Windows Updates & Release Notes
86 updates curated from 110 sources by the Releasebot Team. Last updated: Aug 13, 2026
- Aug 11, 2026
- Date parsed from source:Aug 11, 2026
- First seen by Releasebot:Aug 13, 2026
August 11, 2026—KB5121000 (OS Build 28000.2704)
Windows ships the Windows 11 version 26H1 cumulative update KB5121000 with the latest security fixes, non-security improvements from the optional preview, better TPM maintenance reporting, and expanded Secure Boot certificate coverage.
This cumulative update for Windows 11, version 26H1 (KB5121000) includes the latest security fixes and improvements, along with non-security updates from last month's optional preview release. Visit the Windows release health dashboard for the latest status on this release.
Improvements
This update includes new features and quality improvements that were part of the following update:
- July 14, 2026—KB5101649 (OS Build 28000.2525)
- July 28, 2026—KB5101681 (OS Build 28000.2608) Preview
This update addresses security vulnerabilities documented in the following guide:
- August 2026 Security Updates
The following summary outlines key quality improvements addressed by this update. The bold text within the brackets indicates the item or area of the change.
- [Device] This update improves TPM maintenance reporting by ensuring that EK certificate status is reported accurately.
- [Secure Boot] This update includes additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates. Certificate deployment via Windows updates continues across supported PCs and non-managed business devices in the coming months.
If you've already installed previous updates, your device will download and install only the new updates included in this package.
Components updates
Known issues in this update
Microsoft is not currently aware of any issues with this update.
How to get this update
Before you install this update
Microsoft combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see Servicing stack updates.
Deployment
If you deploy dynamic updates such as this update to an existing Windows image, ensure the boot.stl file is included as part of the installation media. Failure to include the file might prevent devices from successfully starting from the installation media and can result in error code 0xc0430001.
Note
The boot.stl file is used during Secure Boot validation and must match the Windows version and architecture of the image you are updating.
To ensure the boot.stl file is included as part of the installation media, do one of the following:
- Use the Update WinPE script to update an existing Windows image. (Recommended)
- Manually copy the boot.stl file from the device Windows\Boot\EFI folder to the corresponding folder on your installation media before deploying the update.
For information about how to apply Dynamic Update packages to existing Windows images, see Update Windows installation media with Dynamic Update.
Install this update
To install this update, use one of the following Windows and Microsoft release channels.
Windows Update
✅
This update downloads and installs automatically from Windows Update and Microsoft Update.
File information
For a list of the files provided in this update, download the file information for cumulative update KB5121000.
For a list of the files provided in the servicing stack update, download the file information for the SSU (KB5101747) - version 28000.2602.
Related topics
Windows monthly updates explained
Description of the standard terminology used for Microsoft software updates
Windows release health
Original source - Aug 11, 2026
- Date parsed from source:Aug 11, 2026
- First seen by Releasebot:Aug 13, 2026
August 11, 2026—KB5120240 (OS Build 22631.7517)
Windows releases the latest Windows 11 23H2 cumulative update with security fixes, quality improvements, and a refreshed emoji panel that now supports GIPHY. It also improves File History backups, MDM reliability, and Secure Boot certificate coverage.
This cumulative update for Windows 11, version 23H2 (KB5120240), includes the latest security fixes and improvements, along with non-security updates from last month’s optional preview release. Visit the Windows release health dashboard for the latest status on this release.
Announcements and messages
This section provides key notifications related to this release, including announcements, change logs, and end-of-support notices.
Windows Secure Boot certificate expiration
Important: Secure Boot certificates used by most Windows devices are set to expire starting in June 2026. Microsoft has been updating these certificates on consumer and non-managed business devices over the past several months. Devices that haven’t received the newer certificates will continue to start and operate normally, and standard Windows updates will continue to install. Updated certificates will continue to be delivered through Windows Update in the coming months.
Improvements
This update addresses security issues for your Windows operating system.
Important
Use EKB KB5027397 to update to Windows 11, version 23H2.
This security update contains fixes and quality improvements from KB5099414 (released July 14, 2026). The following summary outlines key issues addressed by this update. Also, included are available new features. The bold text within the brackets indicates the item or area of the change.
- [Connectivity] This update refreshes the COSA profile for SolNet-Mobile to support the latest mobile operator settings.
- [Device Management] This update improves reliability for devices managed through mobile device management (MDM) by helping devices continue to perform normally when an MDM certificate expires.
- [File History] This update improves the reliability of File History backups to SMB network shares, helping scheduled backups access network locations and copy files as expected.
- [Secure Boot] This update includes additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates. Certificate deployment via Windows updates continues across supported PCs and non-managed business devices in the coming months.
- [Emoji Panel] The emoji panel (Windows key + period (.)) now supports GIPHY following the deprecation of Google's Tenor API.
If you've already installed previous updates, your device will download and install only the new updates included in this package.
For more information about security vulnerabilities, see the Security Update Guide and the August 2026 Security Update.
Windows 11 servicing stack update (KB5120239) - 22621.7513
This update makes quality improvements to the servicing stack, which is the component that installs Windows updates. Servicing stack updates (SSU) ensure that you have a robust and reliable servicing stack so that your devices can receive and install Microsoft updates. To learn more about SSUs, see Simplifying on-premises deployment of servicing stack updates.
Known issues in this update
Microsoft is not currently aware of any issues with this update.
How to get this update
Before you install this update
Microsoft combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see Servicing stack updates.
Deployment
If you deploy dynamic updates such as this update to an existing Windows image, ensure the boot.stl file is included as part of the installation media. Failure to include the file might prevent devices from successfully starting from the installation media and can result in error code 0xc0430001.
Note
The boot.stl file is used during Secure Boot validation and must match the Windows version and architecture of the image you are updating.
To ensure the boot.stl file is included as part of the installation media, do one of the following:
- Use the Update WinPE script to update an existing Windows image. (Recommended)
- Manually copy the boot.stl file from the device Windows\Boot\EFI folder to the corresponding folder on your installation media before deploying the update.
For information about how to apply Dynamic Update packages to existing Windows images, see Update Windows installation media with Dynamic Update.
Install this update
To install this update, use one of the following Windows and Microsoft release channels.
Available
✅
This update downloads and installs automatically from Windows Update and Microsoft Update.
File information
For a list of the files provided in this update, download the file information for cumulative update KB5120240.
For a list of the files provided in the servicing stack update, download the file information for SSU KB5120239 - versions 22621.7513.
Related topics
Windows release health
Microsoft Store for Business and Education with Configuration Manager
Get updates for apps and games in Microsoft Store
Original source All of your release notes in one feed
Join Releasebot and get updates from Microsoft and hundreds of other software products.
- Aug 11, 2026
- Date parsed from source:Aug 11, 2026
- First seen by Releasebot:Aug 13, 2026
August 11, 2026—KB5121003 (OS Builds 26200.9168 and 26100.9168)
Windows releases a Windows 11 update with security improvements, broader Secure Boot certificate targeting, and cumulative quality fixes from earlier updates. It also notes no known issues and automatic delivery through Windows Update and Microsoft Update.
Announcements and messages
This section provides key notifications related to this release, including announcements, change logs, and end-of-support notices.
