<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Windows IT Pro Blog articles</title>
    <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/bg-p/Windows-ITPro-blog</link>
    <description>Windows IT Pro Blog articles</description>
    <pubDate>Fri, 24 Jul 2026 00:38:21 GMT</pubDate>
    <dc:creator>Windows-ITPro-blog</dc:creator>
    <dc:date>2026-07-24T00:38:21Z</dc:date>
    <item>
      <title>Strengthening Key Management Service - (KMS) with Hardware-Based Trust</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/strengthening-key-management-service-kms-with-hardware-based/ba-p/4539465</link>
      <description>&lt;P&gt;For years, organizations have relied on Microsoft’s Key Management Service (KMS) to activate Windows devices at scale. While KMS helped enable broad deployment scenarios, modern organizations increasingly require stronger assurances around device identity and activation integrity. Microsoft has continued to enhance activation capabilities with innovations that leverage hardware-backed validation to provide stronger protection against activation misuse and improve trust in device identity.&lt;/P&gt;
&lt;P&gt;As attackers have exploited fake or cloned KMS servers, organizations face increased compliance and licensing risk. Microsoft is now further strengthening defenses with KMS Hardware-Secured, which uses Trusted Platform Module (TPM)-based attestation to help verify that a KMS host is running on trusted hardware before it can activate Windows devices.&lt;/P&gt;
&lt;H4&gt;Build trust into every activation&lt;/H4&gt;
&lt;P&gt;The cornerstone of this modernization is TPM-based attestation. &lt;STRONG&gt;Starting with upcoming Windows Server releases, KMS hosts must prove they are running on verified, uncompromised hardware before activating clients. &lt;/STRONG&gt;This is achieved through TPM – a hardware root of trust that provides cryptographic proof of integrity.&lt;/P&gt;
&lt;P&gt;TPM attestation delivers:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Stronger security: &lt;/STRONG&gt;Help ensure only verified servers can issue activation licenses.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Tamper resistance:&lt;/STRONG&gt; Help protect activation secrets from theft or spoofing by binding them to hardware.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Future-ready compliance:&lt;/STRONG&gt; Help ensure the infrastructure is ready for future activation security requirements.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The result is a more trustworthy activation model that helps reduce spoofing risk today while preparing organizations for future security requirements.&lt;/P&gt;
&lt;P&gt;How TPM attestation works:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Hardware identity: &lt;/STRONG&gt;The KMS host uses TPM-backed attestation to prove its hardware identity. Microsoft verifies this proof before the host can activate devices.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Platform integrity:&lt;/STRONG&gt; The TPM confirms the KMS host has not been subject to tampering.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Activation flow:&lt;/STRONG&gt; Once verified, the KMS host can securely serve activation requests for Windows devices in the organization.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For customers, this means activation can be tied to a trusted host, not just a software configuration that can be copied or spoofed.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;colgroup&gt;&lt;col style="width: 33.3868%" /&gt;&lt;col style="width: 33.3868%" /&gt;&lt;col style="width: 33.2584%" /&gt;&lt;/colgroup&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;KMS Hardware-Secured&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Legacy KMS&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Basis of trust&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Hardware root-of-trust via TPM&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Software-only; vulnerable to spoofing&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Deployment requirement&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;TPM&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;No hardware requirement&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Operational outcome&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Greater trust and simpler long-term operations&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Increased risk and operational overhead&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H4&gt;Getting ready for KMS-Hardware Secured requirements&lt;/H4&gt;
&lt;P&gt;Preparing now helps ensure your KMS environment is ready for the transition to hardware-based trust. The following steps can help you assess readiness and plan any required updates.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Inventory your KMS hosts:&lt;/STRONG&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;For physical KMS host&lt;/STRONG&gt;, confirm the host is certified for Windows Server on &lt;A class="lia-external-url" href="https://www.windowsservercatalog.com/" target="_blank" rel="noopener"&gt;Windows Server Catalog&lt;/A&gt;. Ensure TPM is installed and enabled.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;For virtual KMS host&lt;/STRONG&gt;, guidance for virtualized environments will be provided in future blogs.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Validate TPM attestation&lt;/STRONG&gt;: In an elevated Windows PowerShell session, run&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Get-TpmSupportedFeature -FeatureList "Key Attestation”&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;A successful response that displays “Key Attestation” confirms the server supports the TPM attestation capability for KMS Hardware-Secured.&lt;/P&gt;
&lt;img /&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Plan:&lt;/STRONG&gt; Inventory your KMS hosts and identify any hardware upgrades needed to support KMS Hardware-Secured.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Communicate:&lt;/STRONG&gt; Share readiness plans with IT teams and monitor upcoming enforcement timelines.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;Coming soon: KMS Hardware-Secured readiness check&lt;/H4&gt;
&lt;P&gt;Starting &lt;STRONG&gt;August 2026&lt;/STRONG&gt;, Windows Server 2025 will provide readiness messaging to help administrators assess whether a KMS host is ready for hardware-based security, giving teams time to plan upgrades before enforcement begins.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Where you’ll see them&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Command line (slmgr /dlv)&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;✅&lt;EM&gt; “This device is eligible to serve as a KMS host with hardware-based security.”&lt;/EM&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;⚠️ &lt;EM&gt;“This device does not meet the requirements for using KMS host with hardware-based security.”&lt;/EM&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Event logs&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Warning entries under Applications and Services Logs &amp;gt; Key Management Service.&lt;/P&gt;
&lt;H4&gt;Plan your transition now&lt;/H4&gt;
&lt;P&gt;With the next Windows Server LTSC release, TPM attestation will become &lt;STRONG&gt;mandatory&lt;/STRONG&gt; for KMS Hardware-Secured activation. Taking action now gives your organization time to prepare and transition on your own schedule.&lt;/P&gt;
&lt;P&gt;As Windows security continues to evolve, trusted activation infrastructure will play an increasingly important role. KMS Hardware Secured helps position your environment for the future while aligning with Microsoft's continued investment in hardware-rooted trust.&lt;/P&gt;
&lt;H4&gt;Securing today. Preparing for what’s next.&lt;/H4&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Security in Windows is built into the platform - continuously maintained and designed to evolve as threats change.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;EM&gt;Learn more in the &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/security/book/" target="_blank" rel="noopener"&gt;Windows Security book&lt;/A&gt; and &lt;A class="lia-external-url" href="https://aka.ms/ws2025securitybook" target="_blank" rel="noopener"&gt;Windows Server Security book&lt;/A&gt; or explore &lt;A class="lia-external-url" href="https://www.microsoft.com/windows/business" target="_blank" rel="noopener"&gt;Windows 11&lt;/A&gt;, &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows-server/" target="_blank" rel="noopener"&gt;Windows Server&lt;/A&gt;, and &lt;A class="lia-external-url" href="https://www.microsoft.com/windows/business/devices/copilot-plus-pcs" target="_blank" rel="noopener"&gt;Copilot+ PCs&lt;/A&gt;. For broader solutions, visit the&amp;nbsp;&lt;A class="lia-external-url" href="https://www.microsoft.com/security/business" target="_blank" rel="noopener"&gt;Microsoft Security site&lt;/A&gt;, follow the &lt;A class="lia-external-url" href="https://www.microsoft.com/security/blog/" target="_blank" rel="noopener"&gt;Security blog&lt;/A&gt;, or connect with &lt;A class="lia-external-url" href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;Microsoft Security&lt;/A&gt; on LinkedIn and &lt;A class="lia-external-url" href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;@MSFTSecurity&lt;/A&gt;.   &lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/strengthening-key-management-service-kms-with-hardware-based/ba-p/4539465</guid>
      <dc:creator>Monika_Kumar</dc:creator>
      <dc:date>2026-07-22T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Now available: Admin control for SSO prompts in Windows</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/now-available-admin-control-for-sso-prompts-in-windows/ba-p/4534613</link>
      <description>&lt;P&gt;IT administrators can now &lt;STRONG&gt;automatically accept SSO permissions&lt;/STRONG&gt; on managed Windows devices using a supported registry setting. In this context, SSO, or single sign-on, refers to using the Microsoft credentials from a user’s Windows sign-in to access other Microsoft apps and services without seeing any prompts. This new capability is available beginning with the &lt;STRONG&gt;July 2026 monthly security update (&lt;A href="https://support.microsoft.com/en-us/servicing/os/windows-11/2026/07/july-14-2026-kb5101650-os-builds-26200-8875-and-26100-8875" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;KB5101650&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;) &lt;/STRONG&gt;for Windows 11, version 24H2 and 25H2.&lt;/P&gt;
&lt;img /&gt;
&lt;H4&gt;Background: What changed and why&lt;/H4&gt;
&lt;P&gt;In the European Economic Area (EEA), Microsoft updated the Windows sign-in experience so that users are not automatically signed in to other Microsoft applications and services after signing in to Windows. Instead, Windows asks users whether they want to use the same credentials to sign in to additional apps or services — giving users choice over how their Windows account is used for sign-in.&lt;/P&gt;
&lt;P&gt;For managed enterprise environments, some organizations wanted additional flexibility to manage the SSO prompt experience on devices where their organizations already manage sign-in policies and trust relationships. To support those scenarios, we’ve developed a registry-based control that lets IT administrators automatically accept SSO permissions on eligible managed Windows devices.&lt;/P&gt;
&lt;H4&gt;What’s new: Enterprise admin control for sign-in behavior&lt;/H4&gt;
&lt;P&gt;Starting with the July 2026 monthly security update for Windows 11, version 24H2 and 25H2, IT administrators can deploy the following registry policy to automatically accept SSO permissions on managed devices:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;PRE&gt;&lt;STRONG&gt;Registry Path: &lt;/STRONG&gt;HKLM\SOFTWARE\Policies\Microsoft\Windows\AAD&lt;BR /&gt;&lt;STRONG&gt;Value:&lt;/STRONG&gt; AutoAcceptSsoPermission (DWORD) = 1&lt;/PRE&gt;
&lt;/BLOCKQUOTE&gt;
&lt;img /&gt;
&lt;P&gt;This policy can be deployed via:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Group Policy (GPO)&lt;/LI&gt;
&lt;LI&gt;Microsoft Intune or similar mobile device management (MDM) tool&lt;/LI&gt;
&lt;LI&gt;Microsoft Configuration Manager&lt;/LI&gt;
&lt;LI&gt;Any management tool that supports registry policy deployment&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Important details&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Scope: &lt;/STRONG&gt;Applies only to managed enterprise devices with Microsoft Entra ID accounts&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Personal accounts:&lt;/STRONG&gt; Prompts remain for personal Microsoft accounts (MSA)&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Unmanaged devices:&lt;/STRONG&gt; Not affected —prompts remain for non-policy-controlled environments&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Supported OS:&lt;/STRONG&gt; Windows 11, version 24H2 and 25H2&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;Getting started&lt;/H4&gt;
&lt;P&gt;To get started:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Ensure that your devices are running &lt;STRONG&gt;Windows 11, version 24H2 and 25H2&lt;/STRONG&gt; or later.&lt;/LI&gt;
&lt;LI&gt;Install the July 2026 monthly security update.&lt;/LI&gt;
&lt;LI&gt;Deploy the registry policy via GPO, Intune, or your preferred management tool.&lt;/LI&gt;
&lt;LI&gt;Validate SSO behavior across your managed device fleet.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;For detailed deployment guidance, visit &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?LinkId=2371147" target="_blank" rel="noopener" aria-label="Link Admin control for SSO prompts in Windows"&gt;Admin control for SSO prompts in Windows&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;What’s next&lt;/H4&gt;
&lt;P&gt;We’re continuing to evaluate additional admin controls and transparency features that will give your organization greater confidence in managing authentication experiences across your device fleet. Have feedback? Share your ideas in the Comments.&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;Continue the conversation. Find best practices. Bookmark the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Tech Community&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;, then follow us on&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/company/windows-it-pro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;or&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://twitter.com/mswindowsitpro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSWindowsITPro&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;for updates. Looking for support? Visit&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows on Microsoft Q&amp;amp;A&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:257}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jul 2026 20:42:06 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/now-available-admin-control-for-sso-prompts-in-windows/ba-p/4534613</guid>
      <dc:creator>Justin-Ploegert</dc:creator>
      <dc:date>2026-07-21T20:42:06Z</dc:date>
    </item>
    <item>
      <title>Understanding Windows monthly updates: Servicing explained</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/understanding-windows-monthly-updates-servicing-explained/ba-p/4532290</link>
