Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Windows Autopatch quality-update reports are now in the Microsoft Intune admin center, not a separately branded MEM Portal. Go to Reports → Windows Autopatch → Windows quality updates. For individual-computer investigation, open the Reports tab and select Quality update status. The page supports search, filtering, column selection, sorting, and CSV export, with data refreshed approximately every four hours from managed devices.

What the Windows Autopatch quality-update report covers

“Windows Autopatch Quality Updates Report” describes a group of monitoring views for Windows devices managed through Windows Autopatch. Quality updates generally mean cumulative monthly Windows updates and related servicing releases, not feature upgrades.

It is not a universal inventory of every Windows computer in a tenant. Results depend on enrollment, Autopatch management, policy targeting, device check-ins, permissions, and the particular report selected.

Where to find it in the current Intune admin center

  1. Sign in to the Microsoft Intune admin center.
  2. Select Reports.
  3. Select Windows Autopatch.
  4. Select Windows quality updates.
  5. Open the Reports tab.
  6. Select Quality update status.

Use Reports → Windows Autopatch → Windows quality updates → Summary for an aggregate view. Microsoft can change menu labels, so use the report names as well as the path. The documented status-report location and controls are described in Microsoft’s Quality update status documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose the right report

Administrator question Best report
Which individual devices are current, delayed, or failing? Quality update status
What is the overall Autopatch picture? Quality update Summary
Is the update population improving or declining? Quality update trending
Which enrolled devices receive Hotpatch updates? Hotpatch quality updates
Which vulnerabilities and remediation states are visible? Common Vulnerabilities and Exposures (CVEs)
Which devices are outside the expected update-management method? Autopatch management status
How are Intune and co-managed devices distributed by update level? Windows Update Distribution Report

Quality update status: the device-level view

The status report combines Intune communication data with Windows Update service and client data. Microsoft lists these default columns:

Column How to use it Important qualification
Intune last check-in time Determine whether the device is communicating recently. A current report row does not prove a current device check-in.
Service State and Service Substate Assess the Windows Update service-side condition. Interpret with client fields and policy context.
Client State and Client Substate See whether local processing is installing, waiting, blocked, or reporting an error. These states alone do not establish root cause.
Servicing Channel Confirm the expected servicing channel. Channel and feature-version applicability affect results.
User Last Logged On and Primary User UPN Identify the last interactive user and device owner for follow-up. Treat user information as potentially sensitive.
Hex Error Code Use the code as an investigation key. It is not automatically a complete diagnosis.
Cadence Type Check the device’s rollout schedule. A delay may be intentional for its ring or cadence.
Quality update Installed Time Compare the reported installation with the expected release or deployment window. The value is based on what the service received from the device.
Servicing Channel as reported by Windows Update Compare the Windows-reported channel with policy expectations. Differences can indicate configuration or reporting issues.
Extended Security Updates enrollment status Check whether ESU enrollment is reported. Do not infer update applicability without the device’s edition and lifecycle context.

Search, filter, customize, and export

Quality update status supports searching by device name, Microsoft Entra device ID, or serial number. You can sort columns, apply available filters, add or remove columns, and export devices to CSV. Available filters can vary with permissions, service rollout, and UI changes.

  1. Open the Summary view to understand the size of a problem.
  2. Open Quality update status.
  3. Search for a device or filter the relevant status, ring, group, or error condition.
  4. Add the columns needed for investigation.
  5. Export the filtered list to CSV.
  6. Compare the report refresh time with each device’s Intune last check-in.

Refresh timing and what it means

Autopatch quality-update status and Summary data refresh approximately every four hours, and the page displays its last refresh time. That is a service refresh interval, not a guarantee that every device checked in during that period. A device can have a recent Intune check-in while Windows Update is still processing, or the report can lag behind an installation observed locally.

The Summary dashboard documentation also records a known issue in which the Paused column may not appear.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the other Autopatch views show

Summary

Summary aggregates current status across the report’s Intune device population. Use it for operational orientation and to decide which device-level view to open. Its counts should not be presented as a formal security-compliance percentage unless the population, update definition, and calculation method are explicitly defined.

