← All articles

Windows Hotpatch Baseline Eligibility: Don't Miss the Secure Boot Rollout

Two restart-required baselines in two months — and the Secure Boot certificate rollout riding on the second. Here is what to verify across the fleet.

Windows hotpatch baseline eligibility was planned to cost four restarts in 2026. By mid-July, it had already cost four. Microsoft’s hotpatch release notes list baselines in January and April, an additional restart-required baseline on June 9, and the planned baseline on July 14 — with October still to come. Devices must be on the latest baseline to keep receiving restart-free hotpatch updates, and July’s baseline carries something more: a wider automatic rollout of the new Secure Boot certificates.

That is the quiet risk in restart-free servicing. Hotpatch packages are scoped to security updates and install silently. Everything else — cumulative fixes, new features, and the Secure Boot certificate rollout — travels with the baselines that still require a restart. When the calendar itself slips, as it did in June, the assumption that “we restart four times a year and we’re covered” stops holding. IT teams need to see which devices are current, which fell out of the cadence, and which received the new certificates.

How Windows Hotpatch Baseline Eligibility Works

The Baseline Calendar Slipped in 2026

The model is simple on paper: baseline months (planned for January, April, July, and October) deliver cumulative updates that require a restart, and the months in between deliver restart-free hotpatch security updates. Eligibility rests on staying current — a device that is not on the latest baseline falls back to standard cumulative updates, with restarts, until it catches up. What 2026 has shown is that the calendar is a plan, not a promise: June 9 brought an unplanned baseline, and July 14 followed with the scheduled one. Two consecutive restart months in a model built to keep restarts to a minimum.

July’s Baseline Carries the Secure Boot Rollout

The July baseline (KB5101650) widens the pool of devices eligible to automatically receive the 2023 Secure Boot certificates — the replacements for certificates that began expiring in June 2026. The rollout is automatic, and devices that have not yet received the new certificates continue to start and continue to update. But automatic and staged also means uneven: at any given moment, some devices in a fleet have the new certificates and some do not. The question is not whether Microsoft’s mechanism works. The question is whether you can document where it has landed — and which devices are drifting behind the baselines that carry it.

How CapaOne Keeps Invisible Updates in Compliance

CapaOne does not deploy Windows OS updates — the hotpatch rollout itself belongs to Microsoft’s tooling. What CapaOne delivers is the fleet-wide view that decides whether the restart-free model actually lands safely.

See Which Devices Are Behind on Baseline

Security Monitor surfaces configuration drift and exposure across the fleet, so IT can see which endpoints run behind on baseline — and where the fleet’s actual state has drifted from the intended one. The principle is the same one we described in Endpoint Configuration Drift — The Exposure Patching Doesn’t Close: a fleet can look patched and still stand open when its real state slides away from the plan.

Watch Reliability After Silent Updates

Experience Monitor tracks reliability and performance after updates install, so regressions surface before users report them. When updates no longer announce themselves, reliability data is how IT confirms that the silent model works — and catches the cases where it doesn’t.

Both run on the CapaOne Endpoint Management Platform — standalone, or alongside a Microsoft-managed update flow. For the third-party side of the same story, see what hotpatch doesn’t patch. And when a double-baseline summer produces a backlog, endpoint vulnerability prioritization ranks what to fix first.

What IT Teams Gain

The operational payoff is concrete:

  • Baseline stragglers become visible while it still matters — before the next hotpatch month arrives and the fleet’s eligibility splits in two.
  • Compliance evidence emerges from daily operations: which devices follow the hotpatch cadence, which drifted, and what their exposure looks like.
  • Post-update regressions surface from reliability data instead of user tickets.

Restart-free servicing is where Windows is heading, and it changes the discipline IT teams need: from scheduling restarts to verifying state. June and July made the case better than any calendar could — when the rhythm changes without warning, the teams that can see their fleet adapt in a day. When that verification runs continuously, compliance becomes the natural result of everyday IT operations, not a quarterly scramble.

Book a demo of the CapaOne Endpoint Management Platform to see baseline and exposure state across your fleet — or start a free trial and explore the platform hands-on.

Frequently Asked Questions

What Is Windows Hotpatch Baseline Eligibility?

Windows hotpatch baseline eligibility means a device must run the latest baseline update to receive restart-free hotpatch security updates. Microsoft plans four baseline months per year — January, April, July, and October — but can add more: 2026 added an extra baseline on June 9. A device that is not on the latest baseline receives standard cumulative updates, with restarts, instead.

How Do the New Secure Boot Certificates Reach Windows Devices?

Through Windows quality updates. The July 14, 2026 baseline (KB5101650) widened the pool of devices eligible to automatically receive the 2023 Secure Boot certificates, which replace certificates that began expiring in June 2026. The rollout is automatic and staged, so timing varies across a fleet — and verifying where it has landed is the IT team's job.

What Happens if a Device Misses a Baseline Update?

The device loses hotpatch eligibility and receives the latest cumulative update, which requires a restart. During a later hotpatch month, an enrolled device that is behind receives both the latest baseline and the hotpatch. The catch-up is automatic, but the restart-free benefit — and a predictable fleet state — is lost in the meantime.

Does CapaOne Deploy Windows Hotpatch Updates?

No. Microsoft's tooling manages the hotpatch rollout itself. CapaOne provides the compliance and reliability layer: Security Monitor shows which devices run behind on baseline and where exposure builds, and Experience Monitor tracks reliability after updates install.

Book a Demo →Start Free Trial