      <description>&lt;P&gt;Windows updates help keep devices secure, reliable, and productive. Whether you're an IT admin or a general user, understanding the different types of Windows updates can help you keep devices protected, productive, and continuously improving.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Most individuals and organizations regularly deploy monthly security updates, released on the second Tuesday of each month. Windows also provides optional non-security preview updates, which give IT teams and early adopters an opportunity to validate upcoming fixes before they're included in the next monthly security update.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;This guide explains the purpose of each update type, when updates are released, and how they fit into the modern Windows servicing model.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Monthly security updates&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;For many of you, the second Tuesday of each month (often referred to as "Patch Tuesday") is a regular part of Windows servicing for client and server endpoints. On this day, we publish monthly security updates for supported versions of Windows. &lt;BR /&gt;&lt;BR /&gt;Monthly security updates are designed to help you maintain security, compliance, and device health. These updates are cumulative. They include security and non-security content introduced in the prior month's security and optional non-security preview updates (see below). In other words, deploying the latest update brings a device up to date with all previously released fixes for that version of Windows. This helps simplify update management and reduce fragmentation across devices.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; People tend to use "B release," quality update, security update, monthly cumulative update, and latest cumulative update (LCU) interchangeably.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P style="margin-top: 16px;"&gt;You can deploy updates through a variety of channels depending on your scenario. General users and some small business environments rely on the built-in Windows Update, allowing Microsoft to manage your updates. Enterprise environments use any combination of Windows Update, Windows Autopatch, Microsoft Intune, Windows Server Update Services (WSUS), Microsoft Configuration Manager, the Microsoft Update Catalog, and/or non-Microsoft tools.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;IT admins can also enroll devices in &lt;A href="https://learn.microsoft.com/windows/deployment/windows-autopatch/manage/windows-autopatch-hotpatch-updates" target="_blank"&gt;hotpatch updates&lt;/A&gt; for a faster time to compliance. Hotpatch updates include security fixes only. They don't include the additional features and enhancements contained in monthly security updates. A quarterly baseline (a monthly security update with restart) is required to bring devices up to date on all the features. After that, the design is that the two subsequent monthly security updates are installed without requiring a restart.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Optional non-security preview updates&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Typically released during the fourth week of the month, optional non-security preview updates provide an opportunity to validate upcoming fixes before they become part of the next monthly security update. Optional non-security preview updates are also cumulative and are only offered for the most recent supported versions&lt;SUP&gt;&lt;A href="#community--1-_note1" target="_self"&gt;[1]&lt;/A&gt;&lt;/SUP&gt; of Windows. These updates are intended primarily for early preview of new features before broader rollout, as well as for testing and validation.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;New features, like &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/point-in-time-restore-for-windows-11-is-now-generally-available/4508101" target="_blank"&gt;point‑in‑time restore for Windows 11&lt;/A&gt;, might initially be released in an optional non-security preview update, then roll out broadly in the following month's security update. Please note that &lt;A href="https://support.microsoft.com/Windows/Deployment/Updates-Lifecycle/delivering-continuous-innovation-in-windows-11" target="_blank"&gt;some features roll out gradually&lt;/A&gt;, so you might not see them on your devices immediately upon installing an update.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;To access optional non-security preview updates on non-IT-managed devices, navigate to &lt;STRONG&gt;Settings&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Windows Update&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Advanced options&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Optional updates&lt;/STRONG&gt;. Select from the available updates and select &lt;STRONG&gt;Download and install&lt;/STRONG&gt;. Additionally, see how to &lt;A href="https://support.microsoft.com/Windows/Deployment/Updates-Lifecycle/get-windows-updates-as-soon-as-they-re-available-for-your-device" target="_blank"&gt;get Windows updates as soon as they're available for your device&lt;/A&gt;. The behavior of IT-managed devices depends &lt;A href="https://learn.microsoft.com/windows/deployment/update/waas-configure-wufb" target="_blank"&gt;on admin controls and policies&lt;/A&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; The term "optional non-security preview update" replaces what was formerly referred to as a "C" or "D" release. You might still see lettered shorthand references in IT management tools or documented&lt;A href="https://learn.microsoft.com/windows/release-health/windows11-release-information" target="_blank"&gt; release information.&lt;/A&gt; Inside Windows Update, you'll find them in the format of &lt;EM&gt;YYYY-MM Preview Update (KB number) (update build number)&lt;/EM&gt;. Learn more about &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/simplified-windows-update-titles/4465287" target="_blank"&gt;Simplified Windows Update titles&lt;/A&gt;.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Out-of-band update&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;In exceptional cases, Microsoft releases an out-of-band (OOB) update outside the normal monthly servicing cadence. These updates are designed to help resolve a known issue or to address an immediate, high-risk security concern. Some of these are optional, while others are recommended as security updates. OOB updates are typically cumulative, meaning they include all previously released fixes for the supported version of Windows in addition to the targeted fix. In enterprise environments, these updates are available for deployment through quality update approval and scheduling in Windows Autopatch, the Microsoft Update Catalog, and other enterprise update management tools.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;New features and improvements in Windows 11&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Windows 11 uses multiple delivery mechanisms to bring new features, experiences, and improvements to supported devices throughout the year. New capabilities can reach you through the annual feature update, monthly updates, or Microsoft Store updates, depending on the scenario or applicable IT controls. This enables us to deliver enhancements when they're ready while maintaining quality and reliability.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;In some cases, features become available to devices gradually over time, helping validate quality and compatibility before broader rollout. Aside from using optional non-security preview updates to release new capabilities before enabling them more broadly, Microsoft also uses Controlled Feature Rollout (CFR) technology. Capabilities released via CFR technology are typically disabled by default for organizations. If your organization needs greater control over when certain features become available, you can use &lt;A href="https://learn.microsoft.com/windows/deployment/update/waas-configure-wufb" target="_blank"&gt;commercial management controls&lt;/A&gt;.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Recommendations&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Keeping devices up to date is critical for security. &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/protect-your-estate-reassess-your-windows-update-policies/4515228" target="_blank"&gt;We recommend&lt;/A&gt; that organizations install the latest security updates as soon as they become available.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;We also encourage you to take advantage of optional non-security preview updates to internally validate features and fixes ahead of the following month's security update. For early access to the latest Windows features and to give feedback, join the &lt;A href="https://www.microsoft.com/en-us/windowsinsider/" target="_blank"&gt;Windows Insider Program&lt;/A&gt;.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;To help manage updates across your organization, bookmark these:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://support.microsoft.com/topic/windows-11-version-25h2-update-history-99c7f493-df2a-4832-bd2d-6706baa0dec0" target="_blank"&gt;Update history and release notes: Windows 11, versions 25H2 and 24H2&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/windows/release-health/" target="_blank"&gt;Windows release health&lt;/A&gt; (also available in the Microsoft 365 admin center)&lt;/LI&gt;
&lt;LI&gt;Additional tips and resources in &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/your-windows-release-information-toolbox/4430980" target="_blank"&gt;Your Windows release information toolbox&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;The updated reference onthe &lt;A href="https://learn.microsoft.com/windows/deployment/update/release-cycle" target="_blank"&gt;Update release cycle for Windows clients&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;Whether you're updating your personal device or deploying updates across your organization, understanding the Windows servicing model can help you make informed decisions. Now you can manage updates better, prepare for new features with confidence, and keep devices protected and productive throughout the year.&lt;/P&gt;
&lt;P style="margin-top: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-size: 14px; font-weight: 400; color: #333333;"&gt;&lt;a id="community--1-_note1" class="lia-anchor"&gt;&lt;/a&gt;&lt;SUP&gt;[1]&lt;/SUP&gt; As of July 9, 2026, "most recent supported versions" refers to Windows 11, versions 26H1, 25H2, and 24H2.&lt;/P&gt;
&lt;HR /&gt;
&lt;P style="font-size: 14px;"&gt;Continue the conversation. Find best practices. Bookmark the &lt;A href="http://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;Windows Tech Community&lt;/A&gt;. Looking for support? Visit &lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;Windows on Microsoft Q&amp;amp;A&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/understanding-windows-monthly-updates-servicing-explained/ba-p/4532290</guid>
      <dc:creator>Chris_Morrissey</dc:creator>
      <dc:date>2026-07-09T16:00:00Z</dc:date>
    </item>
    <item>
      <title>RDP Multipath with redundant TCP is now generally available for Windows 365 and Azure Virtual Desktop</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/rdp-multipath-with-redundant-tcp-is-now-generally-available-for/ba-p/4534610</link>
      <description>&lt;P&gt;Reliable connectivity is essential for delivering a productive Cloud PC and virtual desktop experience. Network variability—whether caused by packet loss, ISP instability, restrictive firewalls, proxy configurations, VPN routing, or UDP-restricted environments—continues to be one of the most common causes of session interruptions across enterprise remote desktop deployments.&lt;/P&gt;
&lt;P&gt;Today, we're excited to announce the&lt;STRONG&gt; general availability of RDP Multipath with redundant TCP support for Windows 365 and Azure Virtual Desktop&lt;/STRONG&gt;. This enhancement extends the resiliency benefits of RDP Multipath to TCP-based connections, helping organizations maintain a more reliable and consistent connectivity experience across a broader range of network environments.&lt;/P&gt;
&lt;P&gt;RDP Multipath continuously evaluates multiple available connection paths and dynamically selects the most reliable route for each session. If the active connection experiences degradation or becomes unavailable, RDP Multipath can automatically transition to an alternate path, helping reduce session interruptions and improve the overall user experience.&lt;/P&gt;
&lt;H4&gt;How RDP Multipath works&lt;/H4&gt;
&lt;P&gt;RDP Multipath establishes and maintains multiple available connection paths between the client device and the Windows 365 Cloud PC or Azure Virtual Desktop session host.&lt;/P&gt;
&lt;P&gt;When UDP-based RDP Shortpath connectivity is available, UDP remains the preferred transport protocol for optimal performance and reliability. RDP Multipath can establish multiple UDP paths using STUN (Simple Traversal Underneath NAT) and TURN (Traversal Using Relays around NAT) protocols, enabling sessions to dynamically transition between alternate UDP routes if degradation or failure is detected.&lt;/P&gt;
&lt;P&gt;With the addition of redundant TCP support, Windows 365 and Azure Virtual Desktop can now establish standby TCP paths alongside existing UDP connectivity. This means customers connecting through restrictive network environments can benefit from the same resiliency capabilities previously available only across UDP-based connections.&lt;/P&gt;
&lt;P&gt;If the active connection becomes unavailable or experiences degraded performance, RDP Multipath automatically transitions to the next available path—UDP or TCP—without requiring user intervention or reconnection. In situations where all paths are lost, such as a temporary network outage, the session attempts to reconnect once connectivity is restored.&lt;/P&gt;
&lt;P&gt;Many organizations operate in environments where UDP connectivity is restricted or unavailable because of firewall, proxy, or security requirements. In these scenarios, remote desktop sessions often rely on TCP-based Reverse Connect transport.&lt;/P&gt;
&lt;P&gt;Previously, these environments generally relied on a single TCP connection. With redundant TCP support, Windows 365 and Azure Virtual Desktop can now maintain standby TCP paths and dynamically transition between them if the active connection becomes degraded or unavailable. This extends the resiliency benefits of RDP Multipath to customers operating in restrictive network environments.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Key Benefits:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Improved connection reliability: &lt;/STRONG&gt;Multiple connection paths are maintained throughout the session. If the active path becomes unstable or unavailable, RDP Multipath can automatically switch to a backup path, helping reduce session interruptions.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Enhanced resiliency across network environments: &lt;/STRONG&gt;Organizations can benefit from RDP Multipath whether connections are established through UDP-based RDP Shortpath or TCP-based Reverse Connect transport.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Seamless user experience:&lt;/STRONG&gt; Path selection and failover occur automatically and transparently, helping users stay connected and productive without requiring any action.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;No additional configuration required: &lt;/STRONG&gt;RDP Multipath works automatically when prerequisite requirements are met, simplifying deployment and adoption for IT administrators.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;Understanding RDP Multipath connectivity&lt;/H4&gt;
&lt;img /&gt;
&lt;P&gt;The diagram above illustrates &lt;STRONG&gt;one example&lt;/STRONG&gt; of how RDP Multipath can establish and manage multiple connection paths between a client device and a Windows 365 Cloud PC or Azure Virtual Desktop session.&lt;/P&gt;
&lt;P&gt;The exact paths available for a connection depend on factors such as network topology, firewall and proxy configuration, NAT behavior, and whether UDP-based RDP Shortpath connectivity is available.&lt;/P&gt;
&lt;P&gt;In the scenario shown above:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;A UDP-based RDP Shortpath connection is used as the primary active path.&lt;/LI&gt;
&lt;LI&gt;Additional UDP transport paths can be established through STUN or TURN when supported by the network configuration.&lt;/LI&gt;
&lt;LI&gt;Redundant TCP transport paths can also be maintained as standby paths to improve resiliency.&lt;/LI&gt;
&lt;LI&gt;RDP Multipath continuously evaluates available transport paths and monitors connection health.&lt;/LI&gt;