Rank #2
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
  • 256 GB SSD of storage.
  • Multitasking is easy with 16GB of RAM
  • Equipped with a blazing fast Core i5 2.00 GHz processor.

Quality update trending

The trending report covers the previous 90 days and can be filtered by update status and deployment ring. Display trends as a percentage or device count. Percentage is useful when the managed population changes; device count is better for estimating remediation workload. A rising percentage can result from devices leaving the population, so compare trends with enrollment and inventory changes. See Microsoft’s trending report documentation.

Hotpatch quality updates

The Hotpatch report is a policy-level view for devices receiving Hotpatch updates: Reports → Windows Autopatch → Windows quality updates → Reports → Hotpatch quality updates. Hotpatch eligibility, supported editions, infrastructure, enrollment, and licensing are separate considerations; ordinary quality-update results and Hotpatch results are not interchangeable. Microsoft documents this view at Hotpatch quality update report.

Common Vulnerabilities and Exposures (CVEs)

The CVE report provides Autopatch-managed-device visibility into detected CVEs, remediation status, severity distribution, and related Microsoft Knowledge Base updates. Microsoft documents an approximately two-hour refresh interval. It answers a vulnerability question, not simply an installation-status question, and is not a replacement for a complete vulnerability-management platform. See the CVE report documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Investigate a device that appears unpatched

  1. Check Intune last check-in. If it is stale, investigate enrollment, connectivity, MDM, or device-health issues first.
  2. Review Service State and Service Substate. These describe the reported service-side condition.
  3. Review Client State and Client Substate. Determine whether processing is pending, active, blocked, or failing.
  4. Record the Hex Error Code. Use it to guide further investigation; do not treat it as the entire diagnosis.
  5. Compare Quality update Installed Time. Relate it to the applicable release and deployment window.
  6. Verify Cadence Type, ring, and servicing channel. A device may be deliberately staged behind another ring.
  7. Check management status. Confirm that the device is actually managed for quality updates.

When the report is empty or a device is missing

  • You may be in the wrong report family.
  • The tenant may have no eligible Autopatch-managed devices.
  • Your account may not have the required authorization.
  • Devices may not have reported data yet, or the service may be refreshing.
  • The devices may use ordinary update rings or co-management rather than the Autopatch workload.
  • The visible data may be stale.

Compare the result with Autopatch management status and the general Windows Update Distribution Report before concluding that the devices do not exist.

Autopatch reporting versus the Intune Windows Update Distribution Report

The general Intune report is broader. It can include Intune-managed and co-managed devices, environments using standard update rings, mixed management methods, and devices with no Intune update policy. Its documented views are Windows quality update distribution, distribution per feature version, and Windows quality update device version.

Rank #3

It can show the selected update, the selected update or later, devices that need the update, feature version, build number, KB article, device identity, and last check-in details. Its data is cached; after the cache expires (up to three days), use Generate Again for a new report. Read the scope and report behavior at Reports for Windows Quality Update Policies.

Use Management Status to find coverage gaps

The Autopatch management status report is device-centric and tenant-wide for Intune-managed Windows 10 and Windows 11 devices. It identifies coverage for quality updates, feature updates, driver policies, update rings, Hotpatch enrollment, other management mechanisms, and active alerts.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Its navigation is different: Devices → Overview or Windows updates → Monitor → Autopatch management status. Use it when the question is which update-management method actually covers a device, especially in a mixed cloud-policy, ring, and unmanaged environment. See Windows Autopatch management status report.

Why numbers differ between reports

Differences are often expected because reports can use different device populations, management mechanisms, data sources, refresh intervals, scope tags, cache states, and definitions such as “on this update,” “on this update or later,” “needs update,” and “not applicable.” Reconcile them by comparing the population, last refresh time, device check-in age, management method, cache or generation time, and update applicability.

Common edge cases

Stale check-in

Old update information may reflect a device that has not communicated recently. Check-in age before labeling it a patch failure.

