What’s changing
Microsoft has delayed the rollout of automatic monthly security update installation during Windows Autopilot device preparation. The new target date is 9 September 2025. The capability applies to Windows 11 devices provisioned through the device preparation flow, where the latest cumulative security update would be installed as part of enrolment rather than waiting for a later update scan.
Why it matters
Until the feature ships, newly provisioned devices will still be built from whatever update level the installed image carries. That means a gap between the moment a device reaches the desktop and the moment it is fully patched — a window worth accounting for in your provisioning and compliance planning.
What IT admins should do
Treat the delay as a short extension of your existing patching approach rather than a reason to change design. Keep your current controls in place and revisit them once the feature is live.
- Continue to deliver security updates through your existing Windows Update for Business or Autopatch policies after enrolment.
- Refresh provisioning images or reference media where practical to reduce the initial patch gap.
- Check compliance policies and grace periods so freshly provisioned devices are not flagged before their first update cycle completes.
- Note the 9 September 2025 date in your change calendar and validate behaviour on a pilot group once it arrives.
- Watch the Microsoft 365 message centre and Windows release health for any further movement on the date.
Bottom line
Nothing breaks today, but the automated first-boot patching you may have planned around is not available yet. Assume manual or policy-driven patching remains your responsibility until the September date, then retest your device preparation flow to confirm the update runs as expected.
Source: Microsoft Learn. Summarised independently — check the source for the latest detail.