&lt;LI&gt;If the active transport path becomes unavailable or experiences degradation, RDP Multipath can transition traffic to another available transport path to help maintain session continuity.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;When UDP connectivity is available, it remains the preferred transport protocol for optimal performance and reliability. Redundant TCP transport paths extend Multipath resiliency to environments where UDP connectivity may be restricted or unavailable due to firewall, proxy, or network policies.&lt;/P&gt;
&lt;H4&gt;How to enable RDP Multipath&lt;/H4&gt;
&lt;P&gt;By default, this feature is enabled for everyone providing seamless integration and enhanced connectivity without requiring any changes from IT departments or end users. &lt;STRONG&gt;Redundant TCP transport paths are currently supported only on Windows devices using Windows App on Windows client, version 2.0.1069.0 or later.&lt;/STRONG&gt;&lt;/P&gt;
&lt;H4&gt;Learn more&lt;/H4&gt;
&lt;P&gt;To learn more about RDP Multipath, visit:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/virtual-desktop/rdp-multipath" target="_blank" rel="noopener"&gt;Use RDP Multipath with Azure Virtual Desktop | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/windows-365/enterprise/rdp-multipath" target="_blank" rel="noopener"&gt;Use RDP Multipath with Windows 365 | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;Continue the conversation. Find best practices. Bookmark the &lt;/SPAN&gt;&lt;A href="https://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Tech Community&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;, then follow us on &lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/company/windows-it-pro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; or &lt;/SPAN&gt;&lt;A href="https://twitter.com/mswindowsitpro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSWindowsITPro&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; for updates. Looking for support? Visit &lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows on Microsoft Q&amp;amp;A&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:257}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jul 2026 16:42:03 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/rdp-multipath-with-redundant-tcp-is-now-generally-available-for/ba-p/4534610</guid>
      <dc:creator>Rinku_Dalwani</dc:creator>
      <dc:date>2026-07-21T16:42:03Z</dc:date>
    </item>
    <item>
      <title>Windows 365 for Agents: A secured execution environment for AI agents</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-365-for-agents-a-secured-execution-environment-for-ai/ba-p/4529336</link>
      <description>&lt;P&gt;AI agents are rapidly evolving from answering questions to performing tasks across enterprise systems. As organizations move from experimentation to production, one question continues to rise to the top for security leaders: &lt;STRONG&gt;how do you run agents securely at scale?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Today, many agents operate in fragmented environments: local machines, shared virtual machines, or unmanaged cloud infrastructure. That can make it hard to consistently enforce identity, apply policies, and maintain the visibility security teams need.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Windows 365 for Agents changes that.&lt;/STRONG&gt;&lt;/P&gt;
&lt;H4&gt;A Cloud PC for enterprise agents, with security built-in&lt;/H4&gt;
&lt;P&gt;Windows 365 for Agents provides secured, managed Cloud PCs built for AI agents. As your organization governs and protects your human users today, Windows 365 for Agents enables you to apply the same enterprise security and compliance controls to agentic workloads.&lt;/P&gt;
&lt;P&gt;Windows 365 for Agents works with Microsoft Entra, Microsoft Intune, Microsoft Defender, Microsoft Purview, and Microsoft Agent 365&lt;SUP&gt;1&lt;/SUP&gt; to provide identity, device management, security, and data governance capabilities for agentic workloads. Agents are designed to operate within enterprise security and compliance boundaries, running in a managed environment with identity, compliance, and security controls.&lt;/P&gt;
&lt;P&gt;These core security tenets make it possible.&lt;/P&gt;
&lt;img /&gt;
&lt;H4&gt;1. Reduced identity risk with distinct agent identity&lt;/H4&gt;
&lt;P&gt;Agents running in Windows 365 for Agents are provisioned with their &lt;STRONG&gt;own identity&lt;/STRONG&gt; in Microsoft Entra, &lt;STRONG&gt;separate from any human user&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;When an agent is hired, a unique &lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/agent-id/" target="_blank" rel="noopener"&gt;agent identity&lt;/A&gt; is automatically assigned, helping ensure:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Every action is attributable to a specific agent&lt;/LI&gt;
&lt;LI&gt;Permissions can be scoped precisely&lt;/LI&gt;
&lt;LI&gt;Access can be revoked when necessary&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This separation is foundational to &lt;A class="lia-external-url" href="https://learn.microsoft.com/security/zero-trust/zero-trust-overview" target="_blank" rel="noopener"&gt;Zero Trust&lt;/A&gt;. It reduces identity crossover risks and helps ensure agents operate only with the permissions they are explicitly granted. Agents can be governed with full lifecycle management, role-based access control, and auditability built in.&lt;/P&gt;
&lt;P&gt;With &lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/identity/conditional-access/policy-autonomous-agents?tabs=use-the-enhanced-object-picker#require-a-compliant-device-for-agents-user-accounts" target="_blank" rel="noopener"&gt;Entra Conditional Access&lt;/A&gt;, organizations can enforce access policies by allowing access to organizational resources only when the Windows 365 for Agents Cloud PC is compliant with the organization’s security requirements. This helps ensure agents access enterprise resources only from managed and compliant Cloud PCs.&lt;/P&gt;
&lt;P&gt;By combining identity-based access control with &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-security/compliance/overview" target="_blank" rel="noopener"&gt;Intune device compliance&lt;/A&gt;, organizations can extend Microsoft’s &lt;A class="lia-external-url" href="https://learn.microsoft.com/security/zero-trust/deploy/identity" target="_blank" rel="noopener"&gt;Zero Trust policy engine&lt;/A&gt; to agents with the same rigor used for human users.&lt;/P&gt;
&lt;H4&gt;2. Reduced access risk with agent-only access&lt;/H4&gt;
&lt;P&gt;Windows 365 for Agents Cloud PCs are reserved exclusively for agents and run on &lt;STRONG&gt;isolated and enterprise-managed compute environments&lt;/STRONG&gt; built for agent operations. By providing agents with a dedicated and contained execution environment, organizations can mitigate risks such as privilege escalation, accidental human-agent crossover, and lateral movement across shared accounts. IT administrators can further reinforce these boundaries through Intune provisioning policies that assign Cloud PCs only to agent users, helping ensure these environments are used for their intended purpose.&lt;/P&gt;
&lt;H4&gt;3. Consistent security and compliance enforcement&lt;/H4&gt;
&lt;P&gt;Every Windows 365 for Agents Cloud PC is Entra-joined and Intune-enrolled. Such Cloud PCs are managed by Microsoft Intune&lt;SUP&gt;1&lt;/SUP&gt;, applying the same security posture your organization already relies on for employee devices.&lt;/P&gt;
&lt;P&gt;That means:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Security baselines and compliance policies can be applied from the moment of provisioning&lt;/LI&gt;
&lt;LI&gt;Configuration, hardening, and updates are centrally managed&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Agents inherit endpoint security controls, including antivirus, encryption, and device compliance checks. Because these Cloud PCs are managed like any other endpoint, you can extend your existing security investments directly to agentic workloads, simplifying operations while strengthening protection and governance.&lt;/P&gt;
&lt;H4&gt;4. Network protection with Global Secure Access&lt;/H4&gt;
&lt;P&gt;Windows 365 for Agents also extends agent security to how agents access the network. Windows 365 for Agents integrates with &lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/global-secure-access/" target="_blank" rel="noopener"&gt;Microsoft Entra Global Secure Access (GSA)&lt;/A&gt; to provide an identity-driven network security layer for agents. This helps organizations apply the same Zero Trust principles they already use for users and devices to agent traffic.&lt;/P&gt;
&lt;P&gt;With GSA, organizations can route internet traffic through secure, policy-enforced profiles to help protect agents from malicious destinations, risky connections, and unsafe web activity. Security teams can apply controls for web content filtering, URL-based access policies, and inline threat protection.&lt;/P&gt;
&lt;P&gt;By combining network signals with identity and device context, organizations can extend Zero Trust protection beyond authentication and into every network connection an agent makes, while maintaining full visibility into how agents interact with enterprise and external resources.&lt;/P&gt;
&lt;P&gt;Read our &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows-365/agents/network-security-globalsecureaccess" target="_blank" rel="noopener"&gt;network security with Global Secure Access&lt;/A&gt; learn article to learn more.&lt;/P&gt;
&lt;H4&gt;5. Governance and visibility into Agent Activity&lt;/H4&gt;
&lt;P&gt;Security is more than prevention; it is also about governance, visibility, and control. By integrating with &lt;A class="lia-external-url" href="https://www.microsoft.com/security/blog/2026/05/01/microsoft-agent-365-now-generally-available-expands-capabilities-and-integrations/" target="_blank" rel="noopener"&gt;Microsoft Agent 365&lt;/A&gt;&lt;SUP&gt;1&lt;/SUP&gt;, organizations gain visibility into agent activity and can apply governance and policy controls across agent execution environments. Windows 365 for Agents is exposed as a model context protocol (MCP) server in &lt;A class="lia-external-url" href="https://learn.microsoft.com/microsoft-copilot-studio/mcp-windows-365-agents-work-iq" target="_blank" rel="noopener"&gt;Agent 365&lt;/A&gt;, and the telemetry flows into the tools your security teams already use such as &lt;A class="lia-external-url" href="https://learn.microsoft.com/microsoft-agent-365/leadership/defender-agent-365" target="_blank" rel="noopener"&gt;Microsoft Defender&lt;/A&gt; and &lt;A class="lia-external-url" href="https://learn.microsoft.com/purview/ai-agent-365" target="_blank" rel="noopener"&gt;Microsoft Purview&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Resilience against threats with &lt;A class="lia-external-url" href="https://learn.microsoft.com/defender-xdr/security-for-ai/ai-agent-inventory" target="_blank" rel="noopener"&gt;Microsoft Defender&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Agent activity integrates into Microsoft Defender's AI agent inventory and protection, letting security administrators discover Agent 365 enabled agents in your estate. For agents, Defender offers:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Advanced hunting across all agent activity&lt;/LI&gt;
&lt;LI&gt;Traceability of agent identity, tools, and actions&lt;/LI&gt;
&lt;LI&gt;Threat detection and investigation workflows&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Protection of sensitive data with &lt;A class="lia-external-url" href="https://learn.microsoft.com/purview/ai-agents" target="_blank" rel="noopener"&gt;Microsoft Purview&lt;/A&gt;&lt;SUP&gt;1&lt;/SUP&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;On the data side, Microsoft Purview extends your existing security and compliance controls to agentic workloads.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Data Security Posture Management (DSPM) for AI continuously assesses how agents interact with your data and helps you evaluate alignment with your policies.&lt;/LI&gt;
&lt;LI&gt;Activity Explorer delivers granular visibility into agent data usage, including what was accessed, classified, or shared, so sensitive information stays within your policy boundaries.&lt;/LI&gt;
&lt;LI&gt;Existing sensitivity labels, Data Loss Prevention (DLP), and retention policies apply to agent actions similar to human users.&lt;/LI&gt;
&lt;LI&gt;Insider Risk Management (IRM) detects risky agent behaviors, identifies elevated risk levels, and prioritizes investigations before sensitive data is exposed or misused.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Together, Agent 365, Defender, and Purview provide organizations with governance, visibility, and security capabilities for agent activity on Windows 365 for Agents Cloud PCs.&lt;/P&gt;
&lt;P&gt;This Windows 365 for Agents demo shows how agents execute in a secure, managed environment.&lt;/P&gt;
&lt;DIV class="lia-embeded-content" contenteditable="false"&gt;&lt;IFRAME src="https://www.youtube.com/embed/WakkSy4efpE?si=CGN644UPkN4LDzL0" width="560" height="315" title="YouTube video player" allowfullscreen="allowfullscreen" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" frameborder="0" sandbox="allow-scripts allow-same-origin allow-forms"&gt;&lt;/IFRAME&gt;&lt;/DIV&gt;
&lt;H4&gt;Are you ready for enterprise-ready agentic computing?&lt;/H4&gt;
&lt;P&gt;Windows 365 for Agents brings identity, device management, and observability together into a unified, secure platform built for AI agents. In summary, this includes:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Distinct identity&lt;/STRONG&gt; to establish the Zero Trust foundation&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Agent-only environments&lt;/STRONG&gt; to reduce risk of misuse by design&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Intune management&lt;/STRONG&gt; that enforces a consistent security posture&lt;/LI&gt;
&lt;LI&gt;Identity-aware, real-time &lt;STRONG&gt;network protection &lt;/STRONG&gt;with Global Secure Access&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Governance and visibility&lt;/STRONG&gt; with Agent 365&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;As your organization scales AI adoption, this model provides governance, compliance, and security capabilities designed to help manage agent workloads throughout their lifecycle.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Ready to put agents to work securely?&lt;/STRONG&gt; Learn more about Windows 365 for Agents security on our &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows-365/agents/security-overview" target="_blank" rel="noopener"&gt;support page&lt;/A&gt; and start running enterprise-ready agentic workloads today.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P style="font-size: 0.85em; color: #666;"&gt;Footnote: 1. Access to and use of Microsoft Entra, Microsoft Intune, Microsoft Defender, Microsoft Purview, and Microsoft Agent 365 capabilities are subject to applicable licensing requirements and may require separate purchases.&lt;/P&gt;
&lt;P&gt;Continue the conversation. Find best practices. Bookmark the &lt;A href="https://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Tech Community&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, then follow us&amp;nbsp;on &amp;nbsp;&lt;A href="https://www.linkedin.com/company/windows-it-pro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;or&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://twitter.com/mswindowsitpro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSWindowsITPro&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; for updates. Looking for support? Visit &lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows on Microsoft Q&amp;amp;A&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-365-for-agents-a-secured-execution-environment-for-ai/ba-p/4529336</guid>
      <dc:creator>Aarthi_Sukumar</dc:creator>
      <dc:date>2026-07-08T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Windows settings backup becoming a new resilience baseline</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-settings-backup-becoming-a-new-resilience-baseline/ba-p/4530757</link>