Windows Secure Boot certificate expiration
End of updates
Improvements
This update includes improvements from the following previously released updates:
- July 28, 2026—KB5101684 (OS Builds 26200.8973 and 26100.8973) Preview
- July 18, 2026—KB5121767 (OS Builds 26200.8894 and 26100.8894) Out-of-band
- July 14, 2026—KB5101650 (OS Builds 26200.8875 and 26100.8875)
The following summary outlines key quality improvements addressed by this update. The bold text within the brackets indicates the item or area of the change.
- [Security updates] This update provides security improvements. For more information about the security vulnerabilities resolved by this update, see the Security Update Guide
- [Secure Boot] This update includes additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates. Certificate deployment via Windows updates continues across supported PCs and non-managed business devices in the coming months.
If you've already installed previous updates, your device will download and install only the new updates included in this package.
Components updates
AI components
Servicing stack update
Known issues in this update
Microsoft is not currently aware of any issues with this update.
How to get this update
Before you install this update
Microsoft combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see Servicing stack updates.
Deployment
If you deploy dynamic updates such as this update to an existing Windows image, ensure the boot.stl file is included as part of the installation media. Failure to include the file might prevent devices from successfully starting from the installation media and can result in error code 0xc0430001.
Note
The boot.stl file is used during Secure Boot validation and must match the Windows version and architecture of the image you are updating.
To ensure the boot.stl file is included as part of the installation media, do one of the following:
- Use the Update WinPE script to update an existing Windows image. (Recommended)
- Manually copy the boot.stl file from the device Windows\Boot\EFI folder to the corresponding folder on your installation media before deploying the update.
For information about how to apply Dynamic Update packages to existing Windows images, see Update Windows installation media with Dynamic Update.
Install this update
To install this update, use one of the following Windows and Microsoft release channels.
Windows Update
Available Next Step
✅ This update downloads and installs automatically from Windows Update and Microsoft Update.
File information
For a list of the files provided in this update, download the file information for cumulative update KB5121003.
For a list of the files provided in the servicing stack update, download the file information for the SSU (KB5123304) - version 26100.9156.
Related topics
Windows monthly updates explained
Description of the standard terminology used for Microsoft software updates
Microsoft Store for Business and Education with Configuration Manager
Get updates for apps and games in Microsoft Store
Original source - Aug 3, 2026
- Date parsed from source:Aug 3, 2026
- First seen by Releasebot:Aug 5, 2026
Windows news you can use: July 2026
Windows adds July updates for IT admins, with new security, device management, Windows Server, Windows 365, accessibility, and lifecycle planning highlights. It brings passkeys, settings backup, RDP Multipath, Arc-enabled hotpatching, redesigned Start, and other Windows 11 improvements.
New in Windows update and device management
- [WINDOWS 365] [AI] – New details are available to help you explore Windows 365 for Agents. Learn more about building secure, managed Cloud PC environments that extend enterprise identity, security, compliance, and governance controls to agentic workloads.
- [BACKUP] – Windows 11, version 26H2 will enable Windows settings backup by default on eligible devices. Improve resiliency by automatically backing up user settings and Microsoft Store app lists. Unfamiliar with the Windows settings backup and restore experience? Take a quick video tour.
- [INTUNE] – As of July 1, advanced Microsoft Intune Suite capabilities are included in Microsoft 365 E5, with select capabilities available in Microsoft 365 E3.
- [INTUNE] – The updated per-device sync experience in the Intune admin center now shows progress. Confirm more easily that actions are running and understand where they are in the process.
- [WINDOWS 365] [AZURE VIRTUAL DESKTOP] [NETWORKING] – Windows 365 and Azure Virtual Desktop now support RDP Multipath with redundant TCP. Check out a more resilient remote desktop experience with improved connectivity and fewer disconnects.
- [SERVICING] – Looking for a quick refresh on monthly update types and release schedules? To help you make informed decisions about your update management strategy, check out Understanding Windows monthly updates: Servicing explained.
- [TOOLS] – The latest Sysinternals updates add new tools. These include JPEG and WEBP snip support for ZoomIt and a new timeout option for ProcDump. Additionally, security protections in LiveKD help prevent non-administrators from viewing potentially sensitive debugging data in dump files.
New in Windows security
- [AI] – As AI accelerates vulnerability discovery, Windows is investing in AI-powered tools. They can identify security issues earlier, accelerate remediation, help strengthen validation processes, and deliver fast, high-quality security updates.
- [SSO] – A new Windows policy gives you greater control over sign-in experiences. You can now automatically accept single sign-on (SSO) permissions on managed devices.
- [PASSKEYS] [ENTRA] – Microsoft Entra ID is updating its authentication experience by making passkeys the default phishing-resistant authentication method. This lets you reduce reliance on phishable methods such as SMS and voice.
- [KMS] [TPM] – Upcoming KMS enhancements use TPM-backed hardware attestation to strengthen activation integrity by tying activation to a trusted host rather than only to a software configuration. TPM attestation helps prove that the KMS host is a real, trusted server and has not been tampered with before it is allowed to activate Windows devices.
- [AI] – Microsoft introduces Project Perception, a next-generation security platform that uses AI to continuously perceive, reason about, and respond to threats. With it, defenders can better keep pace with the speed and scale of AI-era attacks. For details on how Microsoft is using AI to proactively identify security risks, strengthen platform defenses, and advance quantum-safe security across products and services, check out the latest Secure Future Initiative report.
To explore what’s new in security across the Microsoft platform, see What’s new in Microsoft Security: July 2026.
New in Windows Server
For the latest features and improvements for Windows Server, see the Windows Server 2025 release notes and Windows Server, version 23H2 release notes.
- [HOTPATCH] – Arc-enabled hotpatch updates for Windows Server 2025 are now available at no additional cost. Use them to apply most security updates without restarting servers. This feature helps reduce downtime while maintaining security compliance through Azure Arc and Azure Update Manager.
- [TPM] – Trusted Launch for virtual machines (TVMs) is now available in the Windows Server Insider Program. Strengthen VM security with Secure Boot and vTPM protections against sophisticated firmware and boot attacks.
- [SECURITY] – New guidance is available for managing RDP file security through Group Policy. Help your organization reduce phishing risks by controlling which .rdp files users can open.
- [HARDENING] – The July 2026 security update introduces a security hardening change that enforces TDI transport registration requirements. As applications that use sockets over unregistered third-party TDI transports might stop working after installing this update, learn how to determine if you’re affected and manage the behavior.
- [HARDENING] – Starting with the October 2026 security update, AD FS Distributed Key Manager (DKM) container ACL hardening remediations will run by default on supported versions of Windows Server.
New in productivity and collaboration
Install the July 2026 security update for Windows 11, versions 25H2 and 24H2 to get these and other capabilities, which will be rolling out gradually:
- [START] – A redesigned Start menu is available on commercial and managed Windows devices. Customize the experience for your organization using the Start Policy CSP and Start policy settings.
- [ACCESSIBILITY] – Accessibility improvements make it easier for people to work their way. Now available are the new full-screen color overlay for greater visual comfort, more precise zoom controls in Magnifier, and expanded voice access and voice typing support in French, German, and Spanish.
- [WIDGETS] – A quieter, more focused Widgets experience helps reduce interruptions and improves default settings and notification controls.
- [NETWORKING] – Connections used by apps and system features, such as the NetUseAdd function, now work more reliably, including unauthenticated (null session) connections. This makes it easier for devices to access shared network resources.
