Windows Updates & Release Notes

Follow

103 updates curated from 128 sources by the Releasebot Team. Last updated: Oct 4, 2026

Get this feed:
  • Oct 2, 2026
    • Date parsed from source:
      Oct 2, 2026
    • First seen by Releasebot:
      Oct 4, 2026
    Microsoft logo

    Windows by Microsoft

    Windows news you can use: September 2026

    Windows ships version 26H2 as generally available, with new rollout and management tools, settings backup on by default for eligible devices, Windows 365 Reserve provisioning, Autopilot guidance, Autopatch controls, and productivity updates for Start, Taskbar, Search, File Explorer, Bluetooth, and accessibility.

    With the end of September came a big milestone: Windows 11, version 26H2 is now generally available. If you're ready to get started, explore how to get the update. Then dive into the details regarding updating via enablement package, the support lifecycle, features now on by default, and adoption tools. You'll find some of those resources outlined below, along with other updates across the Windows ecosystem, so let's dive in.

    New in Windows update and device management

    • [26H2] – New and updated tools and resources are now available to help you evaluate and roll out Windows 11, version 26H2 at scale:
      • Windows 11, version 26H2 security baseline
      • Administrative templates (ADMX) for Windows 11, version 26H2
      • Group Policy Settings Reference for Windows 11, version 26H2
      • What's new in Windows 11, version 26H2 for IT pros
      • Windows 11, version 26H2 update history
      • Windows release health: Known issues and notifications
      • Windows 11 Enterprise Evaluation
      • Microsoft Intune settings catalog
    • [BACKUP] – Starting with Windows 11, version 26H2, Windows settings backup is enabled by default for eligible devices. Any existing administrator-configured policy (enabled or disabled) will continue to be honored.
    • [W365] [PROVISIONING] – User-initiated provisioning for Windows 365 Reserve is now generally available, allowing eligible users to provision their own Reserve Cloud PC.
    • [AUTOPILOT] – New guidance can help you move from Windows Autopilot to Windows Autopilot device preparation, so you can plan the transition while accounting for your existing deployment configurations and processes. Also, if you missed it, you can now associate a Windows 11 device with your organization before enrollment. Do this to target device-specific policies and configure parts of the out-of-box experience before a user signs in.
    • [AUTOPATCH] – Starting October 15, Windows Autopatch gives you more granular control over Windows quality updates. Automatically or manually approve monthly security, non-security, and out-of-band updates individually. Manage supported .NET Framework updates and Quick machine recovery through quality update policies. New reporting gives you visibility into update approvals, applicability, installation progress, and deployment status. Quickly see what's installed, in progress, paused, failed, or needs attention.
    • [INTUNE] [APPS] [POLICIES] – Now in public preview, deployments in Microsoft Intune let you gradually roll out apps and device configuration policies to Windows devices using defined deployment rings.
    • [PODCAST] – Tune in to a new monthly podcast for a quick rundown of what's new in Windows management. Airing live the last Monday of each month, Ctrl + Manage is an opportunity to hear what the latest capabilities mean for your organization, and how you can try, plan for, and use them today.
    • [VIRTUALIZATION] – Azure Virtual Desktop Hybrid is now generally available. Run session hosts on your existing on-premises infrastructure while managing them through Azure Virtual Desktop.
    • [ACTIVATION] – Do you use VBScript, and specifically slmgr.vbs, to automate Windows activation? Learn how to keep Windows activation automated using PowerShell.

    New in Windows security

    • [NTLM] – Get answers to frequently asked questions about the multi-phase Microsoft effort to move Windows to a secure-by-default authentication posture by eventually disabling NTLM by default.
    • [PRIVACY] – Windows Insiders in the Experimental channel, decide which desktop apps access your camera, microphone, and location with individual controls. For more details, see Giving you more control over camera, microphone, and location.

    To explore what's new in security across the Microsoft platform, see What's new in Microsoft Security: September 2026.

    New in Windows Server

    For the latest features and improvements for Windows Server, see the Windows Server 2025 release notes and Windows Server 2022 release notes.

    • [ADMIN] [VMODE] – Windows Admin Center version 2610 is now in public preview with a single installer for Administration Mode and Virtualization Mode. Additional new Virtualization Mode features include Azure Arc onboarding, backup and restore, and certificate lifecycle management.

    New in productivity and collaboration

    Install the September 2026 security update for Windows 11, versions 25H2 and 24H2 to get these and other capabilities, which will be rolling out gradually:

    • [FILE EXPLORER] – The Recommended section now supports touch scrolling, making it easier to browse files in the carousel.
    • [START] – You can now choose between a small or large Start menu in addition to the default option that's available today. We've also updated Start menu settings, so you can independently show or hide Pinned, Recommended, and All.
    • [TASKBAR] – You can now customize where the taskbar appears, choosing the bottom, top, left, or right side of your screen. You can also select a smaller taskbar option to help maximize screen space on smaller devices.
    • [SEARCH] – Search does a better job showing where a result comes from—app, setting, file, web result, or Store suggestion—so it's easier to tell where you will go before you make a selection. A new setting lets you choose whether web and Microsoft Store suggestions appear alongside local results. In addition, Windows now automatically indexes your most used folders to make those files appear in subsequent search results.
    • [UI] – Updated progress indicators across Windows provide a more consistent and modern experience during startup, sign-in, restart, shutdown, and update installation.

    New features and improvements are coming in the October 2026 security update. You can preview them by installing the September 2026 optional non-security update for Windows 11, versions 26H2, 25H2, and 24H2. This update includes the gradual rollout of:

    • [FILE EXPLORER] – File Explorer Home now preserves the state of sections (expanded or collapsed), so you can pick up where you left off. In addition, the preview pane now enables you to preview PDFs downloaded from the web automatically.
    • [BLUETOOTH] – Bluetooth reliability and audio performance are improved. Experience more accurate connection and volume status, better microphone compatibility, and improved stability with LE Audio and shared audio accessories.
    • [ACCESSIBILITY] – A new setting, Open apps maximized, automatically maximizes app windows as they open. This removes a bit of everyday friction whether you use a screen reader or magnification, work in tablet mode, or simply prefer a consistent, full-screen workspace.
    • [TOUCHPADS] – Gesture controls for touchpads now include single-finger scrolling and automatic scrolling.
    • [KEYBOARD] – This update introduces a new Windows 11 setting that lets you remap the Copilot key to function as the Right Ctrl or Context Menu key. This feature helps preserve familiar keyboard shortcuts and accessibility workflows.

    To learn about planned productivity, security, and reliability updates for Windows 11, visit the Windows Roadmap.

    Lifecycle reminders

    • [W11] [24H2] – On October 13, 2026, Windows 11, version 24H2 Home and Pro editions will reach end of updates. After this date, devices running these editions will no longer receive monthly security and non-security preview updates containing protections from the latest security threats. Enterprise and Education editions remain supported until October 12, 2027.
    • [W11] [24H2] – The September 2026 non-security preview update is the final preview update for Windows 11, version 24H2. Supported editions of version 24H2 will continue to receive monthly security updates in accordance with their servicing lifecycle. If you rely on preview releases, we recommend that you update to a newer version of Windows 11 to continue receiving non-security preview updates.
    • [W10] [LTSB] [LTSC] – On October 13, 2026, Windows 10 Enterprise LTSB 2016 and Windows 10 IoT Enterprise LTSB 2016 will reach the end of extended support. Windows 10 Enterprise LTSC 2021 will reach end of support (EOS) on January 12, 2027. In both cases, we recommend updating to the latest LTSC release, Windows 11 Enterprise LTSC 2024. If you need additional time to complete the transition, explore options and Extended Security Update (ESU) offerings for Windows 10 Enterprise LTSB 2016 and Windows 10 Enterprise LTSC 2021.
    • [SERVER] [2022] – On October 13, 2026, Windows Server 2022 will reach end of mainstream support. After this date, Windows Server 2022 will transition to extended support, which includes security updates at no additional cost. These devices will continue to receive monthly security updates through October 14, 2031. For detailed information, see the Windows Server 2022 lifecycle page.

    Check out our lifecycle documentation for the latest updates on Deprecated features in the Windows client and Windows Server 2025.

    Additional resources

    If you want to be among the first to see what's next, register now for Microsoft Ignite, November 17-20. In-person passes are still available for the full conference experience in San Francisco, or you can register for free digital access. Browse the catalog of Windows sessions and save your favorites.

    Looking for the latest news and previews for Windows, Copilot, Copilot+ PCs, the Windows and Windows Server Insider Programs? Find out this and more through the following resources:

    • What’s new in Windows 365: September 2026 recap for a monthly roundup of Windows 365 and Azure Virtual Desktop updates
    • Windows Roadmap for new Windows features – filter by platform, version, status, and channel or search by feature name
    • Microsoft 365 Copilot release notes for latest features and improvements
    • Windows Insider Blog for what's available in the Beta and Experimental channels
    • Windows Server Insider for feature preview opportunities
    • Understanding update history for Windows Insider preview features, fixes, and changes to learn about the types of updates for Windows Insiders

    Join the conversation

    Is this update missing areas or topics you want us to include? Drop us a note in the Comments and share your thoughts on what you'd like to see.

    Continue the conversation. Find best practices. Bookmark the Windows Tech Community. Looking for support? Visit Windows on Microsoft Q&A.

