Latest / The Windows Podcast with Fexingo: Microsoft, PC, and Enterprise Windows Conversations / Why Windows Enterprise Patches Are Slowing Down
Transcript
- Lucas: If you manage enterprise Windows desktops, you might have noticed something strange over the last two months. The April 2026 cumulative update took noticeably longer to install than any previous patch this year. Luna: Yeah, I saw a thread from IT admins at a manufacturing firm saying their patch window jumped from about 45 minutes to nearly 90 minutes on some older machines. That's a huge operational shift. Lucas: It is. And what's interesting is that Microsoft didn't announce this change with a banner. They quietly updated the servicing stack, and the cumulative update itself grew by about 30 percent in size compared to the January 2026 release. For enterprise fleets with thousands of devices, that compounds fast. Luna: Right. And if you're an IT manager scheduling patches over a weekend window, an extra hour per machine means you either stagger deployments or you buy faster hardware. There's a real cost here. Lucas: And that's the thread I want to pull today. Because this isn't just about one slow patch. It's about Microsoft's quiet signal that Windows 11 is optimising for newer CPUs, and older hardware — even if it's officially 'supported' — is going to feel the drag. Luna: You know, speaking of the show, a few listeners have asked how we keep this podcast going without ads or sponsors. So here's the honest answer: a handful of listeners chip in monthly through buy me a coffee dot com slash fexingo, and that literally funds our ability to produce this many episodes. We wanted to mention it because it's the only reason we can stay independent. Lucas: Absolutely. And we're grateful for that. It's a small group, but it makes a real difference. Alright, back to the patches. Lucas: So let's look at what changed. The April 2026 cumulative update included a new servicing stack update — that's the code that actually installs the patch. Microsoft has been updating that stack more aggressively on Windows 11, adding protections against rollback attacks and improving integrity checks. Luna: Which is good for security, but it means the patch installer itself is doing more work. It's not just applying a diff file anymore. Lucas: Exactly. And on newer hardware with fast NVMe drives and modern CPUs, the overhead is barely noticeable. But on a four-year-old Dell Latitude with a SATA SSD and an Intel 10th-gen processor, that same patch can take nearly twice as long. We've seen user reports of install times going from 35 minutes to 65 minutes on comparable machines. Luna: And this matters because many enterprises are still running Windows 10 on hardware that is technically Windows 11 capable but older. They held off on the Windows 11 upgrade, and now they're being forced into a decision: upgrade the OS or upgrade the hardware. Lucas: Right. Windows 10 end of support is October 2025, so that's not far away. But even for organizations that moved to Windows 11 early, some of that hardware is now three or four years old. The patch slowdown effectively adds a hidden refresh cycle. Luna: Let's talk numbers. What's the actual financial impact? If a mid-size company has 2,000 desktops and each takes an extra 30 minutes to patch, that's a thousand hours of patching time per month. At an average IT salary of, say, fifty dollars an hour, that's fifty thousand dollars a month in labor cost. Lucas: And that's just the direct labor. There's also the opportunity cost of machines being offline, and the risk of delayed patches leaving a window for exploits. Microsoft's own data shows that unpatched vulnerabilities are the leading cause of breaches in enterprise environments. Luna: So what can IT departments do? One option is to move to Windows 11 LTSC — the Long-Term Servicing Channel. That gets you patches without the feature updates, but it also means you don't get the latest servicing stack improvements. Microsoft actually recommends against LTSC for general-purpose devices. Lucas: And LTSC is a separate license, so there's a cost there too. The more practical move might be to accelerate hardware refreshes. If you're on a three-year refresh cycle, consider moving to two and a half. That sounds aggressive, but the math on patching labor might justify it. Luna: There's also the option of using Windows Update for Business and deferring patches by a week or two. That gives you a buffer to test the patch on a pilot group and measure install times before rolling out to the whole fleet. But that only helps with timing, not the core slowdown. Lucas: Right. And I want to emphasize: this isn't about Windows being broken. It's about Microsoft making a deliberate tradeoff. They're prioritizing security and integrity over installation speed on older hardware. That's a defensible choice, but enterprises need to see it clearly so they can plan. Luna: One thing that caught my eye: the servicing stack update for Windows 11 version 24H2, which is expected later this year, reportedly includes even more integrity checks. So the trend is not reversing. Lucas: That's a good point. If anything, patch times may increase further with the 24H2 feature update. So enterprises that are planning a hardware refresh in 2027 might want to pull that forward to mid-2026 if they can. Luna: And what about using cloud-based patch management tools? Some third-party solutions can offload the patching workload by using peer to peer distribution or pre-staging the patches on local servers. That reduces the network bottleneck but doesn't change the installation time on each machine. Lucas: True. The installation step is cpu bound and disk-bound. You can't speed that up with better networking. So the real lever is hardware. And I think that's the key takeaway for IT leaders: start benchmarking your current patch install times now. Get a baseline for a representative sample of your fleet. Then you can project the cost of waiting. Luna: And if you're planning a hardware refresh, consider that newer machines with Intel 13th-gen or AMD Ryzen 7000 series processors have been shown to install patches up to 40 percent faster than 10th-gen machines in independent tests. Lucas: That's a concrete number. Forty percent faster. So the ROI on a hardware upgrade isn't just about user productivity or security features — it's also about reducing the operational burden of patching. That's a line item many IT budgets don't explicitly account for. Luna: Yeah, patching cost is often hidden in the 'operations' bucket. But when you surface it, the business case for a refresh becomes clearer. Lucas: Let's look at a real example. A listener from a regional bank with about 1,200 Windows 11 devices told us they ran a test after the April patch. Their older fleet — Dell OptiPlex 7080s with Intel 10th-gen — averaged 68 minutes for the April cumulative update. Their newer fleet — OptiPlex 7010s with 13th-gen — averaged 38 minutes. That's a 44 percent difference. Luna: And they told us they do patching twice a month. So that's 60 extra minutes per older machine per month. Across 800 older machines, that's 800 hours per month. At their blended IT rate, that's about forty thousand dollars a month in extra labor. Lucas: Which is almost half a million dollars a year. That alone could fund a refresh of several hundred machines. So the question becomes: is it cheaper to upgrade hardware or to keep paying the patch tax? Luna: And that's a decision every enterprise will face in the next 12 to 18 months. Because Microsoft is not going to slow down the servicing stack. They're building for the future. Lucas: Right. And I think that's the right call from a security standpoint. But as with everything in enterprise IT, the key is visibility. If you know the cost, you can manage it. If you don't, it just eats your budget silently. Luna: So for our listeners who are IT pros: run a test on your next patch cycle. Measure install times on a few old and new machines. Then multiply by your fleet size. You might be surprised by what you find. Lucas: We'll put a link in the show notes to a simple PowerShell script that logs patch install duration. And we'll also link to Microsoft's documentation on servicing stack updates so you can see exactly what changed. Luna: That sounds like a practical next step. And as always, we'd love to hear your own patch time stories. You can reach us at the show's email. Lucas: Alright, that's our time for this episode. We'll be back next week with another deep dive. Until then, keep your systems patched — and maybe budget for that new hardware.