Rank #4
15.6 Inch Laptop Computer, N4020, 4GB DDR4 RAM, 128GB eMMC,with Windows 11
  • EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
  • 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
  • RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
  • ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
  • LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.

Intentional deployment delay

Autopatch rings and cadence settings can stage updates. Being behind the newest release is not necessarily an error.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Not applicable

An update may not apply to a device’s feature version, edition, servicing channel, or state. The general distribution report explicitly distinguishes applicable devices from devices for which the selected update does not apply.

Co-management

Co-managed devices can appear in the broader Intune distribution report without appearing identically in an Autopatch-specific view.

Hotpatch assumptions

Hotpatch reporting does not prove that every Windows client supports rebootless updates; eligibility and enrollment are separate.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Practical decision guide

  • Use Quality update status for current per-device state, service/client states, error clues, and installation time.
  • Use Summary for an aggregate Autopatch overview.
  • Use Trending for 90-day direction by percentage or count.
  • Use Hotpatch only for the separately enrolled Hotpatch population.
  • Use CVEs for vulnerability and remediation visibility.
  • Use Management Status to discover coverage gaps and management ownership.
  • Use Windows Update Distribution Report for broader Intune, co-managed, and update-ring populations.

Frequently Asked Questions

Is the Windows Autopatch report still in the MEM Portal?

The current location is the Microsoft Intune admin center: Reports → Windows Autopatch → Windows quality updates.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Windows 11 Laptop with i3 Processor 15.6" Work Laptop for College Students
  • 【Efficient Performance】 Powered by Intel Core i3 processor (2 cores, 4 threads, up to 3.4GHz) with 12GB RAM and 256GB SSD. Handles multitasking, office software, online classes, and HD video streaming smoothly. Integrated Intel UHD Graphics 620
  • Backlit Keyboard & Complete Package】Comes with a cool backlit keyboard. Comes with awebcam, dual stereo speakers (8Ω/1.0W each), DC charger, and user manual – ready for late-night studying, online classes, video conferencing, and daily productivity
  • 【Vibrant Display】 15.6-inch Full HD (1920x1080) anti-glare screen with 16:9 aspect ratio delivers crisp images and vivid colors – perfect for studying, watching lectures, or entertainment. Thin-bezel design maximizes viewing area
  • 【Fast Connectivity & Expansion】 Equipped with WiFi 6 (802.11ax) and Bluetooth 5.2 for stable, high-speed wireless. Features 3 x USB 3.0, HDMI 2.1, Type-C (supports PD3.0 fast charging), and a TF card slot expandable up to 2TB – easily connect external monitors, mice, drives, or expand storage for all your files
  • 【Long Battery Life & Portable】 Built-in 11.55V 5000mAh/57.75Wh high-capacity battery delivers approximately 7 hours of mixed-use battery life – enough for a full day of classes and assignments. Lightweight at just 1.63kg (3.6 lbs) and 19.5mm thin, plus a compact packing size – easily slips into a backpack for campus, library, or coffee shop

How often does Autopatch quality-update data refresh?

Microsoft documents an approximately four-hour refresh for the quality-update status and Summary views. This does not mean every device checked in during that interval.

Can I export device results?

Yes. Quality update status supports search, filtering, column selection, sorting, and CSV export.

Does the Autopatch report include every co-managed device?

Not necessarily. The broader Windows Update Distribution Report is the appropriate view for Intune-managed and co-managed populations; Autopatch views depend on Autopatch management scope.

Why do Autopatch and Intune show different counts?

They may use different populations, management methods, refresh intervals, cache states, scope tags, and definitions of update applicability or update level.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does a current quality-update status prove that a device is secure?

No. It describes the reported state for the relevant update workload. CVE exposure, applicability, other products, configuration, and reporting time require separate analysis.

Quick Recap

Bestseller No. 1
Bestseller No. 2
Dell Latitude 5420 14' FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
256 GB SSD of storage.; Multitasking is easy with 16GB of RAM; Equipped with a blazing fast Core i5 2.00 GHz processor.
$304.99
Bestseller No. 3
HP 14' HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
$249.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.