Microsoft Makes Hotpatching Free for Windows Server 2025
Microsoft has just announced that the Hotpatching feature for Windows Server 2025, managed through Azure Arc, is now free! With this capability, servers can apply security updates without requiring a reboot.
Hotpatching is now free for hybrid environments
Previously subject to billing, the use of the Hotpatching service via Azure Arc is now completely free for those running Windows Server 2025 Standard and Datacenter. In a new blog post, Microsoft also stated that billing had been stopped since May 15, 2026 for all machines already registered. You do not need to do anything: Microsoft handled this change on its side.
As a result of this decision, physical and virtual servers running on-premises or in a cloud other than Azure (multicloud context) can benefit from Hotpatching. There is still one condition to meet: the server must be connected to Azure Arc. This component acts as the bridge between the local machine and the Azure cloud, since Hotpatching must be enabled through the cloud console. In addition, you need to make sure that virtualization-based security (VBS - Virtualization-based security) is enabled on the machine.

This article is also a reminder that this feature is already free for those running virtual machines on Azure (IaaS) or via Azure Local with the Windows Server Datacenter: Azure Edition editions (versions 2022 and 2025).
A quarterly cadence alternating between reboot and no-reboot
Hotpatching makes it possible to drastically reduce the number of reboots required to apply updates. A reboot is still needed once per quarter (January, April, July, October). For the rest, security updates are installed without requiring a reboot, meaning they can be applied in production with no service interruption.
The update cycle works as follows:
- Baseline months: servers install a standard cumulative security update. This process includes all security fixes as well as the new features and improvements accumulated since the last baseline update. A reboot is required.
- The following two months: machines receive only security updates in the form of hotpatches. These monthly fixes are applied instantly and do not require any system reboot to take effect.
In other words, Windows Server still needs to reboot to apply OS changes that are not related to security.

It is a good decision by Microsoft, because Hotpatching was well received by administrators, but the fact that it was paid frustrated everyone (once again).