      <description>&lt;P style="margin-bottom: 20px;"&gt;Resilience is about to get easier for the Windows devices you manage! Eligible devices will now have the backup function on by default with &lt;STRONG&gt;Windows settings backup and restore&lt;/STRONG&gt; (previously called Windows Backup for Organizations). Today, it's available to Windows Insiders and will be generally available starting with Windows 11, version 26H2. A recoverable list of settings and Microsoft Store apps is becoming a baseline part of the Windows experience rather than an opt-in configuration step.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Note: &lt;/STRONG&gt;Restore behavior is unchanged and isn't enabled by default. You still need explicit admin configuration to restore Windows devices&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;A baseline designed with IT admins in mind&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Staying resilient today is no longer a nice-to-have for businesses. Resetting, replacing, and reimaging a PC is fundamental to onboarding and user experience. It's also a baseline for staying resilient.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Imagine a lost laptop, a hardware refresh, or an unexpected reset. These are some of the moments when your users need backup most. And that's rarely when anyone wants to discover that backup was never turned on.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Making backup the baseline shifts it from a best-effort configuration step to a standard capability across your eligible fleet.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Recovery without configuration: &lt;/STRONG&gt;Eligible devices with the backup policy in a &lt;STRONG&gt;Not Configured&lt;/STRONG&gt; state under Windows settings backup and restore&lt;SUP&gt;&lt;A href="#community--1-_note1" target="_self"&gt;[1]&lt;/A&gt;&lt;/SUP&gt; will back up automatically. Users' settings and Microsoft Store app list are captured out of the box. Note: Restore behavior still requires configuration to be enabled.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Explicit policy always wins: &lt;/STRONG&gt;If you have already enabled or disabled the policy, your setting is honored. The default applies only when policy state is &lt;STRONG&gt;Not Configured&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Restore stays admin-managed: &lt;/STRONG&gt;The default-on change applies to backup only. The restore function continues to require explicit admin configuration and is off by default.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;User choice preserved:&lt;/STRONG&gt;End user settings are protected automatically, and they keep full flexibility — they can run a backup at any time from the Windows Backup app and choose which settings are included from the Windows Settings page, all in line with the admin's policy.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 24px;"&gt;We've experienced these benefits first-hand at Microsoft, when we made backups automatic for employees across the organization.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-22 lia-border-color-custom-0078d4 lia-border-style-dotted" border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr class="lia-border-color-custom-0078d4 lia-border-style-dotted" style="height: 40px;"&gt;&lt;td&gt;
&lt;P style="margin: 16px;"&gt;&lt;EM&gt;"Windows Backup for Organizations&lt;SUP&gt;&lt;A href="#community--1-_note1" target="_self"&gt;[1]&lt;/A&gt;&lt;/SUP&gt; is changing how device refresh works. Pressure tested inside Microsoft on a global scale, it enables Microsoft Store apps and user settings to move seamlessly with our people and free IT teams from the heavy lifting of device reimaging. The result is a simpler, more resilient experience."&amp;nbsp; - &lt;/EM&gt;&lt;EM&gt;Brian Fielder, Vice President, Microsoft Digital&lt;/EM&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 100.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P style="margin-top: 16px;"&gt;The operational benefit is simple: When a device needs to be reset, replaced, or reimaged, you can move forward immediately. No need to rush checking whether backup was ever configured for the users. Their familiar setup is already captured and ready to come back with them.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;The scope of the default-on Windows backup&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;The default-on behavior applies to devices that meet all these conditions:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;S&gt; &lt;/S&gt;Running Windows 11, version 26H2&lt;SUP&gt;&lt;A href="#community--1-_note1" target="_self"&gt;[2]&lt;/A&gt;&lt;/SUP&gt; or later&lt;/LI&gt;
&lt;LI&gt;In countries or regions not regulated by the EU Digital Markets Act (DMA)Not in sovereign or restricted cloud environments&lt;/LI&gt;
&lt;LI&gt;With the backup policy in a &lt;STRONG&gt;Not Configured&lt;/STRONG&gt; state under Windows settings backup and restore*&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;Devices outside this scope keep their existing behavior:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Devices in privacy sensitive countries or regions remain off by default.&lt;/LI&gt;
&lt;LI&gt;Devices in sovereign or restricted cloud environments remain off by default.&lt;/LI&gt;
&lt;LI&gt;Devices with the backup policy explicitly enabled or disabled continue to honor that explicit setting.&lt;/LI&gt;
&lt;LI&gt;Devices running previous &lt;A href="https://learn.microsoft.com/windows/configuration/windows-backup/?tabs=intune" target="_blank" rel="noopener"&gt;supported&lt;/A&gt; Windows 11 versions (except for version 26H1) remain off by default.&lt;/LI&gt;
&lt;LI&gt;Devices originally running Windows 11, version 26H1 will receive the same default-on treatment starting with the following feature update.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Getting started&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;If your environment is already in scope and in the state you want, you're ready. No action required. Otherwise, here's how to pick the behavior that fits your organization:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Keep backup on (recommended): No action required. Eligible devices with the backup policy in a &lt;STRONG&gt;Not Configured&lt;/STRONG&gt; state under Windows settings backup and restore* will enable backup automatically at general availability of Windows 11, version 26H2.&lt;/LI&gt;
&lt;LI&gt;Opt out: Explicitly disable the backup policy through Microsoft Intune, Group Policy, or your MDM solution. Explicit disablement always takes precedence over the default.&lt;/LI&gt;
&lt;LI&gt;Make intent explicit: Set the backup policy to enabled today. This is functionally equivalent to the new default but provides an unambiguous, audit-friendly admin signal, and the ability for user-targeted enablement only.&lt;/LI&gt;
&lt;LI&gt;Control restore behavior separately: Configure the restore policy on its own. The default-on change applies to backup only.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;You can validate the experience early. The default-on behavior is available with Windows 11, version 26H2 in Windows Insider Program Experimental channel starting July 2026. It takes broad effect for eligible devices at Windows 11, version 26H2 general availability later this year. Devices originally running Windows 11, version 26H1 will receive the same default-on treatment starting with the following feature update.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Watch this video for a quick tour of the experience:&lt;/P&gt;
&lt;div data-video-id="https://www.youtube.com/watch?v=x5-NDM91Q7E/1783371663985" data-video-remote-vid="https://www.youtube.com/watch?v=x5-NDM91Q7E/1783371663985" class="lia-video-container lia-media-is-center lia-media-size-large"&gt;&lt;iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2Fx5-NDM91Q7E%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3Dx5-NDM91Q7E&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2Fx5-NDM91Q7E%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" allowfullscreen="" style="max-width: 100%"&gt;&lt;/iframe&gt;&lt;/div&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Ready for broader Windows resiliency&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Thank you for your feedback that shaped this change. Making backup the baseline is one step in a broader Windows resiliency effort. We'll keep sharing what's coming next, so you can plan with confidence.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Catch up and learn more:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/windows/configuration/windows-backup/" target="_blank" rel="noopener"&gt;Windows settings backup and restore&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/windows/configuration/windows-backup/" target="_blank" rel="noopener"&gt;Configure backup and restore policies in Microsoft Intune&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://blogs.windows.com/windows-insider/2026/07/06/announcing-new-builds-for-july-6-2026/" target="_blank" rel="noopener"&gt;Windows Insider Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/windows-insider/release-notes/experimental/preview-build-26300-8772" target="_blank" rel="noopener"&gt;Windows Insider release notes&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/windows-first-sign-in-restore-experience-now-available/4495551" target="_blank" rel="noopener"&gt;Windows first sign-in restore experience now available&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/windows-backup-for-organizations-is-now-available/4441655" target="_blank" rel="noopener"&gt;Windows Backup for Organizations is now available&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;P style="margin-top: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-size: 14px; font-weight: 400; color: #333333;"&gt;&lt;a id="community--1-_note1" class="lia-anchor"&gt;&lt;/a&gt;&lt;SUP&gt;[1]&lt;/SUP&gt;&lt;STRONG&gt;Windows Backup for Organizations&lt;/STRONG&gt; is now &lt;STRONG&gt;Windows settings backup and restore&lt;/STRONG&gt;. You'll start seeing the new name alongside the original name while we update documentation and policy surfaces.&lt;/P&gt;
&lt;P style="font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-size: 14px; font-weight: 400; color: #333333;"&gt;&lt;a id="community--1-_note2" class="lia-anchor"&gt;&lt;/a&gt;&lt;SUP&gt;[2]&lt;/SUP&gt;&lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/get-ready-for-windows-11-version-26h2/4529367" target="_blank" rel="noopener"&gt;Windows 11, version 26H2&lt;/A&gt; is the annual feature update for Windows 11, versions 25H2 and 24H2. It will be released in the second half of the 2026 calendar year.&lt;/P&gt;
&lt;HR /&gt;
&lt;P style="font-size: 14px;"&gt;Continue the conversation. Find best practices. Bookmark the &lt;A href="http://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;Windows Tech Community&lt;/A&gt;. Looking for support? Visit &lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;Windows on Microsoft Q&amp;amp;A&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2026 21:45:48 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-settings-backup-becoming-a-new-resilience-baseline/ba-p/4530757</guid>
      <dc:creator>Miranda_Leschke</dc:creator>
      <dc:date>2026-07-06T21:45:48Z</dc:date>
    </item>
    <item>
      <title>Windows news you can use: June 2026</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-news-you-can-use-june-2026/ba-p/4532288</link>
      <description>&lt;P&gt;Earlier this month, we announced that &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/get-ready-for-windows-11-version-26h2/4529367" target="_blank"&gt;Windows 11, version 26H2&lt;/A&gt;—the next annual feature update for Windows 11—is now available for early testing and validation via the Windows Insider Program. As this release will share the same servicing branch as versions 25H2 and 24H2, devices can be updated using an enablement package, quickly and with minimal disruption to users. Microsoft also announced major &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/made-for-developers-and-agents-windows-365-at-build-2026/4519041" target="_blank"&gt;Windows 365 updates at Build 2026&lt;/A&gt;, introducing ready-to-code Cloud PCs, expanded developer-focused capabilities, and new support for secure enterprise AI agents.&lt;/P&gt;
&lt;P&gt;Now let's dive into more developments in the world of Windows for IT admins from the month of June.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;New in Windows update and device management&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;[RECOVERY] – Now generally available, &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/point-in-time-restore-for-windows-11-is-now-generally-available/4508101" target="_blank"&gt;point‑in‑time restore for Windows 11&lt;/A&gt; can help users recover in minutes instead of hours by safely rolling a device back to a previous state. This built-in recovery capability is available for Windows Enterprise, Pro, and Home editions of Windows 11.&lt;/LI&gt;
&lt;LI&gt;[W365] – An &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/teams-remote-app-cloud-app-optimization-for-windows-365-and-azure-virtual-deskto/4515930" target="_blank"&gt;optimized Teams experience for Remote App scenarios&lt;/A&gt; is now available, offering improved audio and video performance, reliability, and security.&lt;/LI&gt;
&lt;LI&gt;[PRINTING] – What was formerly the Modern Print Platform is now &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/introducing-windows-ready-print-and-modernized-driver-selection/4527563" target="_blank"&gt;Windows Ready Print&lt;/A&gt;. It's now Windows preferred means of communicating to printers, including the Internet Printing Protocol (IPP), eSCL scanning, and Universal Print. Starting in July 2026, new printer installations will default to Windows Ready Print where supported, enabling a simpler and more reliable setup experience.&lt;/LI&gt;
&lt;LI&gt;[APPS] – &lt;A href="https://aka.ms/AutoUpdateForEnterpriseApps" target="_blank"&gt;Auto-updates in Microsoft Intune Enterprise Application Management&lt;/A&gt; are now available. Keep managed applications on the latest incremental release, such as 4.1 to 4.2, without manual packaging or admin intervention.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;New in Windows security&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;[SECURE BOOT] [TIPS] – If your organization hasn't yet finished updating Secure Boot certificates for client devices, servers, or virtual machines, find out which &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/best-practices-for-deploying-secure-boot-certificate-updates/4529884" target="_blank"&gt;best practices&lt;/A&gt; can help. If you run into devices that are blocked from receiving updated Secure Boot certificates, explore &lt;A href="https://support.microsoft.com/en-us/topic/if-you-re-prevented-from-updating-secure-boot-certificates-e01cc486-8721-457f-9bc7-5cb801c1759e" target="_blank"&gt;actions you can consider&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;[SECURE BOOT] [LINUX] – New guidance is now available to help you manage &lt;A href="https://support.microsoft.com/topic/secure-boot-certificate-updates-for-linux-on-azure-virtual-machines-df51ba85-4e1e-4eda-b1d8-f0881970e997" target="_blank"&gt;Secure Boot certificate updates for Linux&lt;/A&gt; on Azure virtual machines. This includes Trusted Launch and Confidential VMs with Secure Boot enabled.&lt;/LI&gt;
&lt;LI&gt;[SECURE BOOT] [EVENTS] – In response to your feedback, two specialized Q&amp;amp;A events for Secure Boot will take place in July. Join &lt;A href="https://techcommunity.microsoft.com/event/windowsevents/secure-boot-office-hours-for-virtualized-environments/4530355" target="_blank"&gt;Secure Boot Office Hours for virtualized environments&lt;/A&gt; (July 8). During &lt;A href="https://techcommunity.microsoft.com/event/windowsevents/oem-secure-boot-office-hours/4530352" target="_blank"&gt;OEM Secure Boot Office Hours&lt;/A&gt; (July 15), get answers from the OEM ecosystem, Broadcom, and Windows cloud experience experts. (Note: There is no on-camera or meeting component to these events. All Q&amp;amp;A will take place in the comments on the Tech Community.)&lt;/LI&gt;