New features and improvements are coming in the August 2026 security update. You can preview them by installing the July 2026 optional non-security update for Windows 11, versions 25H2 and 24H2. This update includes the gradual rollout of:
- [FILE EXPLORER] – File sizes in the Details view now display using appropriate units (KB, MB, GB) instead of KB-only. We hope it helps you understand them easier at a glance.
- [ACCESSIBILITY] – Voice Access now features Voice Isolation. As such, it recognizes your voice better by reducing interference from other speakers and background noise. Voice Access also now supports Korean.
- [SECURITY] – Windows Hello Enhanced Sign-in Security (ESS) support for peripheral fingerprint sensor is now beginning to roll out. Start using fingerprint sensors for desktops and other Windows 11 PCs, including Copilot+ PCs.
To learn about planned productivity, security, and reliability updates for Windows 11, visit the Windows Roadmap.
Lifecycle reminders
- [W11] [24H2] – On October 13, 2026, Windows 11, version 24H2 Home and Pro editions will reach end of updates. After this date, devices running these editions will no longer receive monthly security and non-security preview updates containing protections from the latest security threats. Enterprise and Education editions remain supported until October 12, 2027.
- [W10] [LSTB] - On October 13, 2026, Windows 10 Enterprise LTSB 2016 will reach end of updates. We recommend updating to the latest LTSC release, Windows 11 Enterprise LTSC 2024. If you need additional time to complete the transition, Extended Security Updates (ESU) will be available.
- [SERVER] [2022] – On October 13, 2026, Windows Server 2022 will reach end of mainstream support. After this date, Windows Server 2022 will transition to extended support, which includes security updates at no additional cost. These devices will continue to receive monthly security updates through October 14, 2031. For detailed information, see the Windows Server 2022 lifecycle page.
Check out our lifecycle documentation for the latest updates on Deprecated features in the Windows client and Windows Server 2025.
Additional resources
Looking for the latest news and previews for Windows, Copilot, Copilot+ PCs, the Windows and Windows Server Insider Programs? Find out this and more through the following resources:
- Windows Roadmap for new Windows features – filter by platform, version, status, and channel or search by feature name
- Microsoft 365 Copilot release notes for latest features and improvements
- Windows Insider Blog for what’s available in the Beta and Experimental channels
- Windows Server Insider for feature preview opportunities
- Understanding update history for Windows Insider preview features, fixes, and changes to learn about the types of updates for Windows Insiders
Join the conversation
Is this update missing areas or topics you want us to include? Drop us a note in the Comments and share your thoughts on what you’d like to see.
Continue the conversation. Find best practices. Bookmark the Windows Tech Community. Looking for support? Visit Windows on Microsoft Q&A.
Original source - Jul 28, 2026
- Date parsed from source:Jul 28, 2026
- First seen by Releasebot:Jul 31, 2026
July 28, 2026—KB5101681 (OS Build 28000.2608) Preview
Windows releases the Windows 11 version 26H1 cumulative update KB5101681 with production-quality improvements, AI-powered PC experience updates, and fixes. It rolls out in gradual and normal phases, with no known issues reported.
This cumulative update for Windows 11, version 26H1 (KB5101681), includes production-quality improvements.
Announcements and messages
This section provides key notifications related to this release, including announcements, change logs, and end-of-support notices.
Highlights
This update is available through two release phases: gradual rollout and normal rollout. A gradual rollout delivers an update in phases, so features reach devices over time instead of all at once, meaning availability varies by device. A normal rollout is the broad release to all eligible devices at the same time, usually when it reaches general availability (GA).
The following summary outlines features from AI-powered Windows 11 PC experiences, along with improvements and fixes. The bold text within the brackets indicates the item or area of the change.
Known issues in this update
Microsoft is not currently aware of any issues with this update.
How to get this update
Before you install this update
Microsoft combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see Servicing stack updates.
Deployment
If you deploy dynamic updates such as this update to an existing Windows image, ensure the boot.stl file is included as part of the installation media. Failure to include the file might prevent devices from successfully starting from the installation media and can result in error code 0xc0430001.
Note
The boot.stl file is used during Secure Boot validation and must match the Windows version and architecture of the image you are updating.
To ensure the boot.stl file is included as part of the installation media, do one of the following:
- Use the Update WinPE script to update an existing Windows image. (Recommended)
- Manually copy the boot.stl file from the device Windows\Boot\EFI folder to the corresponding folder on your installation media before deploying the update.
For information about how to apply Dynamic Update packages to existing Windows images, see Update Windows installation media with Dynamic Update.
Install this update
To install this update, use one of the following Windows and Microsoft release channels.
Windows Update
Available: Included
Next Step: Open Start > Settings > Windows Update > Advanced options > Optional updates. In the Optional updates available area, you will find the link to download and install available updates. Check for optional updates
File information
For a list of the files provided in this update, download the file information for cumulative update 5101681.
For a list of the files provided in the servicing stack update, download the file information for the SSU (KB5101747) - version 28000.2602.
Related topics
Windows monthly updates explained
Description of the standard terminology used for Microsoft software updates
Original source Similar to Windows with recent updates:
- Microsoft 365 updates70 release notes · Latest Aug 18, 2026
- Claude updates131 release notes · Latest Aug 25, 2026
- Microsoft Copilot updates37 release notes · Latest Aug 11, 2026
- OpenAI updates186 release notes · Latest Aug 25, 2026
- Anthropic updates57 release notes · Latest Aug 14, 2026
- Gemini updates396 release notes · Latest Aug 25, 2026
- Jul 28, 2026
- Date parsed from source:Jul 28, 2026
- First seen by Releasebot:Jul 31, 2026
July 28, 2026—KB5101684 (OS Builds 26200.8973 and 26100.8973) Preview
Windows releases a cumulative update for Windows 11 25H2 and 24H2 with production-quality improvements, AI-powered PC experience updates, and fixes. It also includes a Secure Boot certificate expiration notice and no known issues.
This cumulative update for Windows 11, version 25H2 and 24H2 (KB5101684), includes production-quality improvements.
Announcements and messages
This section provides key notifications related to this release, including announcements, change logs, and end-of-support notices.
Windows Secure Boot certificate expiration
Important: Secure Boot certificates used by most Windows devices expire starting in June 2026. Microsoft has been updating these certificates on consumer and non-managed business devices over the past several months. Devices that haven’t received the newer certificates will continue to start and operate normally, and standard Windows updates will continue to install. Updated certificates will continue to be delivered through Windows Update in the coming months. For more information, see Windows Secure Boot certificate expiration and CA updates.
Highlights
This update is available through two release phases: gradual rollout and normal rollout. A gradual rollout delivers an update in phases, so features reach devices over time instead of all at once, meaning availability varies by device. A normal rollout is the broad release to all eligible devices at the same time, usually when it reaches general availability (GA).
The following summary outlines features from AI-powered Windows 11 PC experiences, along with improvements and fixes. The bold text within the brackets indicates the item or area of the change.
Known issues in this update
Microsoft is not currently aware of any issues with this update.
How to get this update
Before you install this update
Microsoft combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see Servicing stack updates.
Deployment
If you deploy dynamic updates such as this update to an existing Windows image, ensure the boot.stl file is included as part of the installation media. Failure to include the file might prevent devices from successfully starting from the installation media and can result in error code 0xc0430001.
Note
The boot.stl file is used during Secure Boot validation and must match the Windows version and architecture of the image you are updating.