    Original source
  • Oct 1, 2026
    • Date parsed from source:
      Oct 1, 2026
    • First seen by Releasebot:
      Oct 1, 2026
    Microsoft logo

    Windows by Microsoft

    What’s new in Windows 365: September 2026 recap

    Windows adds a monthly roundup of Windows 365 and Azure Virtual Desktop updates, highlighting new Cloud PC resilience, security, recovery, admin insights, deployment flexibility, and hybrid support across Windows App and Intune.

    WINDOWS IT PRO BLOG

    6 MIN READ

    Windows 365 has turned five and we continue to focus on helping you get more from your Cloud PCs. Welcome to our new monthly roundup of Windows 365 and Azure Virtual Desktop updates together in one place- your guide to what’s new, why it matters, and how to get started. In this edition, explore September’s improvements to everyday experiences, security and recovery, IT management, and deployment flexibility.

    Seamless user experience

    This month, we're making Cloud PCs even more flexible and resilient, helping users work with the tools they use every day, initiate provisioning of Windows 365 Reserve Cloud PCs when needed, and stay productive with a seamless experience as network conditions change.

    TWAIN scanner redirection

    With TWAIN scanners in remote sessions (Public Preview), supported scanners connected to a local Windows device can now be redirected to a Cloud PC using high-level redirection, providing an optimized scanning experience compared with USB redirection.

    Figure 1: Scanner and USB device options in Windows App.

    User provisioning for Windows 365 Reserve

    User provisioning for Windows 365 Reserve (Generally Available) helps employees get back to work when their primary device is unavailable—without waiting for IT to provision a Cloud PC. Once IT enables the capability, eligible users can initiate provisioning directly from Windows App, reducing manual work for administrators while keeping access governed through Microsoft Intune and selected Microsoft Entra ID groups.

    RDP Multipath and RDP Shortpath

    Windows 365 is gaining more resilient connectivity with RDP Multipath availability in Azure Government (Generally Available) and RDP Shortpath with TURN availability in Azure Government (Phased General Availability Rollout). RDP Multipath helps maintain sessions as network conditions change, with redundant UDP paths now generally available and redundant TCP paths rolling out in phases. RDP Shortpath with TURN is also in a phased general availability rollout, providing relayed UDP connectivity when a direct connection isn’t possible. Together, these updates help users stay productive with fewer session interruptions, even as network conditions change or direct connections are unavailable.

    Figure 2: Redundant UDP and TCP paths help maintain Cloud PC session connectivity.

    RDP Shortpath and RDP Multipath support in Windows App for macOS (beta) are now supported, bringing RDP Shortpath for public networks and RDP Multipath with UDP for Windows 365 and Azure Virtual Desktop. The update extends UDP-based connectivity and multipath resiliency to macOS.

    External identities on macOS and iOS

    Windows App is making it easier for external users to connect through macOS support (Generally Available) and iOS support (Preview), extending collaboration to invited users outside the organization without having to create a new user account for them.

    Security & reliability

    Keeping work secure and available takes both everyday protection and preparation for disruption. This month’s updates strengthen sensitive data protection, expand passwordless authentication, and give IT more options for recovery and regional resilience.

    Plan for disruption and simplify recovery

    Preparing for disruption starts with a clear recovery plan. Business continuity and disaster recovery in Cloud PC settings (Generally Available) brings point-in-time restore, cross-region disaster recovery, and disaster recovery plus together through a centralized Cloud PC configuration, making recovery options easier to manage for IT admins.

    Alternate regions for business continuity and disaster recovery (Generally Available) give IT admins more choice in where they back up Cloud PCs. With cross-region disaster recovery and disaster recovery plus, they can now select Australia Southeast, South India, Canada East, or West US to support their recovery and data residency needs.

    Cloud PC recovery for Windows 365 Government (Generally Available) enables IT admins in GCC and GCCH to reprovision and restore eligible Cloud PCs deprovisioned after a license expired. This extends a recovery capability already available in commercial environments.

    Figure 3: Select the Restore option under the Cloud PC overview section.

    Protect sensitive content and simplify authentication

    Protecting sensitive data goes hand in hand with secure authentication. In-session passwordless authentication on iOS (Preview) lets users respond to supported Microsoft Entra ID sign-in prompts within their Cloud PC session using passkeys through Windows App on their iOS device, without entering a password. Supported methods include physical security keys and QR code experiences.

    Display protection for Windows 365 (Public Preview) helps reduce the risk of unauthorized screen capture or display interception on the endpoint devices.

    Figure 4: Server-side verification that Display Protection is enabled on the endpoint.

    Strengthen regional resilience with Azure Virtual Desktop

    Regional host pools (Generally Available) give customers a regional deployment option to support enhanced resiliency and additional data sovereignty. This option is generally available in East US 2 and Central US.

    Easy manageability

    Less time navigating settings means more time supporting your organization. September’s updates help IT teams identify where attention is needed, manage user permissions, and provide Cloud PC environments tailored to different workloads.

    Better insights and simpler access controls

    To help IT admins see important signals more easily across Cloud PC environment, admin insights for Windows 365 (Generally Available) surfaces prioritized issues and optimization opportunities directly on the Cloud PC Overview page in the Microsoft Intune admin center. These service-generated insights link to relevant reports, where available, to help admins investigate and determine their next steps.

    Figure 5: Admin insights on the Cloud PC Overview page.

    Meanwhile, the enable local admin in Cloud PC configurations (Public Preview) setting lets IT admins grant selected users local administrator permissions on their Cloud PCs through the centralized Cloud PC configuration experience in Microsoft Intune. This allows users to perform tasks such as installing development tools that require elevated privileges, while IT centrally manages access through Microsoft Intune.

    Figure 6: Create a Cloud PC configuration in Microsoft Intune.

    Get started faster with Cloud PCs tailored to each workload

    Developer configuration with pre-installed Microsoft 365 Apps (Generally Available) helps developers get productive faster by providing essential development tools, Microsoft 365 Apps, and required configurations from the start. The image is available for Windows 365 Enterprise and Windows 365 Flex in dedicated mode. For developers and other users who need separate environments, IT admins can assign multiple Windows 365 Flex Dedicated Cloud PCs to the same user (Generally Available), using either the same or different configurations. This supports scenarios where users need separate environments for different workloads, projects, configurations, or security boundaries while keeping those environments centrally managed.

    Azure Virtual Desktop Hybrid

    Azure Virtual Desktop Hybrid (Generally Available) lets organizations modernize their virtual desktop environments without moving every workload to the cloud at once. Azure Virtual Desktop Hybrid enables customers to run session hosts in their own datacenters without requiring the purchase of new hardware or changing their existing hypervisor. Partners including Login VSI, Nerdio, and Nutanix can provide additional lifecycle management functionality with their updated offerings.

    Partner news

    Building on the Azure Virtual Desktop Hybrid update above, Hydra by Login VSI manages Azure Virtual Desktop across Azure and on-premises Hyper-V, with capabilities for image management, session host lifecycle automation, monitoring, and day-to-day administration.

    Nerdio Manager for Enterprise adds support for Azure Virtual Desktop Hybrid on Nutanix AHV, including orchestration, automation, visibility, and management capabilities.

    Nutanix AHV supports Azure Virtual Desktop Hybrid session hosts running on-premises while using the Azure Virtual Desktop cloud-based control plane.

    For organizations exploring their next step, Nerdio Compass (Public Preview) is a VDI assessment tool that helps organizations evaluate existing environments and plan migration to Windows 365 or Azure Virtual Desktop.

    Documentation updates

    Windows 365 cloud-native and Zero Trust deployment guidance — New guidance brings recommended decisions across identity, networking, images, updates, management, user data, and clients into one cloud-native, Zero Trust-aligned blueprint.

    Figure 7: Comparative deployment pillars

    Operational benefits of a cloud-native deployment — A companion article explains how cloud-native deployment decisions can reduce issues, increase administrator self-resolution, and help support cases resolve faster.

    Continue the conversation. Find best practices. Bookmark the Windows Tech Community, then follow us on LinkedIn or @MSWindowsITPro for updates. Looking for support? Visit Windows on Microsoft Q&A.

    Original source
  • All of your release notes in one feed

    Join Releasebot and get updates from Microsoft and hundreds of other software products.

    Create account
  • Sep 29, 2026
    • Date parsed from source:
      Sep 29, 2026
    • First seen by Releasebot:
      Sep 29, 2026
    Microsoft logo

    Windows by Microsoft

    Windows 11, version 26H2

    Windows 11 version 26H2 is now generally available, bringing the next annual feature update with a low-disruption enablement package, new security and management enhancements, and productivity improvements across File Explorer, Search, Start, Task Manager, accessibility, and voice access.

    Windows 11, version 26H2 is now generally available

    Windows 11, version 26H2 is now generally available, delivering the next annual feature update for Windows 11. Built on the same servicing foundation as Windows 11, versions 25H2 or 24H2, version 26H2 continues Microsoft focus on providing a predictable, low-disruption update experience for organizations while delivering the latest Windows innovations, security improvements, and management enhancements.

    Windows 11, version 26H2 is delivered as an enablement package for eligible devices running Windows 11, versions 25H2 or 24H2. This means you can move to the latest release with minimal deployment overhead and a streamlined installation experience.

    What is Windows 11, version 26H2?

    Windows 11, version 26H2 is the latest annual feature update for Windows 11 and continues Microsoft annual release cadence for commercial customers.

    Like version 25H2, version 26H2 shares the same servicing branch and underlying code base as previous releases. New features and capabilities have been delivered to supported devices through monthly cumulative updates, with some functionality remaining dormant until activated by the version 26H2 enablement package. This approach reduces disruption while simplifying validation and deployment planning.