&lt;LI&gt;[IDENTITY] – &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/reducing-ntlm-dependency-iakerb-and-localkdc-in-windows-insider-preview/4524615" target="_blank"&gt;IAKerb and LocalKDC&lt;/A&gt; are new capabilities that expand Kerberos authentication across enterprise and local account scenarios. That's how Microsoft is advancing efforts to reduce NTLM dependency and strengthen security. Available today in the Windows Insider Program, a public preview is coming for both client and server.&lt;/LI&gt;
&lt;LI&gt;[W365] [DATA PROTECTION] – &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/adaptive-data-protection-with-context-based-redirections-in-windows-365-now-in-p/4521366" target="_blank"&gt;Context-based redirections for Windows 365&lt;/A&gt; can now be explored in public preview. Apply more granular controls to device and resource redirection based on contextual signals. Available signals are device management state, compliance posture, user or group membership, and network conditions.&lt;/LI&gt;
&lt;LI&gt;[HARDENING] – The final deployment phase for &lt;A href="https://support.microsoft.com/topic/1ebcda33-720a-4da8-93c1-b0496e1910dc" target="_blank"&gt;Kerberos RC4 hardening&lt;/A&gt; begins with the July 2026 Windows security update. This phase completes the transition from legacy encryption types such as RC4. It removes Audit mode and leaves Enforcement mode as the only supported behavior for Kerberos RC4 usage on Windows domain controllers.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;To explore what's new in security across the Microsoft platform, see &lt;A href="https://www.microsoft.com/en-us/security/blog/2026/06/30/whats-new-in-microsoft-security-june-2026/" target="_blank"&gt;What's new in Microsoft Security: June 2026&lt;/A&gt;.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;New in AI&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;[AGENTS] [SECURITY] – At Build 2026, Windows introduced &lt;A href="https://blogs.windows.com/windowsdeveloper/2026/06/02/windows-platform-security-for-ai-agents/" target="_blank"&gt;new security foundations for AI agents&lt;/A&gt;. They're designed to provide governance, containment, and enterprise-grade controls for autonomous agent workloads.&lt;/LI&gt;
&lt;LI&gt;[AGENTS] [W365] – Windows 365 for Agents is generally available within Agent 365. With this update, Cloud PCs that enable AI agents can execute multi-step workflows across software. Use it to open apps, navigate interfaces, enter inputs, and process data.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;New in Windows Server&lt;/H2&gt;
&lt;P&gt;For the latest features and improvements for Windows Server, see the &lt;A href="https://support.microsoft.com/topic/windows-server-2025-update-history-10f58da7-e57b-4a9d-9c16-9f1dcd72d7d7" target="_blank"&gt;Windows Server 2025 release notes&lt;/A&gt; and &lt;A href="https://support.microsoft.com/topic/windows-server-version-23h2-update-history-68c851ff-825a-4dbc-857b-51c5aa0ab248" target="_blank"&gt;Windows Server, version 23H2 release notes&lt;/A&gt;.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;[NETWORKING] – &lt;A href="https://techcommunity.microsoft.com/blog/networkingblog/doh-is-now-generally-available-on-windows-dns-server/4526839" target="_blank"&gt;DoH support for Windows DNS Server&lt;/A&gt; is generally available on Windows Server 2025. You can now deploy encrypted and authenticated client-to-resolver DNS traffic directly within your existing on-premises DNS infrastructure.&lt;/LI&gt;
&lt;LI&gt;[HOTPATCH] – &lt;A href="https://learn.microsoft.com/windows/release-health/status-windows-server-2022#:~:text=Current%20status" target="_blank"&gt;Hotpatch update support for Windows Server 2022&lt;/A&gt; Datacenter: Azure Edition has been extended through October 2027.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;New in productivity and collaboration&lt;/H2&gt;
&lt;P&gt;Install the June 2026 security update for &lt;A href="https://support.microsoft.com/topic/june-9-2026-kb5094126-os-builds-26200-8655-and-26100-8655-1a9bcba6-5f53-4075-8156-fe11ac631737" target="_blank"&gt;Windows 11, versions 25H2 and 24H2&lt;/A&gt; to get these and other capabilities, which will be rolling out gradually:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;[AUDIO] – &lt;A href="https://techcommunity.microsoft.com/blog/WindowsOSPlatform/share-the-moment-listen-together-with-shared-audio/4522401" target="_blank"&gt;Shared Audio&lt;/A&gt; can keep people productive on the move. Two people can now to listen to the same audio from a single Windows 11 PC at the same time.&lt;/LI&gt;
&lt;LI&gt;[SECURITY] – When Windows Hello face or fingerprint is set up and available, it's now the default sign-in method every time you sign in. Even if you used a different method previously.&lt;/LI&gt;
&lt;LI&gt;[FILES] – Windows Search will now find and prioritize files with as few as two characters.&lt;/LI&gt;
&lt;LI&gt;[BATTERY] – This update improves resiliency against apps that could keep the sensor hub powered on and drain power. Enjoy a better battery life.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;New features and improvements are coming in the July 2026 security update. You can preview them by installing the June 2026 optional non-security update for &lt;A href="https://support.microsoft.com/topic/june-23-2026-kb5095093-os-builds-26200-8737-and-26100-8737-preview-0e2a20f2-cf9e-46f8-9f08-e6996220882d" target="_blank"&gt;Windows 11, versions 25H2 and 24H2&lt;/A&gt;. This update includes the gradual rollout of:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;[WIDGETS] – A quieter, more focused Widgets experience helps reduce interruptions and improves default settings and notification controls. For example, Widgets no longer open on hover, and notifications and taskbar badges are minimized by default.&lt;/LI&gt;
&lt;LI&gt;[ACCESSIBILITY] – You can now apply a full-screen color overlay to help reduce eye strain and improve readability. You can also enter a zoom percentage directly and change it in increments in the Magnifier window for more precise, flexible control. And, you can now use voice access and voice typing in French, German, and Spanish.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;To learn about planned productivity, security, and reliability updates for Windows 11, visit the &lt;A href="https://aka.ms/WindowsRoadmap" target="_blank"&gt;Windows Roadmap&lt;/A&gt;.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Lifecycle reminders&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;[SERVER] – &lt;A href="https://support.microsoft.com/topic/directaccess-deprecation-on-future-windows-server-releases-a-new-era-of-always-on-connectivity-c84f69b4-794e-48e2-9701-c36cb1e258d9" target="_blank"&gt;DirectAccess has been deprecated&lt;/A&gt; and will be removed in a future version of Windows Server. It has been replaced by a more modern, flexible solution: Always On VPN. For migration guidance, see &lt;A href="https://learn.microsoft.com/windows-server/remote/remote-access/da-always-on-vpn-migration/da-always-on-migration-overview" target="_blank"&gt;Remote Access Always On VPN migration&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;[WINDOWS 10] [ESU] – The Windows 10 Extended Security Updates (ESU) program for personal use devices is being provided for an additional year. Coverage is now available through Oct. 12, 2027.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Check out our lifecycle documentation for the latest updates on &lt;A href="https://learn.microsoft.com/windows/whats-new/deprecated-features" target="_blank"&gt;Deprecated features in the Windows client&lt;/A&gt; and &lt;A href="https://learn.microsoft.com/windows-server/get-started/removed-deprecated-features-windows-server-2025" target="_blank"&gt;Features removed or no longer developed starting with Windows Server 2025&lt;/A&gt;.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Additional resources&lt;/H2&gt;
&lt;P&gt;Looking for the latest news and previews for Windows, Copilot, Copilot+ PCs, the Windows and Windows Server Insider Programs, and more? Check out these resources:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/windows/business/roadmap" target="_blank"&gt;Windows Roadmap&lt;/A&gt;for new Windows features – filter by platform, version, status, and channel or search by feature name&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/copilot/microsoft-365/release-notes?tabs=all" target="_blank"&gt;Microsoft 365 Copilot release notes&lt;/A&gt;for latest features and improvements&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://blogs.windows.com/windows-insider/" target="_blank"&gt;Windows Insider Blog&lt;/A&gt;for what's available in the Beta and Experimental channels&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/windows-server/discussions/windowsserverinsiders" target="_blank"&gt;Windows Server Insider&lt;/A&gt;for feature preview opportunities&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://support.microsoft.com/topic/understanding-update-history-for-windows-insider-preview-features-fixes-and-changes-bb9dd4b1-9d2b-4753-8b23-ce90e62f6845" target="_blank"&gt;Understanding update history for Windows Insider preview features, fixes, and changes&lt;/A&gt;to learn about the types of updates for Windows Insiders&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Join the conversation&lt;/H2&gt;
&lt;P&gt;We are always looking to improve this monthly summary. Drop us a note in the Comments and let us know what we can do to make this more useful for you!&lt;/P&gt;
&lt;HR /&gt;
&lt;P style="font-size: 14px;"&gt;Continue the conversation. Find best practices. Bookmark the &lt;A href="http://aka.ms/community/Windows" target="_blank"&gt;Windows Tech Community&lt;/A&gt;. Looking for support? Visit &lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank"&gt;Windows on Microsoft Q&amp;amp;A&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2026 22:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-news-you-can-use-june-2026/ba-p/4532288</guid>
      <dc:creator>Chris_Morrissey</dc:creator>
      <dc:date>2026-07-01T22:00:00Z</dc:date>
    </item>
    <item>
      <title>Best practices for deploying Secure Boot certificate updates</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/best-practices-for-deploying-secure-boot-certificate-updates/ba-p/4529884</link>
      <description>&lt;P style="margin-top: 16px;"&gt;Deploying Secure Boot certificate updates across the Windows ecosystem has required coordination across operating systems, device manufacturers, and firmware vendors. The steady and coordinated rollout is strengthening the platform root of trust worldwide.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Many individuals and organizations have already successfully updated certificates for client devices, servers, and virtual machines, with others close behind. Proven deployment and validation tools, automatic certificate installation via Windows updates, and firmware support from our OEM partners are helping us all move forward with confidence. However close you are, finishing Secure Boot certificate deployment remains important. If you're still on the path to finishing your Secure Boot certificate deployment, stay the course.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;What we've seen work in practice&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Every individual device and organization's environment is different.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;In the commercial realm, across customer conversations, Ask Microsoft Anything (AMAs) events, and hands-on deployments, a few consistent patterns have emerged:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Early testing builds confidence. Many organizations start with pilots, validate results, and expand rollouts as confidence grows for both Windows and IT teams.&lt;/LI&gt;
&lt;LI&gt;Layered deployment approaches work best. Teams have successfully deployed OEM firmware updates with Windows security updates, using a mix of automation and staged rollout.&lt;/LI&gt;
&lt;LI&gt;Multiple tools can lead to success. From Microsoft Intune to Group Policy, Azure automation, and PowerShell, there isn't a single "right" tool, only the right fit for your environment.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;From talking with many of you, we learned that the diversity of tools and deployment approaches is a key reason the transition has succeeded at scale. Organizations are using a flexible resource set that meets their needs where they are.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;For home users and organizations that allow Microsoft to manage Windows updates, the experience has been equally straightforward. A few takeaways stand out:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Keeping devices up to date delivers the best experience. Individuals running supported versions of Windows and receiving regular Windows updates have generally received the newer certificates automatically. Don't pause Windows updates; keep them coming!&lt;/LI&gt;
&lt;LI&gt;Built-in protections simplify the update. Secure Boot is enabled by default on most modern PCs, helping these devices receive the newer certificates without manual configuration. Simply keep Secure Boot enabled or &lt;A href="https://support.microsoft.com/windows/windows-11-and-secure-boot-a8ff1202-c0d9-42f5-940f-843abef64fad" target="_blank" rel="noopener"&gt;re-enable it&lt;/A&gt; if needed.&lt;/LI&gt;
&lt;LI&gt;Built-in tools help you be ready. The Windows Security app can help you track progress. It can show whether the new certificates have reached your device and whether Secure Boot remains enabled. If anything is preventing devices from receiving and applying the certificates, you can follow &lt;A href="https://support.microsoft.com/topic/secure-boot-certificate-update-status-in-the-windows-security-app-5ce39986-7dd2-4852-8c21-ef30dd04f046" target="_blank" rel="noopener"&gt;embedded instructions to make progress&lt;/A&gt;. Note: In enterprise environments, the Windows Security app is disabled by default.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;Overall, for most supported Windows Home and Pro PCs and business devices managed by Microsoft, staying protected has been as simple as keeping Windows up to date and Secure Boot enabled.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;&lt;STRONG&gt;NOTE:&lt;/STRONG&gt; While most Secure Boot-enabled PCs receive the newer certificates through the monthly Windows update process, a small number might require a firmware update from the device manufacturer. The Windows Security app can help identify whether your device is waiting for a firmware update. In some cases, the firmware updates needed to support these changes might not be available for older device models, depending on the manufacturer's support lifecycle. Reach out to your device manufacturer if you encounter this case.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Our experience at Microsoft&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Microsoft's internal deployment followed many of the same principles described throughout this post. We began with limited deployments, used validation and deployment signals to build confidence, and expanded over time. This phased approach helped us identify issues early, validate readiness, and scale deployment in a measured way.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Along the way, we encountered many of the same edge cases and scenarios that many of you are navigating. Those experiences shaped the tools and guidance we've continued to share externally, including:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;New Secure Boot status messages in the Windows Security app that help users understand certificate readiness and identify issues that might require attention.&lt;/LI&gt;
&lt;LI&gt;Secure Boot certificate update playbooks for both Windows Client and Windows Server, along with tailored guidance for Windows 365 and Azure Virtual Desktop.&lt;/LI&gt;
&lt;LI&gt;Multiple &lt;A href="https://aka.ms/AMA/SecureBoot" target="_blank" rel="noopener"&gt;Ask Microsoft Anything sessions&lt;/A&gt;, now available on demand.&lt;/LI&gt;
