MSPDepot Blog
← All blogs

What Is Windows Patch Management? A Field Guide For MSPs In 2026

Microsoft's September Patch Tuesday fixed close to a thousand CVEs in one go. Tenable counted 964, which is roughly a 70% jump over the previous record of 569 set in July, and pushed the year's running total past 2,600 with three months still left.

Two of them were already being exploited in the wild: one in Windows Advanced Local Procedure Call, one in the Windows Update Stack itself.

If you run patching for 30 or 300 client tenants, a month like that tells you fast whether you have a patch process or just a scheduled job in your RMM.

What Windows Patch Management Means

Windows patch management is about deciding what each PC should download from Microsoft. After that, you pick a time to send the update packages. Then you roll them out in steps, rather than letting every device update at once. Next, you confirm the installs worked as expected. If one update does not complete, or if it triggers a problem, you deal with it right away.

That last part is what separates patching from clicking "approve all." Anyone can approve updates. Knowing which client had a line-of-business app die after a January cumulative and holding that fleet back a week while the rest of the base gets patched, is the job.

For an MSP, the scope is wider than a single IT teams. You're covering servers, workstations, laptops that rarely come on the VPN, and a mix of Entra-joined, domain-joined, and half-managed devices across tenants that each have their own working hours and risk appetite.

The Update Types You're Actually Managing

Cumulative updates (LCUs): The main monthly security rollup, shipped the second Tuesday of every month. Cumulative means the newest one contains everything before it, so a machine three months behind only needs the current one.

Servicing stack updates (SSUs): These patch the component that installs other updates. Modern Windows bundles the SSU into the LCU, and once an SSU is on a machine, you can't remove it. If a cumulative update fails with a vague error, a missing or broken servicing stack is a fair first suspect.

Out-of-band updates: Emergency releases outside the monthly cycle, either for an actively exploited flaw or to repair a patch that went wrong.

Preview and optional updates: Non-security rollups that land later in the month. Most MSPs skip them on production fleets and pull them only when they fix a specific known issue.

Feature updates: The annual version jumps (24H2, 25H2 and 26H2 this autumn). Different beast from monthly patching, different testing, different rollback window.

Drivers and firmware: Delivered through Windows Update, vendor tools, or your RMM. Also the single most common cause of a "the patch broke it" ticket.

Defender security intelligence: Updates many times a day and rarely needs your attention unless a machine has stopped checking in.

Why MSP Patching Isn't Internal IT Patching

Internal IT patches one estate with one set of rules. You patch dozens of estates with conflicting ones.

A law firm wants zero reboots during business hours and will accept a week of exposure. A manufacturer runs shifts and has a four-hour window at 2 am on Sundays. A 12-person startup has no window at all because nobody thinks about it. Same patch, three different rollouts.

Then there's the reporting side. Cyber insurance renewals now ask how fast you close known exploited vulnerabilities. Compliance audits ask for evidence, not a screenshot. If you can't produce per-tenant patch compliance on demand, you end up rebuilding it by hand at renewal time.

And the money side is real. Patching is labour you've already sold at a flat rate, so every hour spent chasing 20 stuck machines comes straight off your margin.

How A Normal Patch Month Runs

Microsoft releases around 10 am Pacific on the second Tuesday. Within hours, security vendors publish breakdowns, and CISA adds anything under active attack to its Known Exploited Vulnerabilities catalog, with a federal fix-by date attached.

For September 2026, both zero-days went into KEV on September 8 with a remediation deadline of September 22.

That KEV date is a useful anchor even if your clients aren't federal. It gives you a defensible number for your SLA.

A workable month looks like this. Tuesday night, read the release notes and flag anything touching Exchange, SQL, domain controllers or the specific apps your clients run. Wednesday, push to your own machines and a handful of volunteer devices. Friday or the following Monday, pilot fleet.

Midweek after that, everything else. Servers on their own schedule, usually the following weekend.

Most of the worth comes from what people read. Tenable says AI help can make the hunt bigger, but it does not add needles at the same rate. That means the real issues that fit a specific company are still limited.

900 CVEs sounds terrifying until you filter for what's installed, what's reachable, and what's being exploited.

Rings, And Why Most Patch Failures Trace Back To Them

A ring is a group of devices that get updates at the same time. Four rings cover nearly every MSP:

  • Ring 0: your own staff machines. Anything that blows up here costs you nothing but pride.
  • Ring 1: 5% of a client's fleet. Pick technical users who report problems instead of living with them.
  • Ring 2: around 25%, mixed departments and hardware models.
  • Ring 3: everything else, including the machines nobody can afford to lose.

Stagger them by two to three days each with a deadline that forces install after the deferral expires. The mistake to avoid is building rings out of whoever happens to be online.

A ring made entirely of head-office desktops tells you nothing about the field laptops running a different dock and a different GPU driver.

Servers deserve their own rings entirely, and domain controllers should never share a window with the systems that authenticate against them.

The Tools: Wsus, Intune, Autopatch, Hotpatch, And Your Rmm

WSUS is still live, even though Microsoft moved past it. Microsoft labelled it as deprecated on 20 September 2024. Yet more than a year and a half later, it still shows up with Windows Server 2025. It continues to fetch driver files from the Microsoft Update Catalog too. It still works when used with the Configuration Manager Software Update Point.

