.
- The latest baseline is missing.
- The Windows version is unsupported.
- The licence is not eligible.
- The device is not correctly managed.
- An Arm64 compatibility requirement is not met.
Microsoft does not simply leave that PC unprotected.
An ineligible device receives the normal latest cumulative update instead. The standard update contains the required monthly security and non-security servicing content but requires a restart.
This fallback is important. Hotpatch eligibility affects the servicing method, not whether the device should receive security updates.
How Can You Tell Whether Hotpatch Is Enabled?
On a managed device, open:
Settings > Windows Update > Advanced options > Configured update policies
Look for:
Enable hotpatching when available
This indicates that Windows Autopatch has enrolled the device in a policy allowing rebootless updates.
After eligible hotpatch installations, Windows Update may display:
Great news! The latest security update was installed without a restart.
Microsoft also assigns a different KB number and OS build to the hotpatch release than to the standard restart-requiring cumulative update.
IT administrators can confirm status through:
- Microsoft Intune quality-update policies
- Hotpatch quality-update reports
- Windows Autopatch alerts
- Device update status
- Windows Event Viewer
Why Did One PC Receive Hotpatch While Another Needed a Restart?
Two devices in the same organisation may receive different forms of the same month’s security servicing.
Possible reasons include:
- One device is missing the latest baseline.
- VBS is disabled or not running.
- One PC has not received the hotpatch policy.
- The computers have different licences.
- One device was upgraded during a hotpatch month.
- An Arm64 device has an incompatible configuration.
- One machine has fallen outside update-policy requirements.
When a Windows version upgrade is performed during a hotpatch month, the PC can switch temporarily to standard servicing until the next baseline. Microsoft recommends considering the baseline cycle when scheduling feature upgrades for hotpatch-managed devices.
Can a Hotpatch Be Uninstalled?
Yes, but uninstalling it requires a restart.
Microsoft does not support automatic rollback of a hotpatch. Where a hotpatch causes an unexpected problem, an administrator can remove it, install the standard latest cumulative update and restart the device.
This should be managed carefully because:
- The device may temporarily lose the removed security protection.
- The replacement cumulative update must be installed.
- A reboot is required.
- The issue should be documented and investigated.
Business users should not remove hotpatch updates locally without contacting IT.
Feature Updates and Hotpatch Serve Different Purposes
A hotpatch does not upgrade:
Windows 11 24H2 → Windows 11 25H2
It services the Windows release already installed.
A feature update still has to be deployed separately when the organisation is ready to move to the next supported Windows release.
Likewise, receiving hotpatches does not extend the underlying Windows feature version beyond its normal support lifecycle.
A device must still move to a supported release before its current version reaches end of servicing.
Cumulative Update and Hotpatch Are Closely Related
It is easy to treat them as completely separate update families, but hotpatch is better understood as another delivery method for eligible monthly security servicing.
During a normal cumulative-update month:
Download update
Install update
Restart
Complete servicing
During an eligible hotpatch month:
Download smaller hotpatch
Install update
Patch supported running Windows code
No immediate restart
During the next baseline month:
Download full cumulative baseline
Install update
Restart
Begin next hotpatch cycle
Hotpatch reduces restart frequency. It does not remove the need for cumulative baselines.
Which Updates Should Home Users Expect?
A normal personal Windows 11 PC will generally receive:
- Annual feature updates when eligible
- Monthly cumulative security updates
- Optional non-security preview updates when selected
- Driver and Defender updates
- Occasional out-of-band updates
It will normally not receive the managed Windows Autopatch hotpatch cycle described above.
For a home user, a monthly restart after the standard cumulative security update remains normal.
Which Updates Should Business Users Expect?
The answer depends on how the organisation manages Windows.
A conventionally managed business PC may receive:
- Annual feature updates
- Monthly cumulative updates
- Managed driver updates
- Optional or expedited updates
- Planned restarts
An eligible hotpatch-managed device may instead receive:
- Feature updates according to the organisation’s deployment plan
- Quarterly cumulative baseline updates with restarts
- Hotpatch security updates during eligible intervening months
- Standard cumulative updates whenever it is temporarily ineligible
- Emergency or additional baseline updates where required
The organisation still needs:
- Update policies
- Pilot groups
- Restart deadlines
- Compliance reporting
- Compatibility testing
- BitLocker recovery readiness
- Rollback procedures
Hotpatch reduces disruption, but it does not remove update management.