&lt;LI&gt;Expanded tools for IT-managed environments, including event logs, PowerShell scripts, Microsoft Intune remediations, Microsoft Defender insights, and Windows Autopatch reporting.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;Microsoft has been learning alongside you and turning those lessons into resources that you can use.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Keep going; you're on the right path&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;If you're an IT administrator still deploying Secure Boot certificate updates, you're not alone. Organizations and individuals are progressing at different speeds, based on their environments and requirements. This flexibility is intentional.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;What we've seen consistently is that success comes from staying the course:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Keep your devices up to date with the latest Windows updates.&lt;/LI&gt;
&lt;LI&gt;Check that the latest firmware version is installed. You can visit your OEM's support page or use their official support channels.&lt;/LI&gt;
&lt;LI&gt;Continue with your phased rollout. Gradual deployment of certificates, boot managers, and updated OEM firmware, along with validation, remains the most reliable approach.&lt;/LI&gt;
&lt;LI&gt;Use the tools available to you. Whether built into Windows, such as the Windows Security app, or designed for IT-managed environments, these tools help you monitor progress and make informed decisions.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P style="margin-top: 16px;"&gt;Focus on progress over perfection. Each step forward strengthens your environment's platform root of trust.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Devices with older certificates will continue to function and receive updates, giving you time to complete deployment. Completing this transition helps ensure that your devices stay current with evolving Secure Boot protections.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Resources to support your next steps&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;We're nearly finished with rolling out automatic certificate updates to individual PCs and business devices. If you are still in the process of rolling out updates in your organization, these resources can help:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://support.microsoft.com/topic/windows-secure-boot-certificate-expiration-and-ca-updates-7ff40d33-95dc-4c3c-8725-a9b95457578e" target="_blank" rel="noopener"&gt;Windows Secure Boot certificate expiration and CA updates&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/secure-boot-playbook-for-certificates-expiring-in-2026/4469235" target="_blank" rel="noopener"&gt;Secure Boot playbook for certificates expiring in 2026&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/SecureBootForServer" target="_blank" rel="noopener"&gt;Secure Boot playbook for Windows Server&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://support.microsoft.com/topic/secure-boot-certificate-updates-for-windows-365-71839dd8-2832-44ed-9c60-57c04f99a645" target="_blank" rel="noopener"&gt;Secure Boot Certificate Updates for Windows 365&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://support.microsoft.com/topic/secure-boot-certificate-updates-for-azure-virtual-desktop-06a8a1bc-2510-4ead-9bea-3698e1d6b1db" target="_blank" rel="noopener"&gt;Secure Boot Certificate Updates for Azure Virtual Desktop&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://support.microsoft.com/topic/secure-boot-update-from-2011-to-2023-certificates-trusted-launch-vms-tvm-and-confidential-vms-cvm-845ec199-03fa-4629-bdc3-822ae0bbe6ca" target="_blank" rel="noopener"&gt;Secure Boot update: Trusted Launch VMs (TVM) and Confidential VMs (CVM)&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;&lt;BR /&gt;In the coming weeks, there are also still opportunities to ask questions. Save the date for these upcoming events:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;July 1 – &lt;A href="https://aka.ms/AMA/SecureBootForServer" target="_blank" rel="noopener"&gt;Windows Server Secure Boot AMA&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;July 8 – &lt;A href="https://aka.ms/OfficeHours/SecureBootVirtualized" target="_blank" rel="noopener"&gt;Secure Boot Office Hours for virtualized environments&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;July 15 – &lt;A href="https://aka.ms/OfficeHours/SecureBootOEM" target="_blank" rel="noopener"&gt;OEM Secure Boot Office Hours&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;Device owners using Windows Personal and Family accounts can use &lt;A href="https://support.microsoft.com/en-us/home/contact?SourceApp=smc2&amp;amp;ContactUsExperienceEntryPointAssetId=Bing" target="_blank" rel="noopener"&gt;online support channels&lt;/A&gt; and &lt;A href="https://support.microsoft.com/en-us/topic/customer-service-phone-numbers-c0389ade-5640-e588-8b0e-28de8afeb3f2" target="_blank" rel="noopener"&gt;phone numbers&lt;/A&gt; for additional help.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;This has been a long and meaningful journey. Together, we have strengthened the platform root of trust that modern security depends on. Wherever you are in your certificates update process, you are contributing to that shared progress.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2026 21:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/best-practices-for-deploying-secure-boot-certificate-updates/ba-p/4529884</guid>
      <dc:creator>Nuno_Costa</dc:creator>
      <dc:date>2026-06-23T21:00:00Z</dc:date>
    </item>
    <item>
      <title>Point-in-time restore for Windows 11 is now generally available</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/point-in-time-restore-for-windows-11-is-now-generally-available/ba-p/4508101</link>
      <description>&lt;P&gt;When a Windows PC experiences an unexpected issue, every minute of downtime matters. Devices are constantly evolving through updates, apps, policies, drivers, and user activity, which can make recovery complex. For IT teams, getting users back to work often means time-consuming troubleshooting, or full rebuilds that take hours.&lt;/P&gt;
&lt;P&gt;Today, we’re excited to announce the general availability of &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows/configuration/quick-machine-recovery/point-in-time-restore" target="_blank" rel="noopener"&gt;point‑in‑time restore for Windows 11&lt;/A&gt; new built-in recovery capability designed to recover in minutes instead of hours, with confidence, by safely rolling a device back to a previous state. Available in Windows Enterprise, Pro and Home SKUs, point-in-time restore provides admins and employees a quick, built‑in ability to go back in time to a moment before the issue occurred.&lt;/P&gt;
&lt;P&gt;This release marks an important step forward in Windows recovery and resilience and reflects what we’ve heard consistently from Windows users and IT admins: &lt;EM&gt;recovery should be reliable, simple, and easy to use when it matters most.&lt;/EM&gt;&lt;/P&gt;
&lt;img&gt;Point-in-time restore shown in the Troubleshoot menu for Windows Recovery Environment (Windows RE)&lt;/img&gt;
&lt;P&gt;&lt;STRONG&gt;What is point‑in‑time restore for Windows 11 PCs?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Point‑in‑time restore automatically captures comprehensive restore points on a predictable cadence and stores them locally on the device.&lt;/P&gt;
&lt;P&gt;With point‑in‑time restore, a device can be restored to the exact system state captured earlier, including:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Windows OS&lt;/LI&gt;
&lt;LI&gt;Installed applications&lt;/LI&gt;
&lt;LI&gt;System and app configurations&lt;/LI&gt;
&lt;LI&gt;Settings&lt;/LI&gt;
&lt;LI&gt;Local user files&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Key characteristics:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Automatic and predictable:&lt;/STRONG&gt; Restore points are captured on a recurring schedule (default: every 24 hours), so recent recovery points are already available if an issue occurs.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Fast, full‑system recovery:&lt;/STRONG&gt; Restore the entire system to a previous state in minutes*, minimizing user and business impact.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Designed for real‑world disruptions:&lt;/STRONG&gt; Useful for both one‑off device issues and wider incidents affecting many machines, such as a problematic updates, driver regressions, app corruption, configuration errors or other user or admin-initiated changes that result in system instability.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Built into Windows 11:&lt;/STRONG&gt; Configuration is available within system settings, and restore operations are initiated from Windows RE, providing a trusted recovery path even when the Windows PC won’t boot.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;EM&gt;*Note: Restore time is dependent on several factors, such as changes that have occurred on the system since restore point capture and system performance.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Point‑in‑time restore is part of &lt;A class="lia-external-url" href="https://aka.ms/WindowsResiliency" target="_blank" rel="noopener"&gt;Windows resiliency&lt;/A&gt;, focused on helping organizations prevent, manage, and recover from PC incidents more effectively. Check out the &lt;A class="lia-external-url" href="https://aka.ms/PITRDemoGA" target="_blank" rel="noopener"&gt;click-through demo&lt;/A&gt; to see the configuration and restore experience. &lt;/P&gt;
&lt;H5&gt;How is this different from System Restore?&lt;/H5&gt;
&lt;P&gt;You may be wondering how point‑in‑time restore compares to &lt;A class="lia-external-url" href="https://support.microsoft.com/en-us/windows/system-restore-a5ae3ed9-07c4-fd56-45ee-096777ecd14e" target="_blank" rel="noopener"&gt;System Restore&lt;/A&gt;. While both features leverage &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows-server/storage/file-server/volume-shadow-copy-service" target="_blank" rel="noopener"&gt;Volume Shadow Copy Service (VSS)&lt;/A&gt; under the hood, point‑in‑time restore is more comprehensive and is built for modern Windows PCs management and recovery.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; height: 416.207px; border-width: 1px;"&gt;&lt;colgroup&gt;&lt;col style="width: 17.7207%" /&gt;&lt;col style="width: 41.1043%" /&gt;&lt;col style="width: 41.2071%" /&gt;&lt;/colgroup&gt;&lt;tbody&gt;&lt;tr style="height: 42.7344px;"&gt;&lt;td style="height: 42.7344px;"&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-center" style="height: 42.7344px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Point-in-time restore&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-center" style="height: 42.7344px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;System Restore&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 73.8086px;"&gt;&lt;td style="height: 73.8086px;"&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Restore points&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 73.8086px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Automatic, configurable cadence; user files are included in restore point&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 73.8086px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Event-triggered or manual only; u&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ser files are excluded from restore point&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 77.2852px;"&gt;&lt;td style="height: 77.2852px;"&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Reliability&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 77.2852px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Strict retention and cleanup policies&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 77.2852px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;No retention limits&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 72.7305px;"&gt;&lt;td style="height: 72.7305px;"&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;User experience&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 72.7305px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Integrated in system settings&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 72.7305px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Limited to control panel&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 76.2891px;"&gt;&lt;td style="height: 76.2891px;"&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Storage impact&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 76.2891px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Minimizes storage impact by integrating with reserved storage*&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 76.2891px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Higher impact to storage space&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 73.3594px;"&gt;&lt;td style="height: 73.3594px;"&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Management&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 73.3594px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Will support robust remote management capabilities&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 73.3594px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Limited remote management capabilities&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;EM&gt;*Note: Reserved storage is a Windows feature that sets aside a portion of disk space for successful update installation. It helps ensure that updates, temporary files, and system processes can run reliably, without requiring users to free up space.&lt;/EM&gt;&lt;/P&gt;
&lt;H5&gt;How does this feature in Windows 11 compare to point-in-time restore for Windows 365?&lt;/H5&gt;
&lt;P&gt;Some of you are already familiar with &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows-365/enterprise/restore-overview" target="_blank" rel="noopener"&gt;point‑in‑time restore for Windows 365 Enterprise&lt;/A&gt;, which protects Cloud PCs. While these features share the same goals of fast recovery and minimal downtime, they are optimized for different environments.&lt;/P&gt;
&lt;P&gt;Each solution is purpose‑built for its environment, and organizations may use both depending on device types.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; height: 422.574px; border-width: 1px;"&gt;&lt;colgroup&gt;&lt;col style="width: 23.8844%" /&gt;&lt;col style="width: 39.5559%" /&gt;&lt;col style="width: 36.5918%" /&gt;&lt;/colgroup&gt;&lt;tbody&gt;&lt;tr style="height: 39.2383px;"&gt;&lt;td class="lia-align-center" style="height: 39.2383px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-center" style="height: 39.2383px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Windows Client&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-center" style="height: 39.2383px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Windows 365&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 61.2305px;"&gt;&lt;td style="height: 61.2305px;"&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Feature enablement&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 61.2305px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Can be enabled or disabled&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 61.2305px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Always on&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 65.1953px;"&gt;&lt;td style="height: 65.1953px;"&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Restore point retention&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 65.1953px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Up to 72 hours&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 65.1953px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Up to 1 month&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 58.2227px;"&gt;&lt;td style="height: 58.2227px;"&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Restore point types&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 58.2227px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Short-term only&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 58.2227px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Short-term, long term, and manual&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 67.2266px;"&gt;&lt;td style="height: 67.2266px;"&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Restore point sharing&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 67.2266px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;No sharing, restore points remain local&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 67.2266px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Support sharing across Windows 365 and Azure Cloud&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 73.2227px;"&gt;&lt;td style="height: 73.2227px;"&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Restore speed&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 73.2227px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Likely faster due to local storage of restore point&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 73.2227px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Speed is affected by network latency and bulk vs. single restores&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 58.2383px;"&gt;&lt;td style="height: 58.2383px;"&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Storage constraints&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 58.2383px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Bound by physical disk limits&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 58.2383px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Scalable, cloud storage&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H5&gt;What’s included in general availability (GA)?&lt;/H5&gt;
