Microsoft Wants You to Patch in Three Days. Security Teams Say That's Not How It Works.
Microsoft is telling IT administrators to apply security fixes within 72 hours, citing AI tools that find and exploit software flaws faster than ever. Experts agree on the threat. They disagree, sharply, on whether three days is workable.

Key points
- Microsoft's Director of Microsoft 365, Jeremy Chapman, publicly called for enterprises to apply security patches within three days, citing AI-accelerated vulnerability exploitation.
- Microsoft's own MDASH scanning tool and its collaboration with Anthropic's Project Glasswing informed the tighter deadline.
- Verizon's 2024 Data Breach Investigation Report found the median time to patch had risen to 43 days, the opposite direction of Microsoft's new target.
- CISA's Known Exploited Vulnerabilities catalogue shows that only a small fraction of all disclosed flaws are ever confirmed as actively exploited.
- Security experts from Tenable, VulnCheck, and Contrast Security argue a blanket three-day window creates its own risks and that triage, not speed alone, is the answer.
Microsoft wants your IT team to apply security patches, the fixes software companies release to close known security holes, within three days. That is the new guidance from Jeremy Chapman, Director of Microsoft 365, delivered in a public video this month aimed squarely at Windows administrators.
The reasoning is straightforward: artificial intelligence is helping criminals find and exploit software flaws far faster than before. Microsoft says it reached this conclusion partly through its own internal tool, MDASH, a scanning system that uses multiple AI models to hunt for vulnerabilities, and partly through work with Anthropic's Project Glasswing. The upshot, Microsoft argues, is that the old habit of waiting two to four weeks before rolling out a patch is no longer safe.
Why do admins wait at all?
Patching is not as simple as clicking "update." A security fix in a large organisation must be tested against dozens of existing software systems before it goes anywhere near the machines staff actually use. A bad patch can corrupt data, crash a system, or trigger the Blue Screen of Death, where a Windows computer stops working entirely and displays a blue error screen. Multiple vendors, not just Microsoft, have shipped patches that broke other products and caused widespread outages.
"Many organisations have patch windows, review cycles, and test environments to identify these issues prior to patching production environments," says Scott Caveza, senior research manager at vulnerability assessment firm Tenable. "Blindly relying on auto-updates without contextual validation is not a defensible security posture."
Verizon's Data Breach Investigation Report, published earlier this year, found the median time to patch had actually crept up to 43 days. Organisations are not slow because they are careless. They are slow because the process is genuinely hard.
Is three days even achievable?
For most large enterprises, no, at least not for every patch. That is the consensus view among independent experts, even those who accept Microsoft's core argument about AI-driven risk.
| Factor | Detail |
|---|---|
| Microsoft's recommended window | 3 days |
| Current median time to patch (Verizon 2024) | 43 days |
| Typical enterprise deferral window | 2 to 4 weeks |
| CVEs (disclosed vulnerabilities) actively exploited in the wild | A small fraction of all disclosed flaws |
| CISA Known Exploited Vulnerabilities list | Publicly maintained catalogue of confirmed exploited flaws |
The smarter approach, several researchers argue, is triage. Not every vulnerability deserves the same urgency. "The goal cannot be to treat every CVE as an emergency," says Jeff Williams, founder and CTO at Contrast Security. "It has to be identifying, within hours, which vulnerabilities are actually exploitable and require immediate action."
Caitlin Condon, Vice President of Security Research at VulnCheck, points to a practical filter: focus on flaws that have working proof-of-concept code, meaning a demonstrated attack method, verified real-world exploitation, or sustained interest from ransomware groups. That list is far shorter than the full catalogue of disclosed vulnerabilities, and far more actionable.
Danny Jenkins, CEO of endpoint protection firm ThreatLocker, is more sympathetic to Microsoft's urgency. "A controlled interruption is usually far less costly than a successful attack exploiting a known vulnerability," he says. His advice: test fast, prioritise anything actively exploited or exposed to the internet, and stop treating the next scheduled maintenance window as a safe harbour.
For organisations that genuinely cannot validate and deploy a patch within three days, Brad Hibbert, CSO at vulnerability management firm Brinqa, points to interim options: blocking external access to the affected system, reducing its exposure, or in some cases removing the vulnerable component entirely until a proper patch is ready.
What should ordinary users and IT teams actually do?
If you run IT for a business, prioritise patches for anything on CISA's Known Exploited Vulnerabilities catalogue first. Those are confirmed active threats. Everything else can move through your normal testing cycle, but that cycle needs to get faster.
If you are a regular employee, keep your personal and work devices set to install updates promptly. The risk of a bad patch affecting a standard work laptop is far lower than the risk of leaving a known flaw open.