Common Misunderstandings
“A feature update is just a large cumulative update”
Feature updates are cumulative in the sense that they include previous fixes, but they also move the device to a different Windows release and start a new support lifecycle.
“Cumulative means the update keeps getting larger forever”
The servicing model is cumulative, but technologies such as express installation and checkpoint cumulative updates reduce the amount of content a particular device needs to download.
“Hotpatch installs every kind of Windows change without a reboot”
Hotpatch focuses on eligible Windows security fixes. Baselines, feature updates and some exceptional security changes still require restarts.
“Hotpatch means my computer never has to restart”
Quarterly baselines require restarts, and Microsoft can issue extra baseline updates when necessary.
“If hotpatch fails, the PC receives no security update”
Eligible policy-managed devices that cannot receive hotpatch are offered the standard latest cumulative update instead.
“Installing the latest feature update means I can skip monthly updates”
Feature updates and monthly servicing solve different problems. A supported Windows release still needs its cumulative security updates.
“Optional preview updates are required”
Preview updates are normally for early validation or for obtaining a relevant non-security fix before the next standard security release.
A Practical Windows Update Checklist
When reviewing Windows updates:
- Run winver.
- Record the current Windows version and full OS build.
- Open Windows Update history.
- Identify whether the item is a feature, cumulative, preview or hotpatch update.
- Check the KB number.
- Read Microsoft’s release notes.
- Back up important files before a feature update.
- Save the BitLocker recovery key.
- Allow restart time for feature and baseline updates.
- Do not assume every optional preview must be installed.
- Check safeguard holds before forcing a feature update.
- Verify drivers and firmware before a major version upgrade.
- Check Intune policy and VBS status when hotpatch is expected.
- Confirm that ineligible hotpatch devices received the normal cumulative update.
- Monitor installation and compliance across business devices.
- Investigate repeated failures rather than pressing Retry continuously.
How Hamilton Group Can Help
The update itself is only one part of the process.
Businesses also need to know:
- Which devices are eligible
- Which applications are compatible
- Which computers require restarts
- Which updates have failed
- Whether security deadlines have been met
- Whether a Windows version is approaching end of support
Hamilton Group’s experienced IT team can help with:
Windows Version Management
We can identify devices running:
- Old Windows feature releases
- Unsupported versions
- Unexpected editions
- Incomplete upgrades
- Insider or preview builds
Cumulative Update Deployment
Hamilton Group can manage:
- Monthly security updates
- Optional previews
- Out-of-band fixes
- Restart deadlines
- Pilot groups
- Failed installations
- Compliance reporting
Hotpatch Readiness
We can assess:
- Licensing
- Windows version
- Baseline level
- Microsoft Intune enrolment
- Windows Autopatch policies
- VBS status
- Arm64 compatibility
- Device eligibility
Microsoft Intune and Windows Autopatch
Our team can configure:
- Quality-update policies
- Hotpatch settings
- Feature-update policies
- Deployment rings
- Safeguard reporting
- Expedited updates
- Driver management
Compatibility and Recovery
Before deploying a major feature update, we can test:
- Business applications
- Drivers
- Printers
- VPNs
- Security software
- Specialist hardware
When an update causes problems, we can diagnose failed installations, perform safe rollback and restore the device to a secure supported state.
Hamilton Group aims to make first contact on IT support requests within 15 minutes, helping businesses keep Windows secure without unnecessary interruption.
The Simple Explanation
A feature update changes the Windows release.
A cumulative update keeps the current release secure and reliable.
A hotpatch applies eligible monthly security fixes without an immediate restart, but still depends on periodic cumulative baseline updates that do require one.
The most effective update strategy is not to avoid restarts at any cost. It is to control when they happen, confirm that devices remain protected and prevent unsuccessful updates from disrupting the business.
Call 0330 043 0069, book a meeting with one of our experts or visit hgmssp.com for experienced help with Windows Update, Microsoft Intune, Windows Autopatch and hotpatch deployment.