&lt;P&gt;Since its initial public preview, point-in-time restore has been enabled on over 2M devices and the feature has continued to mature based on feedback and real‑world testing. GA signals that point‑in‑time restore is ready for production use and to become part of your Windows recovery toolkit.&lt;/P&gt;
&lt;P&gt;Highlights in the GA release include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Availability for all users on consumer and commercial editions of Windows 11&lt;/LI&gt;
&lt;LI&gt;CSPs for remote configuration&lt;/LI&gt;
&lt;LI&gt;Integration with system reserved storage to minimize local storage impact&lt;/LI&gt;
&lt;LI&gt;Visibility into restore points on the system and their disk usage&lt;/LI&gt;
&lt;LI&gt;Consistency in settings across feature updates and integration with OneSettings&lt;/LI&gt;
&lt;LI&gt;Updated &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows/configuration/quick-machine-recovery/point-in-time-restore" target="_blank" rel="noopener"&gt;documentation&lt;/A&gt; and guidance&lt;/LI&gt;
&lt;/UL&gt;
&lt;H5&gt;Configuring point-in-time restore&lt;/H5&gt;
&lt;P&gt;Configuration defaults for general availability are outlined below:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; height: 317.149px; border-width: 1px;"&gt;&lt;colgroup&gt;&lt;col style="width: 25.0401%" /&gt;&lt;col style="width: 25.0401%" /&gt;&lt;col style="width: 25.0401%" /&gt;&lt;col style="width: 25.0401%" /&gt;&lt;/colgroup&gt;&lt;tbody&gt;&lt;tr style="height: 67.2266px;"&gt;&lt;td class="lia-align-center" style="height: 67.2266px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Configuration&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-center" style="height: 67.2266px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Default&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-center" style="height: 67.2266px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Options&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-center" style="height: 67.2266px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Editions eligible to configure&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 56.2305px;"&gt;&lt;td style="height: 56.2305px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Feature On/Off&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 56.2305px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;See below&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 56.2305px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;On, Off&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 56.2305px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Home, Pro, Enterprise&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 67.2266px;"&gt;&lt;td style="height: 67.2266px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Restore point frequency&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 67.2266px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Every 24 hours&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 67.2266px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;4, 6, 12, 16, 24 hours&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 67.2266px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Enterprise only&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 59.2383px;"&gt;&lt;td style="height: 59.2383px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Restore point retention&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 59.2383px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;72 hours&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 59.2383px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;4, 6, 12, 16, 24, 72 hours&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:257}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 59.2383px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Enterprise only&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 67.2266px;"&gt;&lt;td style="height: 67.2266px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Maximum usage limit&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 67.2266px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;2% of disk&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 67.2266px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Percent of disk (min 2 GB, max 50 GB equivalent)&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 67.2266px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Home, Pro, Enterprise&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;Point-in-time restore is on by default on some systems not under enterprise management:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Windows Home edition devices&lt;/LI&gt;
&lt;LI&gt;Windows Pro edition devices that are not domain joined and not enrolled in enterprise endpoint management&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Point-in-time restore is off by default, until Windows 11, version 26H2 on some enterprise-managed systems:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Windows Enterprise and Education edition devices&lt;/LI&gt;
&lt;LI&gt;Windows Pro edition devices that are domain joined or managed by an organization&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;EM&gt;*Note: Only devices with an OS volume size of 200GB or greater, will have the feature on by default. The feature will be off by default on devices with OS volume size below 200GB, but admins can turn the feature on if desired.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Point-in-time restore can be configured in system settings: &lt;STRONG&gt;System &amp;gt; Recovery &amp;gt; Point-in-time restore.&lt;/STRONG&gt;&amp;nbsp;Only local admins can view or edit point-in-time restore settings on their system.&lt;/P&gt;
&lt;img&gt;&lt;SPAN data-contrast="auto"&gt;Point-in-time restore settings page in System &amp;gt; Recovery&lt;/SPAN&gt;&lt;/img&gt;
&lt;H5&gt;Important considerations before you restore&lt;/H5&gt;
&lt;P&gt;Point‑in‑time restore is a powerful recovery tool, and it’s important to understand its behavior and impact:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Data loss:&lt;/STRONG&gt; Any changes made after the selected restore point including files, apps, and settings will be lost. Cloud data is not affected but may require resync. Microsoft recommends storing data in the cloud.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Local storage: &lt;/STRONG&gt;Restore points are stored locally and require sufficient disk space. Older restore points are automatically removed when limits are reached.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;BitLocker protection:&lt;/STRONG&gt; A BitLocker recovery key is required when restoring encrypted devices.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For detailed requirements, limitations, and best practices, we strongly recommend reviewing the &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows/configuration/quick-machine-recovery/point-in-time-restore" target="_blank" rel="noopener"&gt;documentation&lt;/A&gt;.&lt;/P&gt;
&lt;H5&gt;Restoring a device&lt;/H5&gt;
&lt;P&gt;Currently, a restore can only be triggered&lt;STRONG&gt; locally&lt;/STRONG&gt; by the user when the device is in Windows RE. The steps to perform a point-in-time restore are below:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;In Windows RE select&lt;STRONG&gt; Troubleshoot &amp;gt; Point-in-time restore&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Enter &lt;A class="lia-external-url" href="https://support.microsoft.com/en-us/windows/find-your-bitlocker-recovery-key-6b71ad27-0b89-ea08-f143-056f5ab347d6" target="_blank" rel="noopener"&gt;Bitlocker recovery key&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Select a restore point to restore PC to the exact state it was at the time of the restore point&lt;/LI&gt;
&lt;LI&gt;Acknowledge the risks and limitations associated with this feature by selecting &lt;STRONG&gt;Continue&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Review the restore point selection, OS version and warning of data loss and select &lt;STRONG&gt;Restore&lt;/STRONG&gt; to start the restore process&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;EM&gt;*Note: Microsoft has announced plans to enable remote initiation in the future, through Intune recovery, giving organizations a more scalable way to restore devices when that capability becomes available.&lt;/EM&gt;&lt;/P&gt;
&lt;H5&gt;Start using point‑in‑time restore today and provide feedback&lt;/H5&gt;
&lt;P&gt;Point‑in‑time restore is now generally available on Windows 11 Client PCs on versions 24H2 and later.&lt;/P&gt;
&lt;P&gt;Learn more and get started: &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows/configuration/quick-machine-recovery/point-in-time-restore" target="_blank" rel="noopener"&gt;point-in-time restore for Windows 11 Microsoft Learn&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;We strongly encourage you to share feedback through &lt;STRONG&gt;Feedback Hub&lt;/STRONG&gt;, within &lt;STRONG&gt;Recovery and Uninstall &amp;gt; Point-in-time restore&lt;/STRONG&gt; as we continue investing in Windows recovery and resiliency.&lt;/P&gt;
&lt;H5&gt;Looking ahead&lt;/H5&gt;
&lt;P&gt;Point‑in‑time restore is an important foundation for the future of Windows recovery. As part of &lt;A class="lia-external-url" href="https://www.microsoft.com/en-us/windows/business/windows-resiliency-initiative" target="_blank" rel="noopener"&gt;Windows resiliency&lt;/A&gt;, we’ll continue to enhance point-in-time restore and expand recovery options, improving manageability, and reducing the time it takes to get users back to productivity across a broad range of issues. For the latest updates on Windows, please refer to the &lt;A class="lia-external-url" href="https://aka.ms/windowsitproblog" target="_blank" rel="noopener"&gt;Windows IT Pro Blog&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Continue the conversation. Find best practices. Bookmark the &lt;/SPAN&gt;&lt;A href="https://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Tech Community&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, then follow us&amp;nbsp;on &amp;nbsp;&lt;A href="https://www.linkedin.com/company/windows-it-pro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;or&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://twitter.com/mswindowsitpro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSWindowsITPro&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; for updates. Looking for support? Visit &lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows on Microsoft Q&amp;amp;A&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/point-in-time-restore-for-windows-11-is-now-generally-available/ba-p/4508101</guid>
      <dc:creator>Lia_Vargas</dc:creator>
      <dc:date>2026-06-23T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Get ready for Windows 11, version 26H2</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/get-ready-for-windows-11-version-26h2/ba-p/4529367</link>
      <description>&lt;P&gt;The next annual update for Windows 11 is coming soon and is already available to Windows Insiders! Windows 11, version 26H2 continues our focus on delivering a predictable, low-disruption update experience for organizations and IT professionals.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;For devices already running recent versions of Windows 11, this release should be easy to adopt. It builds on the same platform and servicing approach introduced in prior releases, while continuing to improve how updates are delivered, tested, and deployed.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;In this post, we'll walk through how to prepare for Windows 11, version 26H2.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;A familiar update experience, refined&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Windows 11, version 26H2 uses the same shared servicing model as recent releases available annually in the second half of the calendar year. Supported devices get this feature update as a small enablement package instead of a full OS replacement.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;If your organization is already on Windows 11, version 24H2 or 25H2, the update to 26H2 is similar to a regular monthly update in most environments:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;A small, quick installation&lt;/LI&gt;
&lt;LI&gt;Minimized disruption to users&lt;/LI&gt;
&lt;LI&gt;No need for full reimaging or complex deployment motions&lt;/LI&gt;
&lt;/UL&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;: Devices running Windows 11, version 26H1 won't be able to update to version 26H2. Instead, they'll have a path to update to a future Windows release. This is because Windows 11, version 26H1 is based on a different Windows core than Windows 11, versions 24H2, 25H2, and 26H2. Here's &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/what-to-know-about-windows-11-version-26h1/4491941" target="_blank" rel="noopener"&gt;What to know about Windows 11, version 26H1&lt;/A&gt;.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P style="margin-top: 16px;"&gt;This is possible because multiple versions of Windows 11 share a common servicing branch, including:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The same source code base&lt;/LI&gt;
&lt;LI&gt;The same security and quality updates&lt;/LI&gt;
&lt;LI&gt;The same compatibility validation&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;The difference between versions is simply which features are enabled.&lt;/P&gt;
&lt;img&gt;&lt;STRONG&gt;Shared servicing branch progression&lt;/STRONG&gt;&lt;/img&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Why this matters for IT organizations&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;The shared servicing model isn't just a technical detail. It directly impacts how you manage updates across your environment. Compared to full OS upgrades of the past, Windows 11, version 26H2 comes with reduced deployment complexity, improved compatibility confidence, and faster time to value.&lt;/P&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;Reduced deployment complexity&lt;/H3&gt;
&lt;P style="margin-top: 16px;"&gt;Because features are delivered continuously and enabled later, there's no large "upgrade event." This makes planning easier and reduces operational overhead.&lt;/P&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;Improved compatibility confidence&lt;/H3&gt;
&lt;P style="margin-top: 16px;"&gt;Devices moving between versions on the same servicing branch typically benefit from:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Existing application compatibility validation&lt;/LI&gt;
&lt;LI&gt;Lower risk of regressions&lt;/LI&gt;
&lt;LI&gt;Fewer surprises during rollout&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;Faster time to value&lt;/H3&gt;