    Why an enablement package?

    Traditional Windows feature updates often required a full operating system upgrade. For eligible devices running Windows 11, versions 25H2 or 24H2, version 26H2 is activated through a lightweight enablement package.

    An enablement package:

    • Activates features already present on the device.
    • Installs similarly to a monthly quality update.
    • Requires a small download.
    • Typically results in faster installation times.
    • Allows your organization to use existing servicing and deployment processes.

    Because versions 26H2, 25H2, and 24H2 share a common servicing branch, many organizations might find that validating version 26H2 requires less effort than a traditional feature update.

    What's new in Windows 11, version 26H2

    Windows 11, version 26H2 bundles features and enhancements gradually rolled out over the last year to versions 25H2 and 24H2 in the areas of security, management, accessibility, and productivity.

    Security improvements

    Windows continues to build on Microsoft commitment to security by default and security by design.

    • Administrator protection provides just-in-time administrative privileges and profile separation to help harden Windows against elevation-of-privilege attacks. You can enable it through Microsoft Intune or Group Policy.
    • Built-in Sysmon functionality in Windows enables you to capture system events that security tools can use for threat detection. Sysmon is off by default. You can configure it to capture the events your organization needs.
    • Smart App Control can now be turned on or off without requiring a clean installation of Windows, making it easier to block untrusted or potentially harmful apps.
    • Windows Hello Enhanced Sign-in Security expands support to compatible peripheral fingerprint sensors. As such, enhanced biometric sign-in protection is available on more Windows 11 PCs.
    • Post-quantum cryptography improvements include API support for NIST-standardized ML-KEM and ML-DSA algorithms. They include support for key exchange, signing, and decryption through CNG and .NET.
    • Driver security enhancements change how the Windows kernel trusts third-party drivers. They remove default trust for cross-signed drivers while maintaining support for WHCP and designated trusted legacy drivers.

    Management and deployment enhancements

    Windows 11, version 26H2 introduces improvements designed to help IT administrators deploy, manage, and secure devices at scale.

    • Windows Autopilot device preparation supports device association. It helps organizations identify trusted devices before enrollment and enabling device-targeted policies, automatic corporate device enrollment, and additional OOBE customization.
    • Windows settings backup and restore expands first sign-in restore to Microsoft Entra hybrid joined devices, Cloud PCs, and multi-user environments. Use it to restore user settings and Microsoft Store apps during device refreshes, upgrades, and migrations.
    • Point-in-time restore for Windows provides another recovery option. Roll back a PC, including apps, settings, and personal files, to a recent automatic restore point.
    • Policy-based app removal gives organizations more flexibility to remove preinstalled Microsoft apps on Enterprise and Education devices. Just specify additional MSIX and APPX packages through Group Policy.
    • RSAT on Arm64 enables IT administrators to use tools including Server Manager, Group Policy Management Tools, DNS Server Tools, DHCP Server Tools, and Active Directory management tools on Windows 11 Arm64 devices.
    • App update orchestration allows participating applications to coordinate updates with Windows Update for improved scheduling and a more streamlined update experience

    User experience and accessibility enhancements

    Windows 11, version 26H2 continues to improve everyday productivity with enhancements across Windows experiences.

    • File Explorer adds productivity enhancements including AI actions for working with supported images and summarizing OneDrive and SharePoint documents. Also included are quick actions for work and school accounts, support for additional archive formats, and performance improvements.
    • Windows Search makes results easier to find and understand with previews. It better handles typos and partial app names, identifies result types clearer, and automatically indexes frequently used folders.
    • Start and taskbar enhancements provide additional ways to customize the Windows workspace. Begin with new Start menu views and sizing options, additional taskbar positions, and a smaller taskbar option.
    • Task Manager provides greater visibility into NPU usage, including NPU utilization and memory information. You can also identify applications running in an AppContainer.
    • Magnifier adds clearer screen reader announcements, more precise zoom controls, and screen tint options to improve readability.
    • Narrator adds Braille Viewer, improves reading and navigation in Microsoft Word, and provides more control over how information about on-screen controls is announced.
    • Voice access adds natural language commanding on supported Copilot+ PCs, additional language support, and Voice Isolation to help improve recognition in environments with other speakers or background noise.

    Now enabled by default

    Some features that were behind temporary commercial control in Windows 11, version 25H2 are now enabled by default in version 26H2. These include:

    • Windows settings backup, which helps preserve supported Windows settings and Microsoft Store app lists for recovery and device replacement scenarios. Existing administrator-configured policies are still honored.
    • App-specific taskbar actions that help users access common actions directly from taskbar experiences.
    • File Explorer improvements focused on improving navigation and usability within File Explorer.

    Some of these features have eligibility requirements. Please see related technical documentation for more details.

    For a closer look at new features and enhancements added to Windows 11 since version 25H2, please see What's new in Windows 11, version 26H2.

    Servicing and support lifecycle

    Windows 11, version 26H2 continues Microsoft annual Windows feature update cadence. Installing Windows 11, version 26H2 resets the support lifecycle for supported editions, as noted here:

    Edition Support duration Home 24 months Pro 24 months Enterprise 36 months Education 36 months

    Deployment considerations

    For devices currently running Windows 11, version 25H2 or version 24H2, you can use existing deployment frameworks and update rings to validate and deploy version 26H2.

    As with any release, we recommend that you:

    • Validate version 26H2 in pilot environments.
    • Test business-critical applications, representative hardware, and workflows.
    • Expand deployment through existing update rings.
    • Monitor deployment health and known issues.

    It is also a good time to review security and compliance requirements and educate support personnel on any new functionality.

    Because this release uses servicing technology like that used for monthly cumulative updates, many organizations should experience a streamlined deployment process.

    Tools and resources

    Deployment, security, and management tools have been refreshed for this update. These include:

    • Windows 11, version 26H2 security baseline
    • Administrative templates (ADMX) for Windows 11, version 26H2
    • Group Policy Settings Reference for Windows 11, version 26H2
    • Windows 11 Enterprise Evaluation

    We've also updated key references and documentation:

    • Windows release health (for known and resolved issues)
    • Windows 11 release information (for the release history and hotpatch calendar)
    • What's new in Windows 11, version 26H2
    • Windows lifecycle documentation
    • Windows 11, version 26H2 update history

    Monthly release notes for Windows 11, version 26H2 will be added to the update history page beginning with the first monthly security update for version 26H2, slated for October 13, 2026.

    And, if you're looking for an easy way to keep up on what's new in the world of Windows management, tune in to my new podcast, Ctrl + Manage. The first episode debuts this Thursday, October 1, here on the Tech Community.

    Start planning for Windows 11, version 26H2

    Windows 11, version 26H2 is designed to make moving to the latest version of Windows familiar and straightforward. If you're managing eligible devices on Windows 11, version 25H2 or 24H2, start by validating the update with a targeted set of devices, applications, and workflows. Then expand your deployment using the tools and processes you already have in place.

    As always, we want to hear from you. Drop a comment below and let us know what's working, what questions you have, and what we can do to make managing Windows easier for your organization.

    Continue the conversation. Find best practices. Bookmark the Windows Tech Community. Looking for support? Visit Windows on Microsoft Q&A.

    Original source
  • Sep 22, 2026
    • Date parsed from source:
      Sep 22, 2026
    • First seen by Releasebot:
      Sep 23, 2026
    Microsoft logo

    Windows by Microsoft

    September 22, 2026—KB5124006 (OS Build 28000.3086) Preview

    Windows releases the Windows 11 version 26H1 cumulative update KB5124006, bringing production-quality improvements and a phased rollout through gradual and normal release channels. It also includes servicing stack updates and guidance for deploying Dynamic Update media.

    This cumulative update for Windows 11, version 26H1 (KB5124006), includes production-quality improvements.

    Notifications

    This section provides key notifications related to this release, including announcements, change logs, and end-of-support notices.

    This update is available through two release phases: gradual rollout and normal rollout. A gradual rollout delivers an update in phases, so features reach devices over time instead of all at once, meaning availability varies by device. A normal rollout is the broad release to all eligible devices at the same time, usually when it reaches general availability (GA).

    Note If you installed earlier updates, your device downloads and installs only the new updates contained in this package.

    Microsoft combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see Servicing stack updates.

    If you deploy dynamic updates such as this update to an existing Windows image, ensure the boot.stl file is included as part of the installation media. Failure to include the file might prevent devices from successfully starting from the installation media and can result in error code 0xc0430001.

    Note The boot.stl file is used during Secure Boot validation and must match the Windows version and architecture of the image you are updating.

    To ensure the boot.stl file is included as part of the installation media, do one of the following:

    • Use the Update WinPE script to update an existing Windows image. (Recommended)
    • Manually copy the boot.stl file from the device Windows\Boot\EFI folder to the corresponding folder on your installation media before deploying the update.

    For information about how to apply Dynamic Update packages to existing Windows images, see Update Windows installation media with Dynamic Update.

    To install this update, use one of the following Windows and Microsoft release channels.

    Windows Update: Open Start > Settings > Windows Update > Advanced options > Optional updates. In the Optional updates available area, you will find the link to download and install available updates. Check for optional updates.