To ensure the boot.stl file is included as part of the installation media, do one of the following:
- Use the Update WinPE script to update an existing Windows image. (Recommended)
- Manually copy the boot.stl file from the device Windows\Boot\EFI folder to the corresponding folder on your installation media before deploying the update.
For information about how to apply Dynamic Update packages to existing Windows images, see Update Windows installation media with Dynamic Update.
Install this update
To install this update, use one of the following Windows and Microsoft release channels.
Windows UpdateOpen Start > Settings > Windows Update > Advanced options > Optional updates. In the Optional updates available area, you will find the link to download and install available updates. Check for optional updates
File information
For a list of the files provided in this update, download the file information for cumulative update 5101684.
For a list of the files provided in the servicing stack update, download the file information for the SSU (KB5101711) - version 26100.8962.
Related topics
Windows monthly updates explained
Description of the standard terminology used for Microsoft software updates
Microsoft Store for Business and Education with Configuration Manager
Get updates for apps and games in Microsoft Store
Original source - July 2026
- No date parsed from source.
- First seen by Releasebot:Jul 26, 2026
Windows 11, version 24H2 update history
Windows 11 version 24H2 brings a broad feature update with Copilot+ PC exclusives, Wi‑Fi 7 support, Bluetooth LE Audio improvements, a more streamlined File Explorer, smarter power management, QR code Wi‑Fi sharing, stronger privacy controls, and better Teams, Voice Clarity, Sudo, and Remote Desktop experiences.
Windows 11 is a service, which means it gets better through periodic feature updates. We take a phased and measured approach to rolling out every feature update. That means you’ll receive Windows 11, version 24H2 when data shows that your device is ready and that you will have a great update experience.
On the left side of this page, you’ll find a list of all the updates released for this version of Windows. You can also find more information about releases and any known issues. Installing the most recent update ensures that you also get any previous updates you might have missed, including any important security fixes.
For more information about the update and how to get it, see:
- Inside this update: Windows 11 2024 Update
- How to get new experiences for Windows 11
- What's new in Windows 11, version 24H2
- Windows 11 specifications
What's new for Windows 11, version 24H2
Windows 11, version 24H2 includes all the features and capabilities delivered as part of continuous innovation to Windows 11, now enabled by default. This scoped release also features enhancements designed to improve your overall experience with Windows 11. Highlights include:
- Copilot+ PCs exclusive features:
- Live Captions
- Cocreator in Paint
- Windows Studio Effects
- Auto Super Resolution
- Image Creator and Restyle Image
- Wi-Fi 7 support
- Bluetooth® LE Audio enhancements for assistive hearing devices support
- System tray & taskbar enhancements
- A more streamlined File Explorer
- Smart power management for your PC
- Join and share Wi-Fi networks with QR codes
- Enhanced privacy controls for Wi-Fi network access
- Effortless account management and notifications in Microsoft Teams
- Expanding Voice Clarity across devices
- Sudo for Windows: elevate the Windows command-line efficiency
- Remote Desktop: enhanced connectivity and accessibility
Known issues in this update
For the most up-to-date information about known issues for Windows 11, version 24H2, please go to the Windows release health dashboard.
Issues:
All users: Language selection page during Out of Box Experience (OOBE) may display incorrect translation on the 'Continue' button if device manufacturer used an image based on August 2024 non-security preview update (KB5041865) or September 2024 security update (KB5043080). The installation continues in selected language after clicking the button. This issue does not apply if applying updates via Windows Update release channel or Microsoft Update Catalog. Resolved in non-security preview update released September 30, 2024 (KB5043178).
Enterprise users: After fresh install or In-place upgrade to Windows 11, version 24H2, issues with DirectAccess connection may occur, remaining in 'connecting' state. Affected devices show error code 0x57 and failed connection to IPHTTPS server. More likely if remotely connecting to corporate intranet using DirectAccess. Home users unlikely affected. Enterprise customers recommended to evaluate Always On VPN (AOVPN) until fix available. Issue addressed in KB5044384.
Troubleshooting
If you have questions or need help activating or troubleshooting Windows, see our help topics below:
- Troubleshoot Windows 11 upgrade and Installation errors
- Troubleshoot problems updating Windows
- Jul 18, 2026
- Date parsed from source:Jul 18, 2026
- First seen by Releasebot:Jul 20, 2026
July 18, 2026—KB5121767 (OS Builds 26200.8894 and 26100.8894) Out-of-band
Windows ships an out-of-band update for Windows 11 25H2 and 24H2 that rolls up prior fixes and adds a performance-related fix for devices with Intel IPF drivers. It also improves update reliability through a servicing stack update and updates AI components.
This out-of-band (OOB) update for Windows 11, version 25H2 and Windows 11, version 24H2 (KB5121767) is cumulative. It includes all improvements from previous security and non-security updates, along with an additional fix.
Improvements
This OOB update includes the following improvement:
- [System Performance] This update addresses an issue affecting a limited number of devices with an Intel Innovation Platform Framework (Intel IPF) driver that could cause changes in performance, power consumption, or system behavior after installing recent Windows updates. A limited number of Dell devices that were temporarily prevented from receiving the July 2026 security update KB5101650 can now install this OOB update. This OOB update is only recommended for devices affected by this issue. If your device is not affected, no action is required.
Note
If you have turned on Get the latest updates as soon as they're available in Windows Update settings (Settings > Windows Update), you will automatically receive this OOB update. If the toggle is off on your device, you can install the update by going to Settings > Windows Update and selecting Download & Install. This OOB update is also available from the Microsoft Update Catalog.
Component updates
Servicing stack update (SSU)
Includes KB5120102 (Build 26100.8872), which improves the reliability of the Windows update installation process. To learn more about SSUs, see Simplifying on-premises deployment of servicing stack updates.
AI components
Updated to version 1.2605.856.0 (Image Search, Content Extraction, Semantic Analysis, Settings Model).
How to get this update
Before you install this update
Microsoft now combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see Servicing stack updates and Servicing Stack Updates (SSU): Frequently Asked Questions.
Install this update
To install this update, use one of the following Windows and Microsoft release channels.
Windows Update
This update is an optional update. To install this optional update, go to Settings > Windows Update > Advanced options > Optional updates.
File Information
For a list of the files provided in this update, download the file information for cumulative update KB5121767.
Original source
For a list of the files provided in the servicing stack update, download the file information for the SSU (KB5120102) - version 26100.8872. - Jul 15, 2026
- Date parsed from source:Jul 15, 2026
- First seen by Releasebot:Jul 16, 2026
Now available: Admin control for SSO prompts in Windows
Windows adds an admin registry control that lets IT teams automatically accept SSO permissions on managed Windows 11 devices, reducing sign-in prompts for eligible enterprise users starting with the July 2026 monthly security update.
Background: What changed and why
IT administrators can now automatically accept SSO permissions on managed Windows devices using a supported registry setting. In this context, SSO, or single sign-on, refers to using the Microsoft credentials from a user’s Windows sign-in to access other Microsoft apps and services without seeing any prompts. This new capability is available beginning with the July 2026 monthly security update (2026—KB5101650) for Windows 11, version 24H2 and 25H2.
In the European Economic Area (EEA), Microsoft updated the Windows sign-in experience so that users are not automatically signed in to other Microsoft applications and services after signing in to Windows. Instead, Windows asks users whether they want to use the same credentials to sign in to additional apps or services — giving users choice over how their Windows account is used for sign-in.
