Not a scenario I've tested but #Intune/#Autopatch requires that to be enabled.
I would expect disabling drivers in the ring would block extension drivers, but that's an assumption.
Mythos Preview Turns Patches Into Exploits in Hours
Anthropic tested six Claude models on turning security patches into working exploits.
Mythos Preview crashed 14 of 18 SpiderMonkey vulnerabilities in Firefox with the first proof at 12 minutes.
It produced 8 working Firefox exploits in about 12 hours with the first ready 18 days before Firefox 148 shipped.
On 21 Windows kernel vulnerabilities from January and February 2026 Patch Tuesdays Mythos Preview found 18 in under 6 hours at about $2200 in API credits.
It built 8 full privilege escalation chains to SYSTEM at a total cost near $15700 or roughly $2000 per exploit. It cracked 13 of 14 bugs Microsoft rated as less likely or unlikely to be exploited.
All 8 chains were complete before Windows Autopatch reaches 90% of devices which takes 7 days.
Anthropic says the N Day model is now better described as N Hour and recommends memory safe languages like Rust
Updated Secure Boot status report in Windows Autopatch - Windows IT Pro Blog techcommunity.microsoft.com/…
これでTPMの証明書問題解決か!?
って思ったらazur用だったでごわす。
オンプレには関係なかった…
How do you know which devices will be automatically updated, and which won’t? The updated Secure Boot status report in Windows Autopatch gives you that visibility: msft.it/6012v5oqo
ALT Graphic with a blue abstract background featuring curved, wave-like shapes. White text reads: “Do your devices have up-to-date Secure Boot certificates? Gain visibility into Secure Boot status and where updates are needed—at the device level.” A small call to action in the corner says, “Read the blog.”
AI is shrinking the time between vulnerability discovery and exploitation. Staying current isn't routine maintenance—it's a key part of reducing exposure.
See how Microsoft Intune helps you stay ahead with Enterprise App Management, Windows Autopatch, and hotpatch: msft.it/6019vdhbW
ALT Blue gradient graphic with curved abstract shapes and white text reading “The threat window is shrinking.” Supporting text explains exploring a new security update status dashboard in Microsoft Intune to reduce vulnerability exposure, with a “Read the blog” call to action in the bottom right.
Managing Windows devices with Autopatch?
Microsoft has updated the Secure Boot Status Report, helping admins identify devices that need Secure Boot certificate updates before the June 2026 deadline.
Read more:
techcommunity.microsoft.com/…#WindowsAutopatch#MSIntune#Windows11#MVP
Hi. I’m highly unlikely. Hit 90%. The rest need attention because they’re otherwise unhealthy. All my clients are HP. They’re all on HP Connect and Windows Autopatch. I just had to write a script to check they were on the minimum BIOS required and stuck it in Intune remediations.
HP Connect and Windows Autopatch ensured my clients had minimum BIOS.
Intune Remediation matches model to minimum firmware, sets the registry then triggers the scheduled task.
Intune Secure Boot Report lets me monitor progress.
90% of estate done in just a couple of days.