    Original source
  • Sep 22, 2026
    • Date parsed from source:
      Sep 22, 2026
    • First seen by Releasebot:
      Sep 23, 2026
    Microsoft logo

    Windows by Microsoft

    September 22, 2026—KB5124010 (OS Builds 26200.9550 and 26100.9550) Preview

    Windows ships cumulative update KB5124010 for Windows 11 25H2 and 24H2 with production-quality improvements and notes the September 2026 non-security preview update as the final preview for version 24H2.

    This cumulative update for Windows 11, version 25H2 and 24H2 (KB5124010), includes production-quality improvements.

    Announcements and messages

    This section provides key notifications related to this release, including announcements, change logs, and end-of-support notices.

    Final preview update for Windows 11, version 24H2

    The September 2026 non-security preview update KB5124010 is the final preview update for Windows 11, version 24H2. Supported editions of version 24H2 will continue to receive monthly security updates in accordance with their servicing lifecycle.

    Customers who rely on preview releases should update to a newer version of Windows 11 to continue receiving non-security preview updates. As a reminder, Windows 11, version 24H2 Home and Pro editions reach end of support in October 2026.

    Highlights

    This update is available through two release phases: gradual rollout and normal rollout. A gradual rollout delivers an update in phases, so features reach devices over time instead of all at once, meaning availability varies by device. A normal rollout is the broad release to all eligible devices at the same time, usually when it reaches general availability (GA).

    Note If you installed earlier updates, your device downloads and installs only the new updates contained in this package.

    Known issues in this update

    How to get this update

    Before you install this update

    Microsoft combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see Servicing stack updates.

    Deployment

    If you deploy dynamic updates such as this update to an existing Windows image, ensure the boot.stl file is included as part of the installation media. Failure to include the file might prevent devices from successfully starting from the installation media and can result in error code 0xc0430001.

    Note

    The boot.stl file is used during Secure Boot validation and must match the Windows version and architecture of the image you are updating.

    To ensure the boot.stl file is included as part of the installation media, do one of the following:

    • Use the Update WinPE script to update an existing Windows image. (Recommended)
    • Manually copy the boot.stl file from the device Windows\Boot\EFI folder to the corresponding folder on your installation media before deploying the update.

    For information about how to apply Dynamic Update packages to existing Windows images, see Update Windows installation media with Dynamic Update.

    Install this update

    To install this update, use one of the following Windows and Microsoft release channels.

    Windows Update

    Open Start > Settings > Windows Update > Advanced options > Optional updates. In the Optional updates available area, you will find the link to download and install available updates. Check for optional updates.

    Original source
  • Similar to Windows with recent updates:

  • Sep 14, 2026
    • Date parsed from source:
      Sep 14, 2026
    • First seen by Releasebot:
      Sep 15, 2026
    Microsoft logo

    Windows by Microsoft

    September 14, 2026—KB5129194 (OS Build 28000.2956) Out-of-band

    Windows releases an out-of-band update for Windows 11 version 26H1 that delivers the latest fixes and improvements, adds protections for two elevation-of-privilege vulnerabilities, and resolves Remote Desktop Services, Hyper-V Plan9 folder sharing, and USB multichannel audio issues.

    This out-of-band update for Windows 11, version 26H1 (KB5129194) includes the latest fixes and improvements. Visit the Windows release health dashboard for the latest status on this release.

    Improvements

    This out-of-band update includes the following improvements:

    • [Security] This update includes protections documented in CVE-2026-62721, which refers to a Windows User-Mode Power Service (UMPS) Elevation of Privilege vulnerability.
    • [Security] This update includes protections documented in CVE-2026-85921, which refers to a Windows Secure Kernel Mode Elevation of Privilege vulnerability.
    • [Remote Desktop Services (known issue)] Fixed: This update addresses an issue affecting Remote Desktop Services (RDS) after installing the September 2026 Windows security update (KB5124012). In affected environments, RDS might become unstable, causing RDP connection and sign-in failures or servers to become unresponsive during Remote Desktop configuration. Related tools, including Microsoft Management Console (MMC), RDS Licensing Diagnoser, File Explorer, and the Windows Update page, might also stop responding.
    • [Hyper-V (known issue)] Fixed: Some applications that use HCS-managed virtual machines experienced issues when sharing host folder with Linux VMs using Plan9. Folders shared from the Windows host using Plan9 did not appear or could not be accessed in the guest environment.
    • [8-channel or 3D audio modes] Fixed: Some USB Audio Class 1.0 devices functioning as expected in standard stereo configurations failed when using multichannel audio features, including 8-channel or 3D audio modes. (Note: There are other audio symptoms not resolved in this OOB update. See the “Known issues in this update” section for more information.)

    If you've already installed previous updates, your device will download and install only the new updates included in this package.

    Original source
  • Sep 14, 2026
    • Date parsed from source:
      Sep 14, 2026
    • First seen by Releasebot:
      Sep 15, 2026
    Microsoft logo

    Windows by Microsoft

    September 14, 2026—KB5129242 (OS Build 22631.7584) Out-of-band

    Windows releases an out-of-band Windows 11 23H2 update that bundles prior security fixes with quality improvements and key reliability fixes for Remote Desktop Services, Hyper-V shared folders, and USB multichannel audio, plus a servicing stack update for more reliable Windows updating.

    This out-of-band update for Windows 11, version 23H2 (KB5129242) is cumulative. It includes updates from previous security releases, along with additional improvements. Visit the Windows release health dashboard for the latest status on this release.

    Announcements and messages

    This section provides key notifications related to this release, including announcements, change logs, and end-of-support notices.

    Improvements

    This OOB update includes quality improvements. This update is cumulative and includes security fixes and improvements from the September 8, 2026, security update (KB5122880), in addition to the following:

    • [Remote Desktop Services (known issue)] Fixed: This update addresses an issue affecting Remote Desktop Services (RDS) after installing the September 2026 Windows security update (KB5122880). In affected environments, RDS might become unstable, causing RDP connection and sign-in failures or servers to become unresponsive during Remote Desktop configuration. Related tools, including Microsoft Management Console (MMC), RDS Licensing Diagnoser, File Explorer, and the Windows Update page, might also stop responding.
    • [Hyper-V (known issue)] Fixed: Some applications that use HCS-managed virtual machines experienced issues when sharing host folder with Linux VMs using Plan9. Folders shared from the Windows host using Plan9 did not appear or could not be accessed in the guest environment.
    • [8-channel or 3D audio modes] Fixed: Some USB Audio Class 1.0 devices functioning as expected in standard stereo configurations failed when using multichannel audio features, including 8-channel or 3D audio modes. (Note: There are other audio symptoms not resolved in this OOB update. See the “Known issues in this update” section for more information.)

    Windows 11 servicing stack update (KB5122879) - 22621.7578

    This update makes quality improvements to the servicing stack, which is the component that installs Windows updates. Servicing stack updates (SSU) ensure that you have a robust and reliable servicing stack so that your devices can receive and install Microsoft updates. To learn more about SSUs, see Simplifying on-premises deployment of servicing stack updates.

    Known issues in this update

    USB Audio Class 1.0 devices with error Code 10 or no output

    How to get this update

    Before you install this update

    Microsoft now combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see Servicing stack updates and Servicing Stack Updates (SSU): Frequently Asked Questions.

    Install this update

    To install this update, use one of the following Windows and Microsoft release channels.

    Windows Update

    Open Start > Settings > Windows Update > Advanced options > Optional updates. In the Optional updates available area, you will find the link to download and install available updates. Check for optional updates.

    File Information

    For a list of the files provided in this update, download the file information for cumulative update 5129242.

    For a list of the files provided in the servicing stack update, download the file information for SSU KB5122879 - versions 22621.7578.

    Original source
  • Sep 14, 2026
    • Date parsed from source:
      Sep 14, 2026
    • First seen by Releasebot:
      Sep 15, 2026
    Microsoft logo

    Windows by Microsoft

    September 14, 2026—KB5129195 (OS Builds 26200.9457 and 26100.9457) Out-of-band

    Windows releases an out-of-band update for Windows 11 25H2 and 24H2 that adds security protections and fixes Remote Desktop Services, Hyper-V folder sharing, and USB multichannel audio issues, while also improving the servicing stack.

    This out-of-band (OOB) update for Windows 11, version 25H2 and Windows 11, version 24H2 (KB5129195) is cumulative. It includes updates from previous releases, along with additional security and non-security improvements. Visit the Windows release health dashboard for the latest status on this release.

    Improvements

    This OOB update includes the following improvement:

    • [Security] This update includes protections documented in CVE-2026-62721, which refers to a Windows User-Mode Power Service (UMPS) Elevation of Privilege vulnerability.
    • [Remote Desktop Services (known issue)] Fixed: This update addresses an issue affecting Remote Desktop Services (RDS) after installing the September 2026 Windows security update (KB5122880). In affected environments, RDS might become unstable, causing RDP connection and sign-in failures or servers to become unresponsive during Remote Desktop configuration. Related tools, including Microsoft Management Console (MMC), RDS Licensing Diagnoser, File Explorer, and the Windows Update page, might also stop responding.
    • [Hyper-V (known issue)] Fixed: Some applications that use HCS-managed virtual machines experienced issues when sharing host folder with Linux VMs using Plan9. Folders shared from the Windows host using Plan9 did not appear or could not be accessed in the guest environment.
    • [8-channel or 3D audio modes] Fixed: Some USB Audio Class 1.0 devices functioning as expected in standard stereo configurations failed when using multichannel audio features, including 8-channel or 3D audio modes. (Note: There are other audio symptoms not resolved in this OOB update. See the “Known issues in this update” section for more information.)