For managed enterprise environments, some organizations wanted additional flexibility to manage the SSO prompt experience on devices where their organizations already manage sign-in policies and trust relationships. To support those scenarios, we’ve developed a registry-based control that lets IT administrators automatically accept SSO permissions on eligible managed Windows devices.
What’s new: Enterprise admin control for sign-in behavior
Starting with the July 2026 monthly security update for Windows 11, version 24H2 and 25H2, IT administrators can deploy the following registry policy to automatically accept SSO permissions on managed devices:
Registry Path:
HKLM\SOFTWARE\Policies\Microsoft\Windows\AADValue:
AutoAcceptSsoPermission (DWORD) = 1This policy can be deployed via:
- Group Policy (GPO)
- Microsoft Intune or similar mobile device management (MDM) tool
- Microsoft Configuration Manager
- Any management tool that supports registry policy deployment
Important details
- Scope: Applies only to managed enterprise devices with Microsoft Entra ID accounts
- Personal accounts: Prompts remain for personal Microsoft accounts (MSA)
- Unmanaged devices: Not affected —prompts remain for non-policy-controlled environments
- Supported OS: Windows 11, version 24H2 and 25H2
Getting started
To get started:
- Ensure that your devices are running Windows 11, version 24H2 and 25H2 or later.
- Install the July 2026 monthly security update.
- Deploy the registry policy via GPO, Intune, or your preferred management tool.
- Validate SSO behavior across your managed device fleet.
For detailed deployment guidance, visit Admin control for SSO prompts in Windows.
What’s next
We’re continuing to evaluate additional admin controls and transparency features that will give your organization greater confidence in managing authentication experiences across your device fleet. Have feedback? Share your ideas in the Comments.
Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us on LinkedIn or @MSWindowsITPro for updates. Looking for support? Visit Windows on Microsoft Q&A.
Original source - Jul 14, 2026
- Date parsed from source:Jul 14, 2026
- First seen by Releasebot:Jul 15, 2026
July 14, 2026—KB5101649 (OS Build 28000.2525)
Windows releases a cumulative update for Windows 11 version 26H1 with the latest security fixes, quality improvements, Secure Boot coverage boosts, a fix for Office-related app launch issues, and stronger RDP publisher certificate guidance.
This cumulative update for Windows 11, version 26H1 (KB5101649) includes the latest security fixes and improvements, along with non-security updates from last month's optional preview release. Visit the Windows release health dashboard for the latest status on this release.
Improvements
This update includes new features and quality improvements that were part of the following update:
- June 9, 2026—KB5095051 (OS Build 28000.2269)
- June 23, 2026—KB5095091 (OS Build 28000.2340) Preview
This update addresses security vulnerabilities documented in the following guide:
- July 2026 Security Updates
The following summary outlines key quality improvements addressed by this update. The bold text within the brackets indicates the item or area of the change.
- [Secure Boot] This update includes additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates. Certificate deployment via Windows updates continues across supported PCs and non-managed business devices in the coming months.
- [Apps (Known issue)] Fixed: This update addresses an issue that affects certain third-party apps that use OLE Automation to interact with Microsoft Office. After installing the June 2026 security update (KB5095091), these apps might fail to launch Office or open documents.
- [Input] This update changes hotkey unregister and cleanup behavior. In rare cases, some built-in Windows experiences that rely on previous hotkey lifecycle behavior might temporarily stop responding to certain keyboard shortcuts. This issue can typically be resolved by restarting the app affected. If the issue is not resolved, report it through the Feedback Hub.
- [Management] With this update, at.exe and schedcli.dll can no longer be used to administer "AT Time" or ATSvc servers. Microsoft recommends discontinuing use of ATServer, which has been disabled by default since Windows Server 2012. Developers and system administrators should expect AT.exe and ATServer to be removed in future versions of Windows. The AT Client, at.exe is replaced by "schtasks.exe", PowerShell ScheduledTasks commands, and the ITaskSchedulerService interface.
- [Networking] This update introduces a security hardening change that enforces TDI transport registration requirements. As a result, applications that use sockets over unregistered third-party TDI transports might stop working after installing this update. Registered TDI transports are not affected. For more information, see Third-party TDI transports might stop working after installing Windows security updates released on or after July 14, 2026.
- [Remote Desktop (RDP) Security] Support for SHA-2 certificate thumbprints has been added for trusted RDP publishers, with SHA-1 support retained only for backward compatibility and planned for future removal. New guidance is available for managing RDP file security through Group Policy to help organizations reduce phishing risks by controlling which .rdp files users can open. We recommend IT administrators migrate to SHA-256 thumbprints or a stronger algorithm as soon as possible to avoid disruption.
If you've already installed previous updates, your device will download and install only the new updates included in this package.
Components updates
Known issues in this update
Microsoft is not currently aware of any issues with this update.
How to get this update
Before you install this update
Microsoft combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see Servicing stack updates.
Deployment
If you deploy dynamic updates such as this update to an existing Windows image, ensure the boot.stl file is included as part of the installation media. Failure to include the file might prevent devices from successfully starting from the installation media and can result in error code 0xc0430001.
Note
The boot.stl file is used during Secure Boot validation and must match the Windows version and architecture of the image you are updating.
To ensure the boot.stl file is included as part of the installation media, do one of the following:
- Use the Update WinPE script to update an existing Windows image. (Recommended)
- Manually copy the boot.stl file from the device Windows\Boot\EFI folder to the corresponding folder on your installation media before deploying the update.
For information about how to apply Dynamic Update packages to existing Windows images, see Update Windows installation media with Dynamic Update.
Install this update
To install this update, use one of the following Windows and Microsoft release channels.
File information
For a list of the files provided in this update, download the file information for cumulative update 5101649.
For a list of the files provided in the servicing stack update, download the file information for the SSU (5121292) - version 28000.2524.
Related topics
Windows monthly updates explained
Description of the standard terminology used for Microsoft software updates
Windows release health
Original source - Jul 14, 2026
- Date parsed from source:Jul 14, 2026
- First seen by Releasebot:Jul 15, 2026
July 14, 2026—KB5099414 (OS Build 22631.7376)
Windows ships a Windows 11 23H2 cumulative update with the latest security fixes and quality improvements, plus Secure Boot certificate coverage updates, File Explorer and Recycle Bin fixes, curl security upgrades, and new RDP security guidance to help reduce phishing risk.
This cumulative update for Windows 11, version 23H2 (KB5099414), includes the latest security fixes and improvements, along with non-security updates from last month’s optional preview release. Visit the Windows release health dashboard for the latest status on this release.
Want a quick overview? Watch the Windows 11, version 24H2 and version 25H2 video.
Announcements and messages
This section provides key notifications related to this release, including announcements, change logs, and end-of-support notices.
Windows Secure Boot certificate expiration
Important: Secure Boot certificates used by most Windows devices are set to expire starting in June 2026. Microsoft has been updating these certificates on consumer and non-managed business devices over the past several months. Devices that haven’t received the newer certificates will continue to start and operate normally, and standard Windows updates will continue to install. Updated certificates will continue to be delivered through Windows Update in the coming months.
Improvements
This update addresses security issues for your Windows operating system.
Important
Use EKB KB5027397 to update to Windows 11, version 23H2.
This security update contains fixes and quality improvements from KB5093998 (released June 09, 2026). The following summary outlines key issues addressed by this update. Also, included are available new features. The bold text within the brackets indicates the item or area of the change.
