Protection against multi-modal attacks with Microsoft Defender
August 1, 2025Profiles in Partnership Ep16: Building a Security-First Tech Company Insights from Carl Mazzanti
August 1, 2025This month, there are several improvements based on feedback we have heard from you, our customers. You’ve told us you want Windows to start and stay up to date with minimal interruptions. I’m happy to share that new Windows media includes updated Microsoft Store apps, and that hotpatch updates are generally available for both Windows x64 and Arm64 devices. We’re also continuing to add more resources to your update management toolbox.
Speaking of staying up to date, we continue to hear confusion about the lift involved with moving to Windows 11 and cloud-native management with Microsoft Intune. If you’re looking for quick, accurate information on recommended scenarios and the steps it takes to get there, check out our new guide on the Windows IT Pro Blog. And speaking of quick, accurate information, the Ask Microsoft Anything (AMA) sessions from this week’s Windows edition of Tech Community Live are now available to watch on demand. Quickly catch up on answers to frequently (or not so frequently) asked questions about Windows Autopilot, update and driver management, Microsoft Connected Cache and Delivery Optimization, and AI experiences.
Now let’s move on to the latest news you can use!
New in Windows update and device management
- [AUTOPATCH] If you’re looking for a proven, step-by-step approach to gradually roll out Windows 11 to eligible Windows 10 devices, explore Windows Autopatch groups. Windows Autopatch groups can make the process faster and easier with phased deployments, readiness insights, and reporting so you can upgrade with confidence.
- [HOTPATCH] Hotpatching is now generally available for Windows 11, version 24H2 Arm64 devices. Learn how to get your Arm64 devices hotpatch ready and start benefiting from faster security compliance and increased productivity.
- [OPTIMIZATION] Microsoft Connected Cache is now generally available for enterprise and education organizations. Save significant bandwidth during Windows 11 upgrades, device provisioning, application installation, and monthly updates.
- [RESILIENCY] Built to help you respond to the unexpected with speed, precision, and security, quick machine recovery is now generally available. When enabled, it automatically detects and fixes widespread issues on Windows 11 devices using the Windows Recovery Environment (WinRE). Learn how to customize the experience with the Intune Settings Catalog UI, and explore the new design that will now appear for end users during unexpected restarts, all a part of Resilience in action for Windows devices.
- [BUILT-IN APPS] If you use media refreshed in or after June 2025 to install Windows 11, version 24H2 or Windows Server 2025, that media now includes up-to-date versions of Windows built-in apps.
- [RESOURCES] Looking for information to help you more easily manage Windows Updates? Explore a guide to the essential documentation, communications, and resources that you need in your organizations’ update management toolbox.
New in Windows security
- [HPA] Enhance Microsoft 365 security by eliminating high-privilege access (HPA). Eliminating HPA helps ensure users and applications have only the necessary access rights. Learn more about how you can enhance your organization’s security posture.
- [COPILOT] Security Copilot in Microsoft Intune and Microsoft Entra are now generally available. Discover how Microsoft Entra and Intune play a critical role in modern security strategies and serve as the foundation for implementing a Zero Trust model.
- [INTUNE] You can use the Microsoft Intune Connector for Active Directory to join computers to an on-premises domain during Windows Autopilot provisioning. After users first sign in to the device, it will be Microsoft Entra hybrid joined.
New in Windows Server
For the latest features and improvements for Windows Server, see the Windows Server 2025 release notes and Windows Server, version 23H2 release notes.
- [HOTPATCH] Hotpatching for Windows Server 2025 is now generally available for on-premises and hybrid environments through Azure Arc. Learn more about hotpatching for on-prem servers, prerequisites to enroll in hotpatching for Azure Arc-connected Windows Server 2025 machines, and subscription details.
New in productivity and collaboration
Here are highlights from the July 2025 security update for Windows 11, version 24H2 and version 23H2:
- [TASKBAR] [24H2] The taskbar now resizes icons to fit more apps when space runs low, keeping everything visible and easy to access.
- [SETTINGS] [24H2] The Settings homepage for managed devices now includes cards tailored for enterprise use.
- [SHARE] [24H2] [23H2] When users share links or web content using the Windows share window, they’ll see a visual preview for that content.
- [ACCESSIBILITY] [24H2] In addition to a redesign, the Accessibility menu in Quick settings features text descriptions for assistive technologies like Narrator and Voice access.
For additional details, please refer to the June 2025 non-security preview update release notes for Windows 11, version 24H2 and version 23H2.
If you want to preview what’s coming in the August 2025 security update release, install the July 2025 optional non-security update for Windows 11, version 24H2, which starts the gradual rollout of:
- [START] [24H2] Apply Start menu pins only once with the Configure Start Pins policy. On first sign-in, users receive the Start menu pins you set as the IT admin. They can then personalize their pinned layouts.
Lifecycle milestones
Check out our lifecycle documentation for the latest updates on Deprecated features in the Windows client and Features removed or no longer developed starting with Windows Server 2025.
- [WINDOWS 11 22H2] Windows 11, version 22H2 (Enterprise and Education editions) no longer receives non-security preview updates. Monthly security updates will continue through October 14, 2025, when version 22H2 officially reaches end of servicing.
- [WINDOWS 11 23H2] Windows 11, version 23H2 (Home and Pro editions) will reach end of servicing on November 11, 2025. Enterprise and Education editions will continue to be serviced through November 10, 2026 per the Modern Lifecycle Policy.
- [JSCRIPT9LEGACY] Beginning with Windows 11, version 24H2, JScript9Legacy—based on JScript9—is enabled by default to handle scripting processes and operations. It provides improved security and performance features, and it’s more compatible with modern web standards. Learn more from these FAQs.
- [EOS] Windows 10 end of support (EOS) is now three months away. Find resources to help you get ready, check if current devices are eligible for the upgrade, and learn more about the Extended Security Update (ESU) program. For extra insights, watch the Technical Takeoff session on myths and misconceptions around Windows 10 EOS.
- [WIN10 EOS] [IOT] One size does not fit all when it comes to Windows 10 EOS for Windows 10 IoT Enterprise. Find out which versions of Windows 10 IoT Enterprise are impacted on October 14, 2025.
Additional resources
Looking for the latest news and previews for Windows, Copilot, Copilot+ PCs, the Windows and Windows Server Insider Programs, and more? Check out these resources:
- Windows Roadmap for new Copilot+ PCs and Windows features – filter by platform, version, status, and channel or search by feature name
- Microsoft 365 Copilot release notes for latest features and improvements
- Windows Insider Blog for what’s available in the Canary, Dev, Beta, or Release Preview Channels
- Windows Server Insider for feature preview opportunities
Thanks for reading! We’ll be back next month with even more news you can use.
If I can make this monthly summary more helpful to you, please leave a comment below. Our goal is to make it easier to plan for and manage Windows in your organization.
Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us @MSWindowsITPro on X and on LinkedIn. Looking for support? Visit Windows on Microsoft Q&A.