    Component updates

    Windows 11 servicing stack update (KB5124007) - 22621.9441

    This update makes quality improvements to the servicing stack, which is the component that installs Windows updates. Servicing stack updates (SSU) ensure that you have a robust and reliable servicing stack so that your devices can receive and install Microsoft updates. To learn more about SSUs, see Simplifying on-premises deployment of servicing stack updates.

    Known issues in this update

    USB Audio Class 1.0 devices with error Code 10 or no output

    How to get this update

    Before you install this update

    Microsoft now combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see Servicing stack updates and Servicing Stack Updates (SSU): Frequently Asked Questions.

    Install this update

    To install this update, use one of the following Windows and Microsoft release channels.

    Available

    This update downloads and installs automatically from Windows Update and Microsoft Update.

    File Information

    For a list of the files provided in this update, download the file information for cumulative update KB5129195.

    For a list of the files provided in the servicing stack update, download the file information for SSU KB5124007 - versions 22621.9441.

    Original source
  • Sep 9, 2026
    • Date parsed from source:
      Sep 9, 2026
    • First seen by Releasebot:
      Sep 9, 2026
    Microsoft logo

    Windows by Microsoft

    Retiring NTLM: Frequently asked questions

    Windows is moving toward a Kerberos-first, NTLM-optional future, with new auditing, blocking controls, and Kerberos enhancements like IAKerb and LocalKDC helping customers reduce NTLM and prepare for default disablement in a future major release.

    NTLM has been a loyal companion to Windows since 1993. It helped us log in and share files, but it also quietly fueled a generation of red-team demos and incident reports. We're grateful for the service. We're also, respectfully, showing it the door.

    This FAQ collects the questions we hear most often from customers, partners, and the community as we move Windows to a Kerberos-first, NTLM-optional (and eventually NTLM-free) future. If you've emailed us, cornered us at a conference, or filed a support case that started with "so, about this weird auth thing…", chances are that your question is answered here.

    If your question isn't answered here, please reach out to [email protected] or work with your Microsoft account team, Customer Success Account Manager, or Microsoft Support to route feedback to the product group.

    Strategy, timeline, and roadmap

    What is "NTLMless"?

    NTLMless is Microsoft's multi-phase effort to move Windows to a secure-by-default authentication posture by disabling NTLM as the default fallback and expanding Kerberos to cover the scenarios that historically forced NTLM usage. It is a platform shift, not a single feature or policy.

    Why is Microsoft doing this now?

    NTLM is deprecated and no longer under active feature development. It relies on weak cryptography, has no mutual authentication, and remains a leading vector for credential relay and pass-the-hash attacks that continue to drive real-world breaches. Reducing NTLM usage strengthens security posture and aligns with modern identity standards and post-quantum cryptography (PQC) readiness.

    Is NTLM being removed or just disabled?

    NTLM is being disabled by default, not removed outright. The underlying code will remain in Windows for a period after default disablement so administrators can re-enable it via policy for exceptional or edge-case scenarios where it's still required. Complete removal is a longer-term goal and will only happen after known dependencies have been addressed and viable Kerberos-based migration paths are broadly available.

    When will NTLM be disabled by default?

    Our current target for default disablement is the next major release of Server and Client (subject to change). Interim milestones (IAKerb and LocalKDC, enhanced auditing, blocking policies) will roll out ahead of that date. We publicly announced this direction in early 2026.

    Does this mean NTLM will stop working on my existing Windows Server 2019/2022/2025 or Windows 10/11 devices?

    No. Default disablement applies to the future release train. In-market versions of Windows client and Windows Server will continue to support NTLM. However, Microsoft strongly encourages customers to begin reducing NTLM usage now using the enhanced auditing and Kerberos improvements that are already shipping to supported versions of Windows.

    What happens after NTLM is disabled by default? Can I re-enable it?

    Yes, at least initially. When we ship default disablement, administrators will be able to re-enable NTLM via Group Policy or registry configuration to accommodate legacy applications and edge scenarios. Over time, as customer environments mature and dependencies are eliminated, the ability to re-enable NTLM will be narrowed. Our long-term objective is a Windows platform that doesn't need NTLM at all.

    Kerberos enhancements replacing NTLM

    What is IAKerb?

    Initial and Pass-through Authentication using Kerberos (IAKerb) is a Kerberos extension that lets a client authenticate to a Key Distribution Center (KDC) when the client does not have direct line-of-sight to a domain controller. The target server acts as a proxy, securely passing Kerberos messages between the client and the KDC. That matters most in the scenarios KDC Proxy was never really designed for: machine-to-machine SMB, standalone servers, and (paired with LocalKDC) local-account authentication where there's no domain KDC in the picture at all.

    What is LocalKDC?

    LocalKDC is a lightweight KDC embedded in Windows that issues Kerberos tickets for local accounts. It removes one of NTLM's longest-standing dependencies by allowing Kerberos to be used for local-account authentication in workgroup, non-domain-joined, standalone-server, small-business, and peer-to-peer.

    Note: NTLM in the enterprise (domain accounts, lateral movement, relay, credential theft against high-value identities) and NTLM for local accounts are different risk profiles with different urgency. For most enterprises, the domain-account case is the one that shows up in your threat model, your pen test report, and your board deck. LocalKDC doesn't address that. The enterprise work is IAKerb, the SPN and DFS improvements, and the blocking policies covered elsewhere in this FAQ. LocalKDC closes a different, narrower gap: it means "local account" no longer automatically means "NTLM." That's real cleanup, but it's not the enterprise headline.

    When will IAKerb and LocalKDC be generally available?

    Both features are currently available in Windows Insider preview builds. They will be generally available for Windows Server 2025 and Windows 11 in the coming months. Official release announcements will be made through the Windows IT Pro Blog and Microsoft Learn.

    What about SPN, IP-address, and cross-domain scenarios where Kerberos historically failed?

    These are the "stubborn" NTLM fallback cases, and they fall into two buckets: the ones we're fixing in the platform, and the ones only you can fix in your environment. Being honest about that split is important for your planning. These improvements are targeted for the same Windows Server and Windows client releases that brings default disablement.

    What we're addressing in the platform:

    • Domain-based DFS namespaces — historically a reliable source of NTLM fallback, because the client's target resolution and the referral path didn't line up with a Kerberos-resolvable SPN. We're addressing this so DFS access can stay on Kerberos end to end.
    • Cross-domain and trustless scenarios, and broader, safer target-resolution behavior generally.

    What you'll need to address yourselves:

    We want to be direct here: we cannot fix missing, duplicate, or malformed SPNs in your directory. If a service account has no SPN, or the same SPN is registered on two accounts, or the client is requesting an SPN that doesn't match what's registered, Kerberos will fail and NTLM will pick up the slack. No platform change makes that go away. This is directory hygiene, and it is work that needs to start now rather than when default disablement lands.

    The good news:

    This is well-trodden ground with mature guidance. Start with Kerberos authentication troubleshooting guidance. To troubleshoot specific SPN failures, see Kerberos generates KDC_ERR_S_PRINCIPAL_UNKNOWN or KDC_ERR_PRINCIPAL_NOT_UNIQUE error, which walks through finding the offending SPN with setspn -Q / setspn -X and correcting it.

    What are the new NTLM blocking policies?

    NTLM blocking is being consolidated into a centralized, policy-driven engine. Administrators will have consistent controls to allow, audit, block for single sign-on only, or block NTLM entirely using policies that consider account type, device state, target characteristics, and whether the request is SSO or credential-based. Stay tuned for more information on this one in the coming weeks!

    Scope, impact, and compatibility

    Which scenarios may break when NTLM is disabled?

    The most common failure patterns fall into four categories:

    • Hardcoded NTLM: An application explicitly requests NTLM and does not attempt Negotiate/Kerberos. Auto-Redirect and application updates address most of these.
    • Missing Kerberos prerequisites: The app uses Negotiate, Kerberos fails (missing SPN, IP address, no DC line-of-sight), and NTLM previously succeeded as fallback. IAKerb, LocalKDC, and SPN/IP support close these gaps.
    • Legacy protocol / device dependency: The client talks to a legacy server, embedded device, or third-party appliance that only supports NTLM end-to-end. Vendor updates will be required.
    • Local-account or special identity flows: The application authenticates using local accounts over the network. LocalKDC addresses the majority; a small subset (e.g., local interactive logon) is out of scope for LocalKDC.

    Is NTLM only used on Windows endpoints?

    Primarily, yes. NTLM is a Windows authentication protocol. However, non-Windows clients (macOS, Linux, Android, iOS, network appliances) can and do use NTLM when connecting to Windows resources such as SMB file shares, on-premises Exchange, or Windows-hosted web apps. This is especially common with third-party SMB clients, Outlook for Mac, and mobile device management scenarios. These clients will continue to work if they can negotiate Kerberos with the Windows server. The goal is to make Kerberos possible in more of these scenarios via IAKerb and LocalKDC.

    What about cross-domain authentication without a trust?

    Cross-domain authentication without a configured trust is a scenario that today requires NTLM. We're aware customers avoid cross-forest trusts for ransomware-containment reasons. This is one of the scenarios being addressed in the same Windows Server and Windows client release that brings default disablement so that trustless cross-domain authentication can succeed on Kerberos.

    What about IP-address-based authentication?

    Kerberos does not natively understand IP addresses, so authentication requests made using an IP address (rather than an SPN) fall back to NTLM. The single most important thing to know: do not wait for a platform fix here. Start auditing and eliminating IP-based authentication now. The majority of the transition is addressable today and every instance you remove is one less thing to unblock later.