- [Secure Boot] This update includes additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates. Certificate deployment via Windows updates continues across supported PCs and non-managed business devices in the coming months.
- [Apps (Known issue)] Fixed: This update addresses an issue that affects certain third-party apps that use OLE Automation to interact with Microsoft Office. After installing the June 2026 security update (KB5093998), these apps might fail to launch Office or open documents.
- [Country and Operator Settings Asset (COSA)] This update brings profiles up to date for certain mobile operators.
- [File Explorer (known issue)] Fixed: An issue where the OneDrive shortcut in File Explorer stops working when File Explorer is run with administrative mode.This issue might occur after installing the June 2026 security update (KB5093998).
- [Input] This update changes hotkey unregister and cleanup behavior. In rare cases, some built-in Windows experiences that rely on previous hotkey lifecycle behavior might temporarily stop responding to certain keyboard shortcuts. This issue can typically be resolved by restarting the app affected. If the issue is not resolved, report it through the Feedback Hub.
- [Networking] This update introduces a security hardening change that enforces TDI transport registration requirements. As a result, applications that use sockets over unregistered third-party TDI transports might stop working after installing this update. Registered TDI transports are not affected. For more information, see Third-party TDI transports might stop working after installing Windows security updates released on or after July 14, 2026.
- [Recycle Bin (known issue)] Fixed: This update addresses an issue where the confirmation dialog might display an internal Recycle Bin file name instead of the original file name when permanently deleting a file. This issue might occur after installing the June 2026 security update (KB5093998).
- [Security] This update upgrades the curl tool in Windows to version 8.21.0 and includes security improvements that help protect your device.
- [Remote Desktop (RDP) Security] Support for SHA-2 certificate thumbprints has been added for trusted RDP publishers, with SHA-1 support retained only for backward compatibility and planned for future removal. New guidance is available for managing RDP file security through Group Policy to help organizations reduce phishing risks by controlling which .rdp files users can open. We recommend IT administrators migrate to SHA-256 thumbprints or a stronger algorithm as soon as possible to avoid disruption.
If you've already installed previous updates, your device will download and install only the new updates included in this package.
For more information about security vulnerabilities, see the Security Update Guide and the July 2026 Security Update.
Windows 11 servicing stack update (KB5104023) - 22621.7373
This update makes quality improvements to the servicing stack, which is the component that installs Windows updates. Servicing stack updates (SSU) ensure that you have a robust and reliable servicing stack so that your devices can receive and install Microsoft updates. To learn more about SSUs, see Simplifying on-premises deployment of servicing stack updates.
Known issues in this update
Microsoft is not currently aware of any issues with this update.
How to get this update
Before you install this update
Microsoft combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see Servicing stack updates.
Deployment
If you deploy dynamic updates such as this update to an existing Windows image, ensure the boot.stl file is included as part of the installation media. Failure to include the file might prevent devices from successfully starting from the installation media and can result in error code 0xc0430001.
Note
The boot.stl file is used during Secure Boot validation and must match the Windows version and architecture of the image you are updating.
To ensure the boot.stl file is included as part of the installation media, do one of the following:
- Use the Update WinPE script to update an existing Windows image. (Recommended)
- Manually copy the boot.stl file from the device Windows\Boot\EFI folder to the corresponding folder on your installation media before deploying the update.
For information about how to apply Dynamic Update packages to existing Windows images, see Update Windows installation media with Dynamic Update.
Install this update
To install this update, use one of the following Windows and Microsoft release channels.
Windows Update
Available
This update downloads and installs automatically from Windows Update and Microsoft Update.
File information
For a list of the files provided in this update, download the file information for cumulative update 5099414.
For a list of the files provided in the servicing stack update, download the file information for the SSU (KB5104023) - versions 22621.7373.
Related topics
Windows release health
Microsoft Store for Business and Education with Configuration Manager
Get updates for apps and games in Microsoft Store
Original source - Jul 14, 2026
- Date parsed from source:Jul 14, 2026
- First seen by Releasebot:Jul 15, 2026
July 14, 2026—KB5101650 (OS Builds 26200.8875 and 26100.8875)
Windows ships a cumulative Windows 11 update with the latest security fixes and quality improvements, including Secure Boot certificate targeting, an OLE Automation app fix, Recycle Bin fixes, curl 8.21.0, and stronger RDP certificate thumbprint support.
This cumulative update for Windows 11, version 25H2 and 24H2 (KB5101650) includes the latest security fixes and improvements, along with non-security updates from last month's optional preview release. Visit the Windows release health dashboard for the latest status on this release.
Want a quick overview?: Watch the Windows 11 release note video for this update.
Announcements and messages
This section provides key notifications related to this release, including announcements, change logs, and end-of-support notices.
Update temporarily unavailable for some Dell devices with Intel processors
Important
This update might not be available for a limited number of Dell devices with Intel processors due to an incompatibility reported by Dell that can potentially cause unexpected shutdowns, poor performance, increased heat, and battery drain. We are working together with Dell to prevent the affected models from experiencing the issue and plan to release a resolution for affected devices in the coming days.
Improvements
This update includes new features and quality improvements that were part of the following update:
- June 9, 2026—KB5094126 (OS Builds 26200.8655 and 26100.8655)
- June 23, 2026—KB5095093 (OS Builds 26200.8736 and 26100.8736) Preview
This update addresses security vulnerabilities documented in the following guide:
- July 2026 Security Updates
The following summary outlines key quality improvements addressed by this update. The bold text within the brackets indicates the item or area of the change.
- [Secure Boot] This update includes additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates. Certificate deployment via Windows updates continues.
- [Apps (Known issue)] Fixed: This update addresses an issue that affects certain third-party apps that use OLE Automation to interact with Microsoft Office. After installing the June 2026 security update (KB5094126), these apps might fail to launch Office or open documents.
- [Input] This update changes hotkey unregister and cleanup behavior. In rare cases, some built-in Windows experiences that rely on previous hotkey lifecycle behavior might temporarily stop responding to certain keyboard shortcuts. This issue can typically be resolved by restarting the app affected. If the issue is not resolved, report it through the Feedback Hub.
- [Networking] This update introduces a security hardening change that enforces TDI transport registration requirements. As a result, applications that use sockets over unregistered third-party TDI transports might stop working after installing this update. Registered TDI transports are not affected. For more information, see Third-party TDI transports might stop working after installing Windows security updates released on or after July 14, 2026.
- [Recycle Bin (known issue)] Fixed: This update addresses additional scenarios where the confirmation dialog might display an internal Recycle Bin file name instead of the original file name when permanently deleting a file. This issue might occur after installing the June 2026 security update (KB5094126).
- [Security] This update upgrades the curl tool in Windows to version 8.21.0 and includes security improvements that help protect your device.
- [Remote Desktop (RDP) Security] Support for SHA-2 certificate thumbprints has been added for trusted RDP publishers, with SHA-1 support retained only for backward compatibility and planned for future removal. New guidance is available for managing RDP file security through Group Policy to help organizations reduce phishing risks by controlling which .rdp files users can open. We recommend IT administrators migrate to SHA-256 thumbprints or a stronger algorithm as soon as possible to avoid disruption.
If you've already installed previous updates, your device will download and install only the new updates included in this package.
Known issues in this update
Microsoft is not currently aware of any issues with this update.
How to get this update
Before you install this update
Microsoft combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see Servicing stack updates.