Microsoft even walked back its plan to kill driver synchronisation in April 2025 after customer pushback. Deprecated doesn't mean gone, but it does mean no new features and the occasional bad week.

In July 2026, a buildup of publishing metadata on Microsoft's side degraded WSUS synchronisation across supported client and server releases, with the worst impact landing on 13 July, one day before Patch Tuesday.

Windows Update for Business policies handle deferrals, deadlines, and grace periods without any server infrastructure. Cheap, reliable, no approval workflow.

Intune plus Windows Autopatch gives you ring management, quality update policies, and reporting from one console. It's the direction Microsoft keeps pointing, and for tenants already on Business Premium the licensing argument is mostly settled.

Hotpatch is the part worth understanding properly, because it changed the reboot conversation. Hotpatch-enabled devices install a full cumulative update with a restart in January, April, July and October, then take security-only updates in the months between with no restart at all.

Microsoft announced on 10 March 2026 that it would switch hotpatch on by default for eligible Intune-managed devices starting with the May 2026 release, cutting planned security reboots from twelve a year to four.

Eligible subscriptions include Windows 11 Enterprise E3 and E5, Microsoft 365 F3, Windows 11 Education A3 and A5, Microsoft 365 Business Premium, and Windows 365 Enterprise, with devices needing Windows 11 version 24H2 or later, Virtualization-Based Security turned on, and the current quarterly baseline installed.

Don't promise clients four reboots a year, though. An extra baseline in June already pushed 2026's planned security restart count to five, and Microsoft's Message Center advisory MC1462918 confirmed the September release would arrive as a standard restart-required update because it touched components that can't be swapped in memory.

Your RMM still matters for the machines where Intune doesn't reach, for third-party apps, and for the scripted cleanup nobody else does.

Third-Party Apps Are Where Most Of The Real Risk Sits

Windows Update patches Windows, Edge, and Defender. It does not patch Chrome, Firefox, Zoom, Java, Acrobat, 7-Zip, Notepad++, FileZilla, TeamViewer, the client's accounting package, or the CAD software one department can't live without.

Attackers know this. Browser and document reader flaws stay popular because they're everywhere and they're patched inconsistently.

Every client should have a maintained software inventory, an owner for each line-of-business app, and a monthly pass over third-party version.

If your RMM's software patching module covers 60% of what's installed, write down the other 40% and who handles it. An undocumented gap is the one that ends up in an incident report.

The October 2026 Dates You Can't Push Past

Two lands on the same day.

Year one of Windows 10 Extended Security Updates ends on 13 October 2026, and year two runs to 12 October 2027 at $122 per device, up from $61. ESU is cumulative, so a company that skipped year one can't start at year two; it pays for both.

The free consumer extension doesn't help your clients either, because devices joined to Active Directory or Entra, or enrolled in MDM, are excluded by the program's own rules.

On the same date, Windows 11 version 24H2 Home and Pro editions reach the end of updates, along with Windows 10 Enterprise LTSB 2016. Enterprise and Education editions on 24H2 stay supported until 12 October 2027.

Moving to 25H2 is a small enablement-package upgrade off the same codebase, so it's not the compatibility project a normal feature update would be.

Any client still on Windows 10 needs a hardware decision made now, not a renewal invoice in three weeks.

When Patches Break Things

Have a rollback path before you need one. LCUs can be removed with DISM, feature updates have a ten-day rollback window by default, and SSUs can't be removed at all.

Common causes of a failed install: not enough free space on 128GB SSDs, a corrupted component store, pending reboots stacking up, or a machine that hasn't checked in since March and needs the servicing stack caught up first. Run DISM RestoreHealth and SFC before assuming the update itself is bad.

When something does break after a patch, check Microsoft's Windows Release Health dashboard before you start troubleshooting. Known issues get posted there, sometimes with a Known Issue Rollback already pushed out.

Keep a per-client exception register. Which machines are held back, why, who approved it, and when you'll revisit. Exceptions that nobody reviews turn into permanently unpatched servers.

Numbers Worth Reporting To Clients

Four are enough:

  • Percentage of devices fully patched at 7, 14, and 30 days after release
  • Days to remediate anything in the CISA KEV catalog
  • Devices running an OS version past end of servicing
  • Machines with a pending reboot for more than 7 days

That last one catches the quiet problem. A patch that's installed but not rebooted isn't protecting anything, and reboot-pending counts climb steadily on laptop fleets where people just close the lid.

Conclusion

Patching isn't complicated work. It's work that has to happen every month, in the same order, with somebody checking the result afterward.

The MSPs who do it well aren't running better tools than everyone else. They read the release notes on Tuesday night instead of Friday. They keep their pilot rings honest, with real field laptops in them and not just head-office desktops.

They know which machines they've chosen not to patch, who signed off on that, and when it gets revisited. And they can pull a per-tenant compliance number without spending a day rebuilding it.

If you only fix one thing this quarter, make it the exception register. Held-back machines are where breaches start, and they're almost always held back for a reason that stopped being true months ago.

The October dates are close. Any client still sitting on Windows 10 or on 24H2 Home and Pro needs a decision made now, because the bill for waiting doubles on the 13th.