    Start here:

    1. Audit it: Enhanced NTLM auditing will tell you not just that an IP address was used, but which process used it. That process name is your remediation worklist - it turns a vague "we have some NTLM" into a specific, assignable list of owners.
    2. Fix hardcoded IPs in applications: This is consistently the largest bucket. In-house and line-of-business apps with connection strings, config files, or scripts pointing at literal IP addresses. Route them through DNS names instead. This is usually a configuration change, not a rewrite.
    3. Educate users: \10.1.2.30\share in a bookmark, a mapped drive, or a runbook is a small habit with a real cost. Names, not numbers.
    4. Use TryIPSPN where you genuinely can't change the target: Windows supports IPv4 and IPv6 hostnames in SPNs when the client registry value TryIPSPN is set under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos\Parameters, with the corresponding SPN registered via Setspn -s host/<ip.address> .

    Note: This must be set on each client that needs it, and IP-based SPNs should have static leases. See Configuring Kerberos for IP Address for the full procedure and caveats.

    What's left after that? Only the genuinely irreducible cases: targets you don't control, appliances that can't be changed, scenarios where no name exists. Those scenarios are what our in-flight work is designed for: effectively an allow list for Kerberos over IP address, scoped deliberately so it stays an exception rather than becoming the new default. The smaller you make that list through the steps above, the smoother your path to default disablement.

    Will Microsoft apps still use NTLM after disablement?

    No, Microsoft is running a broad internal effort to identify and remove hardcoded NTLM from first-party Windows components. This ensures Windows itself is not silently re-introducing NTLM through hardcoded paths and gives our components the benefit of Kerberos wherever possible.

    Will there be a list of Microsoft apps still dependent on NTLM?

    We don't plan to publish such a list. Our commitment is that Microsoft-owned dependencies are being fixed as part of the platform work. What matters for your environment is identifying NTLM usage (your own apps, third-party apps, appliances, and services). Enhanced NTLM auditing is designed specifically for this work.

    Auditing, visibility, and discovery

    How do I find out where NTLM is being used in my environment?

    Enhanced NTLM auditing is the recommended starting point. It's a major upgrade to the legacy NTLM event logging that has been available in Windows for years. The new events answer the three questions we hear most from customers:

    • Who is using NTLM - the account, the machine name, the machine IP, and the process
    • Why NTLM was used instead of Kerberos - including structured fallback reason codes (missing SPN, no DC line-of-sight, local account, IP address, hardcoded, etc.)
    • Where the NTLM authentication is happening - both the source and the target of the request

    Which Windows versions have enhanced NTLM auditing?

    Enhanced NTLM auditing is available for Windows 11, versions 25H2 and 24H2 and Windows Server 2025. We are also working on bringing back enhanced auditing to Windows Server 2019 and Windows Server 2022.

    What about NTLMv1 specifically. Is anything changing there?

    Yes. NTLMv1 was blocked and rendered non-functional starting with Windows Server 2025 and Windows 11, version 24H2, with related changes rolling out through recent updates. NTLMv1-derived credentials are still used by some higher-level protocols (Wi-Fi, Ethernet, VPN via MS-CHAPv2), so SSO in those scenarios may be affected. See Upcoming changes to NTLMv1 in Windows 11, version 24H2 and Windows Server 2025 for more details.

    What you can do today

    How can I tell if my code is using NTLM?

    Two ways. First, look at what your code says. Second, look at what it actually does at runtime. You need both sets of information because a lot of NTLM usage isn't explicitly requested; it's inherited by accident.

    For explicitly hardcoded NTLM (the easy ones to find, once you look). search your source for the literal string NTLM and NTLMSSP. In most cases, the fix is the same one-line change: ask for Negotiate instead of NTLM. Negotiate will use Kerberos when it can and gives you a clean migration path; hardcoding NTLM guarantees you can't.

    For accidental NTLM (the ones that hurt), you are looking for code that never mentions NTLM but gets it anyway. This can include:

    • Connecting to a literal IP address rather than a hostname (no SPN, no Kerberos)
    • Connecting to a target whose SPN is missing, duplicated, or malformed
    • Passing explicit credentials where SSO with the ambient identity would work
    • Reaching a target the client has no KDC line of sight to

    To confirm what is happening at runtime, you have options. The NTLM Operational log records outgoing and incoming NTLM, and Security Event ID 4624 shows the authentication package used. Enhanced NTLM auditing goes further and surfaces the process and target behind each event, which is what converts a log into a fix list. Running the klist command on the client is a fast sanity check. If you expected Kerberos and there's no ticket for the target, you have your answer.

    Where do I start?

    Here is a pragmatic, phased approach that has worked well for early adopters:

    • Audit: Turn on enhanced NTLM auditing on clients, servers, and domain controllers. Give yourself several weeks of data to establish a baseline and identify the top NTLM callers, most-used protocols (SMB, RPC, HTTP), and highest-volume scenarios (fallback reasons, IP-based auth, hardcoded).
    • Prioritize: Group findings by root cause (e.g., missing SPN, hardcoded caller, legacy appliance) so you can remediate at scale rather than machine-by-machine.
    • Remediate the easy wins: Register missing SPNs, retire NTLMv1, replace legacy scripts that hardcode NTLM, and pilot IAKerb and LocalKDC on the workloads where they help most.
    • Pilot NTLM blocking: Use the ring-based approach (start with high-value/privileged accounts and non-critical services) and iterate outward.
    • Engage vendors: For hardcoded-NTLM in third-party products, open cases with your ISVs so they can plan their own remediation. Auto-Redirect in Windows will help, but vendor cooperation makes the transition faster and safer.

    Should I wait for IAKerb and LocalKDC to be generally available before starting?

    No, you can start the audit and remediation work today with in-market Windows. Enhanced auditing is already available, Kerberos hygiene work (SPN registration, credential-guard adoption, NTLMv1 removal) can begin now, and legacy-app inventories almost always take longer than expected. When IAKerb and LocalKDC are broadly available, you'll be positioned to adopt them quickly.

    What are the most common blockers other organizations report?

    From our readiness survey and direct customer engagements, the top blockers are:

    • Legacy applications and third-party devices/appliances with hardcoded NTLM or no Kerberos support.
    • Application dependencies whose owners are hard to reach or slow to update.
    • Lack of visibility into where NTLM is being used and why - the top single ask from customers is better reporting and diagnostics.
    • Cross-domain and non-domain-joined scenarios that historically only worked with NTLM.
    • Compatibility risk and the fear of causing an outage - which is why staged blocking, allow-lists, and audit-then-enforce modes matter.
    • Time and resource constraints and competing IT priorities.

    Are there organizations who have already reduced or eliminated NTLM?

    Yes. Multiple enterprises are actively reducing NTLM! Several have reported cutting NTLM usage by more than 90%, and a small number have fully blocked NTLM. Common patterns among success stories: estates running the latest versions of Windows Server and Windows 11, a willingness to invest in enhanced auditing, executive sponsorship for tackling application dependencies, and a phased, ring-based rollout rather than a "big bang" switch.

    Support, feedback, and escalation

    Where do I send NTLM-related questions or feedback to Microsoft

    Email us at [email protected]. Please include details on the version(s) of Windows Server or Windows client you're running, a short description of the scenario or blocker, and whether you have enabled enhanced NTLM auditing. The team monitors this alias and prioritizes recurring themes for updating our public guidance.

    What if I hit a Kerberos or NTLM issue that appears to be a product bug?

    Please open a Microsoft Support case through standard support channels. Support will collect diagnostics and, if needed, escalate to the Windows product group. The support ticket path is important; it lets us track scenarios, telemetry, and reproducibility formally rather than through email threads.

    How can I stay informed of upcoming NTLM-related changes?

    Follow the Windows IT Pro Blog for public announcements and bookmark the Windows message center or subscribe to Windows announcements on the Microsoft 365 admin center message center for tenant-relevant notifications. If you have a non-disclosure agreement (NDA) with Microsoft, you can ask your account team about the NTLMLess newsletter and Management Advisors Program updates. Major NTLM milestones (feature general availability, default disablement dates, backport releases) will be announced through these channels.

    Additional resources

    Here is a short list of useful references for going deeper:

    • NTLM overview - protocol overview and history
    • Reducing NTLM dependency: IAKerb and LocalKDC in Windows Insider Preview - details on feature availability
    • The evolution of Windows authentication - the strategic context behind the move away from NTLM
    • Advancing Windows security: Disabling NTLM by default - the public roadmap announcement
    • Overview of NTLM auditing enhancements in Windows 11, version 24H2 and Windows Server 2025 - how to turn on and read enhanced auditing
    • Upcoming changes to NTLMv1 in Windows 11, version 24H2 and Windows Server 2025 - what's changing for NTLMv1 specifically
    • Active Directory hardening series – Part 8: Disabling NTLM - practical guidance for Active Directory administrators
    • Block NTLM connections on SMB – Guidance on how to block NTLM authentication on SMB clients
    • Eliminating NTLM in Windows - technical deep dive

    Have questions? Email us at [email protected].

    Continue the conversation. Find best practices. Bookmark the Windows Tech Community. Looking for support? Visit Windows on Microsoft Q&A.