Deployment
If you deploy dynamic updates such as this update to an existing Windows image, ensure the boot.stl file is included as part of the installation media. Failure to include the file might prevent devices from successfully starting from the installation media and can result in error code 0xc0430001.
Note
The boot.stl file is used during Secure Boot validation and must match the Windows version and architecture of the image you are updating.
To ensure the boot.stl file is included as part of the installation media, do one of the following:
- Use the Update WinPE script to update an existing Windows image. (Recommended)
- Manually copy the boot.stl file from the device Windows\Boot\EFI folder to the corresponding folder on your installation media before deploying the update.
For information about how to apply Dynamic Update packages to existing Windows images, see Update Windows installation media with Dynamic Update.
Install this update
To install this update, use one of the following Windows and Microsoft release channels.
Windows Update
Available: Included
Next Step: This update downloads and installs automatically from Windows Update and Microsoft Update.
File information
For a list of the files provided in this update, download the file information for cumulative update 5101650.
For a list of the files provided in the servicing stack update, download the file information for the SSU (KB5120102) - version 26100.8872.
Related topics
Windows monthly updates explained
Description of the standard terminology used for Microsoft software updates
Microsoft Store for Business and Education with Configuration Manager
Get updates for apps and games in Microsoft Store
Original source - Jul 6, 2026
- Date parsed from source:Jul 6, 2026
- First seen by Releasebot:Jul 7, 2026
Windows settings backup becoming a new resilience baseline
Windows adds default-on backup for eligible managed devices, making Windows settings backup and Microsoft Store app recovery a built-in baseline. The change is available now to Windows Insiders and will roll out with Windows 11, version 26H2, while restore stays admin-controlled.
Resilience is about to get easier for the Windows devices you manage! Eligible devices will now have the backup function on by default with Windows settings backup and restore (previously called Windows Backup for Organizations). Today, it's available to Windows Insiders and will be generally available starting with Windows 11, version 26H2. A recoverable list of settings and Microsoft Store apps is becoming a baseline part of the Windows experience rather than an opt-in configuration step.
Note: Restore behavior is unchanged and isn't enabled by default. You still need explicit admin configuration to restore Windows devices
A baseline designed with IT admins in mind
Staying resilient today is no longer a nice-to-have for businesses. Resetting, replacing, and reimaging a PC is fundamental to onboarding and user experience. It's also a baseline for staying resilient.
Imagine a lost laptop, a hardware refresh, or an unexpected reset. These are some of the moments when your users need backup most. And that's rarely when anyone wants to discover that backup was never turned on.
Making backup the baseline shifts it from a best-effort configuration step to a standard capability across your eligible fleet.
- Recovery without configuration: Eligible devices with the backup policy in a Not Configured state under Windows settings backup and restore[1] will back up automatically. Users' settings and Microsoft Store app list are captured out of the box. Note: Restore behavior still requires configuration to be enabled.
- Explicit policy always wins: If you have already enabled or disabled the policy, your setting is honored. The default applies only when policy state is Not Configured.
- Restore stays admin-managed: The default-on change applies to backup only. The restore function continues to require explicit admin configuration and is off by default.
- User choice preserved: End user settings are protected automatically, and they keep full flexibility — they can run a backup at any time from the Windows Backup app and choose which settings are included from the Windows Settings page, all in line with the admin's policy.
We've experienced these benefits first-hand at Microsoft, when we made backups automatic for employees across the organization.
"Windows Backup for Organizations[1] is changing how device refresh works. Pressure tested inside Microsoft on a global scale, it enables Microsoft Store apps and user settings to move seamlessly with our people and free IT teams from the heavy lifting of device reimaging. The result is a simpler, more resilient experience." - Brian Fielder, Vice President, Microsoft Digital
The operational benefit is simple: When a device needs to be reset, replaced, or reimaged, you can move forward immediately. No need to rush checking whether backup was ever configured for the users. Their familiar setup is already captured and ready to come back with them.
The scope of the default-on Windows backup
The default-on behavior applies to devices that meet all these conditions:
- Running Windows 11, version 26H2[2] or later
- In countries or regions not regulated by the EU Digital Markets Act (DMA)Not in sovereign or restricted cloud environments
- With the backup policy in a Not Configured state under Windows settings backup and restore*
Devices outside this scope keep their existing behavior:
- Devices in privacy sensitive countries or regions remain off by default.
- Devices in sovereign or restricted cloud environments remain off by default.
- Devices with the backup policy explicitly enabled or disabled continue to honor that explicit setting.
- Devices running previous supported Windows 11 versions (except for version 26H1) remain off by default.
- Devices originally running Windows 11, version 26H1 will receive the same default-on treatment starting with the following feature update.
Getting started
If your environment is already in scope and in the state you want, you're ready. No action required. Otherwise, here's how to pick the behavior that fits your organization:
- Keep backup on (recommended): No action required. Eligible devices with the backup policy in a Not Configured state under Windows settings backup and restore* will enable backup automatically at general availability of Windows 11, version 26H2.
- Opt out: Explicitly disable the backup policy through Microsoft Intune, Group Policy, or your MDM solution. Explicit disablement always takes precedence over the default.
- Make intent explicit: Set the backup policy to enabled today. This is functionally equivalent to the new default but provides an unambiguous, audit-friendly admin signal, and the ability for user-targeted enablement only.
- Control restore behavior separately: Configure the restore policy on its own. The default-on change applies to backup only.
You can validate the experience early. The default-on behavior is available with Windows 11, version 26H2 in Windows Insider Program Experimental channel starting July 2026. It takes broad effect for eligible devices at Windows 11, version 26H2 general availability later this year. Devices originally running Windows 11, version 26H1 will receive the same default-on treatment starting with the following feature update.
Watch this video for a quick tour of the experience:
Ready for broader Windows resiliency
Thank you for your feedback that shaped this change. Making backup the baseline is one step in a broader Windows resiliency effort. We'll keep sharing what's coming next, so you can plan with confidence.
Catch up and learn more:
- Windows settings backup and restore
- Configure backup and restore policies in Microsoft Intune
- Windows Insider Blog
- Windows Insider release notes
- Windows first sign-in restore experience now available
- Windows Backup for Organizations is now available
[1] Windows Backup for Organizations is now Windows settings backup and restore. You'll start seeing the new name alongside the original name while we update documentation and policy surfaces.
[2] Windows 11, version 26H2 is the annual feature update for Windows 11, versions 25H2 and 24H2. It will be released in the second half of the 2026 calendar year.
Continue the conversation. Find best practices. Bookmark the Windows Tech Community. Looking for support? Visit Windows on Microsoft Q&A.
Original source - Jun 23, 2026
- Date parsed from source:Jun 23, 2026
- First seen by Releasebot:Jun 24, 2026
Best practices for deploying Secure Boot certificate updates
Windows expands Secure Boot certificate updates across the ecosystem, with automatic Windows Update delivery, new Windows Security app status messages, and stronger guidance for home users and IT teams to complete deployment with confidence.
Deploying Secure Boot certificate updates across the Windows ecosystem has required coordination across operating systems, device manufacturers, and firmware vendors. The steady and coordinated rollout is strengthening the platform root of trust worldwide.
Many individuals and organizations have already successfully updated certificates for client devices, servers, and virtual machines, with others close behind. Proven deployment and validation tools, automatic certificate installation via Windows updates, and firmware support from our OEM partners are helping us all move forward with confidence. However close you are, finishing Secure Boot certificate deployment remains important. If you're still on the path to finishing your Secure Boot certificate deployment, stay the course.
