Photo by Marija Zaric on Unsplash
Hotpatching in Windows Server 2025
Trouble-Free
Hotpatching directly modifies the code of processes running in RAM, eliminating the need for a restart. The key advantage is reduction of downtime, as servers remain operational and security updates are made without delay. Not all updates support this technology, though, and hotpatching will probably be limited to regular patch day updates in the future. Because not all updates support hotpatching, rebooting is still necessary, which certainly puts the benefits into perspective. In this article, you'll also learn about more limitations.
Microsoft Azure Required
On Windows Server 2022, you need the Datacenter: Azure Edition license, which must be running in Azure or Azure Stack hyperconverged infrastructure (HCI), to use hotpatching. Although hotpatching will also be available in local data centers in the Standard and Datacenter editions in the future, you still need an Azure connection.
To use hotpatching, you must first enable virtualization-based security (VBS) on Windows Server 2025 in the Security | Secured-core section of the Windows Admin Center (Figure 1). VBS uses Hyper-V virtualization technology to move security-critical processes to an isolated environment. VBS isolates particularly sensitive data and processes from the regular operating system environment, which greatly limits the possibilities for attack.
...Buy this article as PDF
(incl. VAT)
Buy ADMIN Magazine
Subscribe to our ADMIN Newsletters
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Most Popular
Support Our Work
ADMIN content is made possible with support from readers like you. Please consider contributing when you've found an article to be beneficial.