    Original source
  • Sep 8, 2026
    • Date parsed from source:
      Sep 8, 2026
    • First seen by Releasebot:
      Sep 9, 2026
    Microsoft logo

    Windows by Microsoft

    September 8, 2026—KB5124012 (OS Build 28000.2954)

    Windows releases the Windows 11 26H1 cumulative update KB5124012 with the latest security fixes, quality improvements, and updates from the optional preview. It also improves Secure Boot coverage, fixes Teams and Outlook crashes on Arm64 PCs, and addresses Remote Desktop audio and logging issues.

    This cumulative update for Windows 11, version 26H1 (KB5124012) includes the latest security fixes and improvements, along with non-security updates from last month's optional preview release. Visit the Windows release health dashboard for the latest status on this release.

    Improvements

    This update includes new features and quality improvements that were part of the following update:

    • August 27, 2026-KB5120996 (OS Build 28000.2804) Preview

    The following summary outlines key quality improvements addressed by this update. The bold text within the brackets indicates the item or area of the change.

    • [Security updates] This update provides security improvements. For more information about the security vulnerabilities resolved by this update, see the Security Update Guide
    • [Secure Boot] This update includes additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates. Certificate deployment via Windows updates continues across supported PCs and non-managed business devices in the coming months.
    • [Teams and Outlook on Arm64 PCs] Fixed: This update addresses an issue that could cause Microsoft Teams and Microsoft Outlook to unexpectedly close on Arm64-based PCs.
    • [Date and Time] This update adjusts Morocco Standard Time to reflect Morocco's transition to permanent UTC+00:00 effective September 20, 2026. This change ensures that the correct local time is displayed after the transition.
    • [Remote Desktop Audio Redirection] This update addresses an issue affecting Remote Desktop audio redirection that could prevent audio from a remote session from playing on the local device in certain configurations.
    • [OMA-DM Client Logging] This update improves diagnostic logging for the OMA-DM client by adding certificate chain information for server connections, helping administrators troubleshoot device management connectivity issues.

    If you've already installed previous updates, your device will download and install only the new updates included in this package.

    Component updates

    Known issues in this update

    Microsoft is not currently aware of any issues with this update.

    How to get this update

    Before you install this update

    Microsoft combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see Servicing stack updates.

    Deployment

    If you deploy dynamic updates such as this update to an existing Windows image, ensure the boot.stl file is included as part of the installation media. Failure to include the file might prevent devices from successfully starting from the installation media and can result in error code 0xc0430001.

    Note

    The boot.stl file is used during Secure Boot validation and must match the Windows version and architecture of the image you are updating.

    To ensure the boot.stl file is included as part of the installation media, do one of the following:

    • Use the Update WinPE script to update an existing Windows image. (Recommended)
    • Manually copy the boot.stl file from the device Windows\Boot\EFI folder to the corresponding folder on your installation media before deploying the update.

    For information about how to apply Dynamic Update packages to existing Windows images, see Update Windows installation media with Dynamic Update.

    Install this update

    To install this update, use one of the following Windows and Microsoft release channels.

    Windows Update

    Available: Available

    Next Step: This update downloads and installs automatically from Windows Update and Microsoft Update.

    File information

    For a list of the files provided in this update, download the file information for cumulative update KB5124012​​​​​​​​​.

    For a list of the files provided in the servicing stack update, download the file information for the SSU (KB5125104) - version 28000.2950.

    Related topics

    Windows monthly updates explained

    Description of the standard terminology used for Microsoft software updates

    Windows release health

    Original source
  • Sep 8, 2026
    • Date parsed from source:
      Sep 8, 2026
    • First seen by Releasebot:
      Sep 9, 2026
    Microsoft logo

    Windows by Microsoft

    September 8, 2026—KB5122880 (OS Build 22621.7582)

    Windows releases a cumulative update for Windows 11 23H2 with the latest security fixes and quality improvements, plus updates for Secure Boot, Morocco Standard Time, cellular profiles, OMA DM logging, and Remote Desktop audio redirection. It also includes servicing stack improvements.

    This cumulative update for Windows 11, version 23H2 (KB5122880), includes the latest security fixes and improvements, along with non-security updates from last month’s optional preview release. Visit the Windows release health dashboard for the latest status on this release.

    Want a quick overview? Watch the Windows 11, version 24H2 and version 25H2 video.

    Announcements and messages

    This section provides key notifications related to this release, including announcements, change logs, and end-of-support notices.

    Improvements

    This update addresses security issues for your Windows operating system.

    Important

    Use EKB KB5027397 to update to Windows 11, version 23H2.

    This security update contains fixes and quality improvements from KB5120240 (released August 11, 2026). The following summary outlines key issues addressed by this update. Also, included are available new features. The bold text within the brackets indicates the item or area of the change.

    • [Security updates] This update provides security improvements. For more information about the security vulnerabilities resolved by this update, see the Security Update Guide.
    • [Secure Boot] This update includes additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates. Certificate deployment via Windows updates continues across supported PCs and non-managed business devices in the coming months.
    • [Date and Time] This update adjusts Morocco Standard Time to reflect Morocco's transition to permanent UTC+00:00 effective September 20, 2026. This change ensures that the correct local time is displayed after the transition.
    • [Cellular] Updating COSA profiles for Telavox and Swisscom.
    • [OMA DM] This update improves the logging features of the Omadmclient component. More debug information is now saved when connecting to a server.
    • [Remote Desktop] This update addresses an issue that affects Remote Desktop audio redirection. Audio from the remote session might not play on the local computer in certain configurations.

    If you've already installed previous updates, your device will download and install only the new updates included in this package.

    Windows 11 servicing stack update (KB5122879) - 22621.7578

    This update makes quality improvements to the servicing stack, which is the component that installs Windows updates. Servicing stack updates (SSU) ensure that you have a robust and reliable servicing stack so that your devices can receive and install Microsoft updates. To learn more about SSUs, see Simplifying on-premises deployment of servicing stack updates.

    Known issues in this update

    Microsoft is not currently aware of any issues with this update.

    How to get this update

    Before you install this update

    Microsoft combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see Servicing stack updates.

    Deployment

    If you deploy dynamic updates such as this update to an existing Windows image, ensure the boot.stl file is included as part of the installation media. Failure to include the file might prevent devices from successfully starting from the installation media and can result in error code 0xc0430001.

    Note

    The boot.stl file is used during Secure Boot validation and must match the Windows version and architecture of the image you are updating.

    To ensure the boot.stl file is included as part of the installation media, do one of the following:

    • Use the Update WinPE script to update an existing Windows image. (Recommended)
    • Manually copy the boot.stl file from the device Windows\Boot\EFI folder to the corresponding folder on your installation media before deploying the update.

    For information about how to apply Dynamic Update packages to existing Windows images, see Update Windows installation media with Dynamic Update.

    Install this update

    To install this update, use one of the following Windows and Microsoft release channels.

    Windows Update

    Available: This update downloads and installs automatically from Windows Update and Microsoft Update.

    File information

    For a list of the files provided in this update, download the file information for cumulative update KB5122880.

    For a list of the files provided in the servicing stack update, download the file information for SSU KB5122879 - versions 22621.7578.

    Related topics

    Windows release health

    Microsoft Store for Business and Education with Configuration Manager

    Get updates for apps and games in Microsoft Store

    Original source
  • Sep 8, 2026
    • Date parsed from source:
      Sep 8, 2026
    • First seen by Releasebot:
      Sep 9, 2026
    Microsoft logo

    Windows by Microsoft

    September 8, 2026—KB5124008 (OS Builds 26200.9445 and 26100.9445)

    Windows ships a Windows 11 update with security improvements, new Secure Boot certificate targeting, and fixes for mouse cursor settings, personalization, Teams and Outlook on Arm64 PCs, Remote Desktop audio redirection, and OMA-DM logging, plus a Morocco time zone adjustment.

    Announcements and messages

    This section provides key notifications related to this release, including announcements, change logs, and end-of-support notices.

    Windows Secure Boot certificate expiration

    End of updates

    Improvements

    This update includes improvements from the following previously released updates:

    • August 27, 2026-KB5120998 (OS Builds 26200.9278 and 26100.9278)

    The following summary outlines key quality improvements addressed by this update. The bold text within the brackets indicates the item or area of the change.

    • [Security updates] This update provides security improvements. For more information about the security vulnerabilities resolved by this update, see the Security Update Guide.
    • [Secure Boot] This update includes additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates. Certificate deployment via Windows updates continues across supported PCs and non-managed business devices in the coming months.
    • [Mouse] Fixed: This update addresses an issue that prevented customized mouse cursor settings, including pointer style and color, from displaying correctly. Selected cursor options and colors now work as expected.
    • [Personalization] Fixed: This update addresses an issue where desktop background and other personalization settings might not load correctly, causing the desktop background to appear black.
    • [Teams and Outlook on Arm64 PCs] Fixed: This update addresses an issue that could cause Microsoft Teams and Microsoft Outlook to unexpectedly close on Arm64-based PCs.
    • [Date and Time] This update adjusts Morocco Standard Time to reflect Morocco's transition to permanent UTC+00:00 effective September 20, 2026. This change ensures that the correct local time is displayed after the transition.
    • [Remote Desktop Audio Redirection] This update addresses an issue affecting Remote Desktop audio redirection that could prevent audio from a remote session from playing on the local device in certain configurations.
    • [OMA-DM Client Logging] This update improves diagnostic logging for the OMA-DM client, providing additional information to help troubleshoot device management server connection issues.

    If you've already installed previous updates, your device will download and install only the new updates included in this package.