What we've seen work in practice
Every individual device and organization's environment is different.
In the commercial realm, across customer conversations, Ask Microsoft Anything (AMAs) events, and hands-on deployments, a few consistent patterns have emerged:
- Early testing builds confidence. Many organizations start with pilots, validate results, and expand rollouts as confidence grows for both Windows and IT teams.
- Layered deployment approaches work best. Teams have successfully deployed OEM firmware updates with Windows security updates, using a mix of automation and staged rollout.
- Multiple tools can lead to success. From Microsoft Intune to Group Policy, Azure automation, and PowerShell, there isn't a single "right" tool, only the right fit for your environment.
From talking with many of you, we learned that the diversity of tools and deployment approaches is a key reason the transition has succeeded at scale. Organizations are using a flexible resource set that meets their needs where they are.
For home users and organizations that allow Microsoft to manage Windows updates, the experience has been equally straightforward. A few takeaways stand out:
- Keeping devices up to date delivers the best experience. Individuals running supported versions of Windows and receiving regular Windows updates have generally received the newer certificates automatically. Don't pause Windows updates; keep them coming!
- Built-in protections simplify the update. Secure Boot is enabled by default on most modern PCs, helping these devices receive the newer certificates without manual configuration. Simply keep Secure Boot enabled or re-enable it if needed.
- Built-in tools help you be ready. The Windows Security app can help you track progress. It can show whether the new certificates have reached your device and whether Secure Boot remains enabled. If anything is preventing devices from receiving and applying the certificates, you can follow embedded instructions to make progress. Note: In enterprise environments, the Windows Security app is disabled by default.
Overall, for most supported Windows Home and Pro PCs and business devices managed by Microsoft, staying protected has been as simple as keeping Windows up to date and Secure Boot enabled.
NOTE: While most Secure Boot-enabled PCs receive the newer certificates through the monthly Windows update process, a small number might require a firmware update from the device manufacturer. The Windows Security app can help identify whether your device is waiting for a firmware update. In some cases, the firmware updates needed to support these changes might not be available for older device models, depending on the manufacturer's support lifecycle. Reach out to your device manufacturer if you encounter this case.
Our experience at Microsoft
Microsoft's internal deployment followed many of the same principles described throughout this post. We began with limited deployments, used validation and deployment signals to build confidence, and expanded over time. This phased approach helped us identify issues early, validate readiness, and scale deployment in a measured way.
Along the way, we encountered many of the same edge cases and scenarios that many of you are navigating. Those experiences shaped the tools and guidance we've continued to share externally, including:
- New Secure Boot status messages in the Windows Security app that help users understand certificate readiness and identify issues that might require attention.
- Secure Boot certificate update playbooks for both Windows Client and Windows Server, along with tailored guidance for Windows 365 and Azure Virtual Desktop.
- Multiple Ask Microsoft Anything sessions, now available on demand.
- Expanded tools for IT-managed environments, including event logs, PowerShell scripts, Microsoft Intune remediations, Microsoft Defender insights, and Windows Autopatch reporting.
Microsoft has been learning alongside you and turning those lessons into resources that you can use.
Keep going; you're on the right path
If you're an IT administrator still deploying Secure Boot certificate updates, you're not alone. Organizations and individuals are progressing at different speeds, based on their environments and requirements. This flexibility is intentional.
What we've seen consistently is that success comes from staying the course:
- Keep your devices up to date with the latest Windows updates.
- Check that the latest firmware version is installed. You can visit your OEM's support page or use their official support channels.
- Continue with your phased rollout. Gradual deployment of certificates, boot managers, and updated OEM firmware, along with validation, remains the most reliable approach.
- Use the tools available to you. Whether built into Windows, such as the Windows Security app, or designed for IT-managed environments, these tools help you monitor progress and make informed decisions.
Focus on progress over perfection. Each step forward strengthens your environment's platform root of trust.
Devices with older certificates will continue to function and receive updates, giving you time to complete deployment. Completing this transition helps ensure that your devices stay current with evolving Secure Boot protections.
Resources to support your next steps
We're nearly finished with rolling out automatic certificate updates to individual PCs and business devices. If you are still in the process of rolling out updates in your organization, these resources can help:
- Windows Secure Boot certificate expiration and CA updates
- Secure Boot playbook for certificates expiring in 2026
- Secure Boot playbook for Windows Server
- Secure Boot Certificate Updates for Windows 365
- Secure Boot Certificate Updates for Azure Virtual Desktop
- Secure Boot update: Trusted Launch VMs (TVM) and Confidential VMs (CVM)
In the coming weeks, there are also still opportunities to ask questions. Save the date for these upcoming events:
- July 1 – Windows Server Secure Boot AMA
- July 8 – Secure Boot Office Hours for virtualized environments
- July 15 – OEM Secure Boot Office Hours
Device owners using Windows Personal and Family accounts can use online support channels and phone numbers for additional help.
This has been a long and meaningful journey. Together, we have strengthened the platform root of trust that modern security depends on. Wherever you are in your certificates update process, you are contributing to that shared progress.
Original source - Jun 23, 2026
- Date parsed from source:Jun 23, 2026
- First seen by Releasebot:Jun 24, 2026
- Modified by Releasebot:Jun 24, 2026
June 23, 2026—KB5095091 (OS Build 28000.2340) Preview
Windows releases a cumulative update for Windows 11 version 26H1 with production-quality improvements, AI-powered PC experience updates, and fixes. The update rolls out gradually or broadly depending on device, and it also includes component updates and a servicing stack update.
This cumulative update for Windows 11, version 26H1 (KB5095091), includes production-quality improvements.
Highlights
This update is available through two release phases: gradual rollout and normal rollout. A gradual rollout delivers an update in phases, so features reach devices over time instead of all at once, meaning availability varies by device. A normal rollout is the broad release to all eligible devices at the same time, usually when it reaches general availability (GA).
The following summary outlines features from AI-powered Windows 11 PC experiences, along with improvements and fixes. The bold text within the brackets indicates the item or area of the change.
Components updates
AI components
Servicing stack update (SSU)
Known issues in this update
Microsoft Office applications might fail to open from certain third-party apps
How to get this update
Before you install this update
Microsoft combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see Servicing stack updates.
Deployment
If you deploy dynamic updates such as this update to an existing Windows image, ensure the boot.stl file is included as part of the installation media. Failure to include the file might prevent devices from successfully starting from the installation media and can result in error code 0xc0430001.
Note: The boot.stl file is used during Secure Boot validation and must match the Windows version and architecture of the image you are updating.
To ensure the boot.stl file is included as part of the installation media, do one of the following:
- Use the Update WinPE script to update an existing Windows image. (Recommended)
- Manually copy the boot.stl file from the device Windows\Boot\EFI folder to the corresponding folder on your installation media before deploying the update.
For information about how to apply Dynamic Update packages to existing Windows images, see Update Windows installation media with Dynamic Update.
Install this update
To install this update, use one of the following Windows and Microsoft release channels.
Windows UpdateOpen Start > Settings > Update & Security > Windows Update. In the Optional updates available area, you will find the link to download and install available updates. Check for optional updates
Original source
Curated by the Releasebot team
Releasebot is an aggregator of official product update announcements from hundreds of software vendors and thousands of sources.
Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.