    Components updates

    AI components

    Servicing stack update

    Known issues in this update

    Microsoft is not currently aware of any issues with this update.

    How to get this update

    Before you install this update

    Microsoft combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see Servicing stack updates.

    Deployment

    If you deploy dynamic updates such as this update to an existing Windows image, ensure the boot.stl file is included as part of the installation media. Failure to include the file might prevent devices from successfully starting from the installation media and can result in error code 0xc0430001.

    Note

    The boot.stl file is used during Secure Boot validation and must match the Windows version and architecture of the image you are updating.

    To ensure the boot.stl file is included as part of the installation media, do one of the following:

    • Use the Update WinPE script to update an existing Windows image. (Recommended)
    • Manually copy the boot.stl file from the device Windows\Boot\EFI folder to the corresponding folder on your installation media before deploying the update.

    For information about how to apply Dynamic Update packages to existing Windows images, see Update Windows installation media with Dynamic Update.

    Install this update

    To install this update, use one of the following Windows and Microsoft release channels.

    Windows Update

    Available

    Next Step

    Available

    This update downloads and installs automatically from Windows Update and Microsoft Update.

    File information

    For a list of the files provided in this update, download the file information for cumulative update KB5124008.

    For a list of the files provided in the servicing stack update, download the file information for the SSU (KB5124007) - version 26100.9441.

    Related topics

    Windows monthly updates explained

    Description of the standard terminology used for Microsoft software updates

    Microsoft Store for Business and Education with Configuration Manager

    Get updates for apps and games in Microsoft Store

    Original source
  • Aug 27, 2026
    • Date parsed from source:
      Aug 27, 2026
    • First seen by Releasebot:
      Aug 28, 2026
    Microsoft logo

    Windows by Microsoft

    August 27, 2026—KB5120996 (OS Build 28000.2804) Preview

    Windows releases a cumulative update for Windows 11, version 26H1, bringing production-quality improvements with phased and broad rollout availability and no known issues reported.

    This cumulative update for Windows 11, version 26H1 (KB5120996), includes production-quality improvements.

    Announcements and messages

    This section provides key notifications related to this release, including announcements, change logs, and end-of-support notices.

    Highlights

    This update is available through two release phases: gradual rollout and normal rollout. A gradual rollout delivers an update in phases, so features reach devices over time instead of all at once, meaning availability varies by device. A normal rollout is the broad release to all eligible devices at the same time, usually when it reaches general availability (GA).

    Known issues in this update

    Microsoft is not currently aware of any issues with this update.

    How to get this update

    Before you install this update

    Microsoft combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see Servicing stack updates.

    Deployment

    If you deploy dynamic updates such as this update to an existing Windows image, ensure the boot.stl file is included as part of the installation media. Failure to include the file might prevent devices from successfully starting from the installation media and can result in error code 0xc0430001.

    Note

    The boot.stl file is used during Secure Boot validation and must match the Windows version and architecture of the image you are updating.

    To ensure the boot.stl file is included as part of the installation media, do one of the following:

    • Use the Update WinPE script to update an existing Windows image. (Recommended)
    • Manually copy the boot.stl file from the device Windows\Boot\EFI folder to the corresponding folder on your installation media before deploying the update.

    For information about how to apply Dynamic Update packages to existing Windows images, see Update Windows installation media with Dynamic Update.

    Install this update

    To install this update, use one of the following Windows and Microsoft release channels.

    Windows Update

    Open Start > Settings > Windows Update > Advanced options > Optional updates. In the Optional updates available area, you will find the link to download and install available updates. Check for optional updates.

    Original source
  • Aug 27, 2026
    • Date parsed from source:
      Aug 27, 2026
    • First seen by Releasebot:
      Aug 28, 2026
    Microsoft logo

    Windows by Microsoft

    August 27, 2026—KB5120998 (OS Builds 26200.9278 and 26100.9278) Preview

    Windows ships a cumulative update for Windows 11 25H2 and 24H2 with production-quality improvements, gradual and normal rollout phases, and no known issues reported. Microsoft also notes Secure Boot certificate updates and deployment guidance for Windows images.

    This cumulative update for Windows 11, version 25H2 and 24H2 (KB5120998), includes production-quality improvements.

    Announcements and messages

    This section provides key notifications related to this release, including announcements, change logs, and end-of-support notices.

    Windows Secure Boot certificate expiration

    Important: Secure Boot certificates used by most Windows devices expire starting in June 2026. Microsoft has been updating these certificates on consumer and non-managed business devices over the past several months. Devices that haven’t received the newer certificates will continue to start and operate normally, and standard Windows updates will continue to install. Updated certificates will continue to be delivered through Windows Update in the coming months. For more information, see Windows Secure Boot certificate expiration and CA updates.

    Highlights

    This update is available through two release phases: gradual rollout and normal rollout. A gradual rollout delivers an update in phases, so features reach devices over time instead of all at once, meaning availability varies by device. A normal rollout is the broad release to all eligible devices at the same time, usually when it reaches general availability (GA).

    If you installed earlier updates, your device downloads and installs only the new updates contained in this package.

    Known issues in this update

    Microsoft is not currently aware of any issues with this update.

    How to get this update

    Before you install this update

    Microsoft combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see Servicing stack updates.

    Deployment

    If you deploy dynamic updates such as this update to an existing Windows image, ensure the boot.stl file is included as part of the installation media. Failure to include the file might prevent devices from successfully starting from the installation media and can result in error code 0xc0430001.

    Note

    The boot.stl file is used during Secure Boot validation and must match the Windows version and architecture of the image you are updating.

    To ensure the boot.stl file is included as part of the installation media, do one of the following:

    • Use the Update WinPE script to update an existing Windows image. (Recommended)
    • Manually copy the boot.stl file from the device Windows\Boot\EFI folder to the corresponding folder on your installation media before deploying the update.

    For information about how to apply Dynamic Update packages to existing Windows images, see Update Windows installation media with Dynamic Update.

    Install this update

    To install this update, use one of the following Windows and Microsoft release channels.

    Windows Update

    Available

    Next Step

    Open Start > Settings > Windows Update > Advanced options > Optional updates. In the Optional updates available area, you will find the link to download and install available updates. Check for optional updates

    File information

    For a list of the files provided in this update, download the file information for cumulative update KB5120998.

    For a list of the files provided in the servicing stack update, download the file information for the SSU (KB5120997) - version 26100.9274.

    Related topics

    Windows monthly updates explained

    Description of the standard terminology used for Microsoft software updates

    Microsoft Store for Business and Education with Configuration Manager

    Get updates for apps and games in Microsoft Store

    Original source
  • Aug 11, 2026
    • Date parsed from source:
      Aug 11, 2026
    • First seen by Releasebot:
      Aug 13, 2026
    Microsoft logo

    Windows by Microsoft

    August 11, 2026—KB5121000 (OS Build 28000.2704)

    Windows ships the Windows 11 version 26H1 cumulative update KB5121000 with the latest security fixes, non-security improvements from the optional preview, better TPM maintenance reporting, and expanded Secure Boot certificate coverage.

    This cumulative update for Windows 11, version 26H1 (KB5121000) includes the latest security fixes and improvements, along with non-security updates from last month's optional preview release. Visit the Windows release health dashboard for the latest status on this release.

    Improvements

    This update includes new features and quality improvements that were part of the following update:

    • July 14, 2026—KB5101649 (OS Build 28000.2525)
    • July 28, 2026—KB5101681 (OS Build 28000.2608) Preview

    This update addresses security vulnerabilities documented in the following guide:

    • August 2026 Security Updates

    The following summary outlines key quality improvements addressed by this update. The bold text within the brackets indicates the item or area of the change.

    • [Device] This update improves TPM maintenance reporting by ensuring that EK certificate status is reported accurately.
    • [Secure Boot] This update includes additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates. Certificate deployment via Windows updates continues across supported PCs and non-managed business devices in the coming months.

    If you've already installed previous updates, your device will download and install only the new updates included in this package.

    Components updates

    Known issues in this update

    Microsoft is not currently aware of any issues with this update.

    How to get this update

    Before you install this update

    Microsoft combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see Servicing stack updates.

    Deployment

    If you deploy dynamic updates such as this update to an existing Windows image, ensure the boot.stl file is included as part of the installation media. Failure to include the file might prevent devices from successfully starting from the installation media and can result in error code 0xc0430001.

    Note

    The boot.stl file is used during Secure Boot validation and must match the Windows version and architecture of the image you are updating.

    To ensure the boot.stl file is included as part of the installation media, do one of the following:

    • Use the Update WinPE script to update an existing Windows image. (Recommended)
    • Manually copy the boot.stl file from the device Windows\Boot\EFI folder to the corresponding folder on your installation media before deploying the update.

    For information about how to apply Dynamic Update packages to existing Windows images, see Update Windows installation media with Dynamic Update.

    Install this update

    To install this update, use one of the following Windows and Microsoft release channels.

    Windows Update

    ✅

    This update downloads and installs automatically from Windows Update and Microsoft Update.

    File information

    For a list of the files provided in this update, download the file information for cumulative update KB5121000​​​​​​​​​.

    For a list of the files provided in the servicing stack update, download the file information for the SSU (KB5101747) - version 28000.2602.

    Related topics

    Windows monthly updates explained

    Description of the standard terminology used for Microsoft software updates

    Windows release health

    Original source
Releasebot

Curated by the Releasebot team

Releasebot is an aggregator of official product update announcements from hundreds of software vendors and thousands of sources.

Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.