&lt;P style="margin-top: 16px;"&gt;With smaller updates and faster installations, organizations can move more quickly to the most current release. New features reach you without lengthy deployment cycles.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Support lifecycle considerations&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;As with previous annual feature updates, moving to Windows 11, version 26H2 resets the Windows support lifecycle for your devices.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;This provides:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;24 months of support for Home, Pro, Pro EDU, and Pro for Workstations editions&lt;/LI&gt;
&lt;LI&gt;36 months of support for Enterprise, Education, IoT Enterprise, and Enterprise Multi-session editions&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;What does it mean for your servicing strategy? The annual update becomes a key milestone for maintaining a supported and secure environment.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;How to prepare for Windows 11, version 26H2&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Already managing Windows 11 in your organization? Preparing for 26H2 should align with your existing update processes.&lt;/P&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;1. Validate today&lt;/H3&gt;
&lt;P style="margin-top: 16px;"&gt;Begin testing with devices running recent versions of Windows 11 to confirm compatibility with your apps, policies, and infrastructure.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;If you'd like to get a peak of what's coming and begin previewing version 26H2 on devices now, the update is available through the &lt;A href="https://aka.ms/WIPBlog6-19-2026" target="_blank" rel="noopener"&gt;Windows Insider Program in the Experimental channel&lt;/A&gt;. Otherwise, your organization might prefer to wait for the update to become available in Release Preview before doing more extensive testing. At that stage, the experience is closer to final shipping quality. We'll have more information to share when version 26H2 is in Release Preview.&lt;/P&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;2. Use your existing deployment tools&lt;/H3&gt;
&lt;P style="margin-top: 16px;"&gt;Windows 11, version 26H2 will be available through familiar channels, including:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Windows Autopatch&lt;/LI&gt;
&lt;LI&gt;Microsoft Intune&lt;/LI&gt;
&lt;LI&gt;Windows Server Update Services (WSUS)&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;3. Plan your rollout rings&lt;/H3&gt;
&lt;P style="margin-top: 16px;"&gt;Use your standard deployment rings to:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Pilot the update with a small group of devices.&lt;/LI&gt;
&lt;LI&gt;Expand gradually based on validation results.&lt;/LI&gt;
&lt;/OL&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;4. Stay current&lt;/H3&gt;
&lt;P style="margin-top: 16px;"&gt;Windows features are delivered continuously. Stay up to date with monthly updates to help ensure a smoother transition when the feature update becomes available.&lt;/P&gt;
&lt;img&gt;&lt;STRONG&gt;Feature delivery over time with enablement moment&lt;/STRONG&gt;&lt;/img&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Looking ahead and staying informed&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Windows 11, version 26H2 continues the move toward a more predictable and efficient servicing model. This model helps reduce disruption while helping your organization stay secure and up to date. By building on a shared platform and delivering innovation continuously, Windows enables you to focus less on large upgrade projects and more on delivering value to your users.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;We'll continue to share updates and guidance as Windows 11, version 26H2 becomes available. In the meantime, test it in the Windows Insider Program's Experimental channel and use the updated &lt;A href="https://learn.microsoft.com/training/paths/stay-current-with-windows/" target="_blank" rel="noopener"&gt;plan-prepare-deploy learning path&lt;/A&gt; to get ready.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Be sure to &lt;A href="https://techcommunity.microsoft.com/category/windows/blog/windows-itpro-blog?action=follow" target="_blank" rel="noopener"&gt;follow the Windows IT Pro Blog&lt;/A&gt; and join us on the &lt;A href="https://techcommunity.microsoft.com/t5/windows" target="_blank" rel="noopener"&gt;Windows Tech Community&lt;/A&gt; for the latest information and best practices.&lt;/P&gt;
&lt;HR /&gt;
&lt;P style="font-size: 14px;"&gt;Continue the conversation. Find best practices. Bookmark the &lt;A href="http://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;Windows Tech Community&lt;/A&gt;, then follow us &lt;A href="https://x.com/mswindowsitpro" target="_self"&gt;@MSWindowsITPro&lt;/A&gt; on X and on &lt;A href="https://www.linkedin.com/company/windows-it-pro" target="_blank" rel="noopener"&gt;LinkedIn&lt;/A&gt;. Looking for support? Visit &lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;Windows on Microsoft Q&amp;amp;A&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2026 17:05:18 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/get-ready-for-windows-11-version-26h2/ba-p/4529367</guid>
      <dc:creator>Jason_Leznek</dc:creator>
      <dc:date>2026-06-19T17:05:18Z</dc:date>
    </item>
    <item>
      <title>Introducing Windows Ready Print and Modernized Driver Selection</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/introducing-windows-ready-print-and-modernized-driver-selection/ba-p/4527563</link>
      <description>&lt;P&gt;Introducing Windows Ready Print: a simpler, more reliable path to modern printing with modern driver selection controls.&lt;/P&gt;
&lt;H2&gt;Windows Ready Print: A clearer path to modern printing on Windows&lt;/H2&gt;
&lt;P&gt;Printing on Windows is evolving.&lt;/P&gt;
&lt;P&gt;As printing environments modernize, customers and partners are asking for solutions that are reliable, secure, and easy to manage across today’s devices. To reflect this shift and make the value of our platform clearer, we are evolving the &lt;STRONG&gt;Modern Print Platform&lt;/STRONG&gt; under a new name: &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?LinkId=2362106" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Windows Ready Print&lt;/STRONG&gt;&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Windows Ready Print&lt;/STRONG&gt; highlights what matters most: a streamlined, dependable printing experience built for modern Windows environments. It represents our commitment to simplifying printing, aligning modern standards, and delivering consistent, forward-looking experiences for users, IT admins, and partners.&lt;/P&gt;
&lt;H2&gt;Driving the transition to Windows Ready Print with driver selection controls&lt;/H2&gt;
&lt;P&gt;At the core of Windows Ready Print is a &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?LinkId=2364024" target="_blank" rel="noopener"&gt;transition away from legacy, third party drive-based workflows &lt;/A&gt;toward modern, standards-based printing with &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?LinkId=2365912" target="_blank" rel="noopener"&gt;IPP (Internet Printing Protocol)&lt;/A&gt; using the Windows inbox IPP printer driver.&lt;/P&gt;
&lt;P&gt;Starting in&lt;STRONG&gt; July 2026&lt;/STRONG&gt;, new printer installations will &lt;STRONG&gt;default to Windows Ready Print where supported&lt;/STRONG&gt;, enabling a simpler and more reliable setup experience. This change reduces the need for traditional driver management and lays the foundation for a more scalable and predictable print experience.&lt;/P&gt;
&lt;P&gt;However, we recognize that not all environments can move to Windows Ready Print immediately. To ensure a smooth and flexible transition, we are introducing the ability for users to configure Windows to install their printers using Windows Ready Print (if supported) or the OEM printer driver during installation.&lt;/P&gt;
&lt;P&gt;You can find this setting under &lt;STRONG&gt;Settings &amp;gt; Bluetooth &amp;amp; Devices &amp;gt; Printers &amp;amp; Scanners &amp;gt; Default install printer using Windows Ready Print.&lt;/STRONG&gt;&lt;/P&gt;
&lt;img&gt;&lt;SPAN data-contrast="auto"&gt;Driver selection configuration in Settings&lt;/SPAN&gt;&lt;/img&gt;
&lt;P&gt;This feature enables users and IT admins to control how Windows selects drivers when installing printers:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;When “Default install printers using Windows Ready Print” is enabled, &lt;STRONG&gt;Windows Ready Print installation is preferred&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;When “Default install printers using Windows Ready Print” is disabled, &lt;STRONG&gt;default driver selection is used&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The configuration applies to &lt;STRONG&gt;new printer installations only&lt;/STRONG&gt;, without affecting existing devices.&lt;/P&gt;
&lt;P&gt;To enable/disable this feature via group policy, go to:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Launch &lt;STRONG&gt;Group Policy Editor&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Navigate to &lt;STRONG&gt;Local Computer Policy -&amp;gt; Administrative Templates -&amp;gt; Printers&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Find and select &lt;STRONG&gt;'Configure Windows Ready Print driver ranking'&lt;/STRONG&gt; -&amp;gt; double click to open it&lt;/LI&gt;
&lt;LI&gt;Select&lt;STRONG&gt; 'Enabled' &lt;/STRONG&gt;(if you wish to enable Windows Ready Print driver selection) or&lt;STRONG&gt; 'Disabled'&lt;/STRONG&gt; (if you wish to explicitly disable Windows Ready Print driver selection).&lt;/LI&gt;
&lt;LI&gt;Select &lt;STRONG&gt;Apply&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Select &lt;STRONG&gt;OK&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;H2&gt;How driver selection configuration works with Windows protected print mode&lt;/H2&gt;
&lt;P&gt;When you enable "&lt;STRONG&gt;Default install printers using Windows Ready Print"&lt;/STRONG&gt;, new printer installations will default to Windows inbox IPP printer driver when supported.&lt;/P&gt;
&lt;P&gt;When you enable &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?LinkId=2281835" target="_blank" rel="noopener"&gt;Windows protected print mode&lt;/A&gt;, printers are exclusively installed with Windows Ready Print. Devices that do not support Windows Ready Print cannot be installed.&lt;/P&gt;
&lt;P&gt;Note: When you’ve enabled Windows protected print mode, you cannot disable “Default install printers using Windows Ready Print".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Continue the conversation. Find best practices. Bookmark the &lt;/SPAN&gt;&lt;A href="https://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Tech Community&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, then follow us&amp;nbsp;on &amp;nbsp;&lt;A href="https://www.linkedin.com/company/windows-it-pro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;or&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://twitter.com/mswindowsitpro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSWindowsITPro&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; for updates. Looking for support? Visit &lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows on Microsoft Q&amp;amp;A&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/introducing-windows-ready-print-and-modernized-driver-selection/ba-p/4527563</guid>
      <dc:creator>elliesekine</dc:creator>
      <dc:date>2026-06-12T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Teams Remote App/ Cloud App optimization for Windows 365 and Azure Virtual Desktop now GA</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/teams-remote-app-cloud-app-optimization-for-windows-365-and/ba-p/4515930</link>
      <description>&lt;P&gt;Today, we are announcing the general availability of Microsoft Teams for Remote App scenarios, expanding support for optimized Microsoft Teams experiences when connecting to Azure Virtual Desktop. Additionally, Cloud Apps for Windows 365 will also be supported. This update introduces a new media engine that replaces the legacy WebRTC-based optimization.&lt;/P&gt;
&lt;H4&gt;Optimized Teams experience for Remote App&lt;/H4&gt;
&lt;P&gt;The new optimization improves audio and video performance, reliability, and security, and simplifies ongoing support by enabling media engine updates without frequent upgrades to the infrastructure or client.&lt;/P&gt;
&lt;P&gt;This feature will be available to anyone using Microsoft Teams as a Remote App on Azure Virtual Desktop or Cloud Apps on Windows 365 from Windows endpoints.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Teams users running in Remote App will automatically transition to the new optimization: &lt;/LI&gt;
&lt;/UL&gt;
&lt;img /&gt;
&lt;UL&gt;
&lt;LI&gt;Audio and video performance and reliability are improved compared to the legacy WebRTC optimization.&lt;/LI&gt;
&lt;LI&gt;Media engine updates no longer require frequent upgrades to the VDI infrastructure or client.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Note: Give and Take control is not supported at this time.&lt;/P&gt;
&lt;H4&gt;Try the optimized Teams experience for Remote App and Cloud Apps today&lt;/H4&gt;
&lt;P&gt;If you are using Windows App on Windows, you can try it today by meeting the following requirements:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;On the user device, use Windows App for Windows version 2.0.964.0 or later&lt;/LI&gt;
&lt;LI&gt;On the remote VM, install Microsoft Teams version 26043.2016.4478.2773 or later&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Learn more: &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/microsoftteams/vdi-2#remoteapp" target="_blank" rel="noopener"&gt;New VDI solution for Teams | Microsoft Teams | Microsoft Learn&lt;/A&gt;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Continue the conversation. Find best practices. Bookmark the &lt;/SPAN&gt;&lt;A href="https://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Tech Community&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, then follow us on &lt;/SPAN&gt;&amp;nbsp;&lt;A href="https://www.linkedin.com/company/windows-it-pro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;or&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://twitter.com/mswindowsitpro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSWindowsITPro&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; for updates. Looking for support? Visit &lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows on Microsoft Q&amp;amp;A&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2026 18:45:09 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/teams-remote-app-cloud-app-optimization-for-windows-365-and/ba-p/4515930</guid>
      <dc:creator>PavithraT</dc:creator>
      <dc:date>2026-06-04T18:45:09Z</dc:date>
    </item>
    <item>
      <title>Adaptive data protection with context-based redirections in Windows 365, now in public preview</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/adaptive-data-protection-with-context-based-redirections-in/ba-p/4521366</link>
      <description>&lt;P&gt;Today, we are excited to announce the public preview of &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-conditional-access-cloud-apps?tabs=powershell#authentication-context" target="_blank" rel="noopener"&gt;context-based redirections&lt;/A&gt; for Windows App. This new capability helps organizations apply more granular controls to device and resource redirection based on contextual signals such as device management state, compliance posture, user or group membership, and network conditions. The result is a more adaptive way to help users stay productive while reducing the risk of data leaving the protected Windows environment.&lt;/P&gt;
&lt;P&gt;Context-based redirections are part of our broader secure bring-your-own-device (BYOD) strategy. Instead of relying only on a one-size-fits-all redirection policy, admins can use Microsoft Entra Conditional Access authentication context with Windows 365 and Azure Virtual Desktop redirection settings to make redirection decisions that better match the trust level of the session.&lt;/P&gt;
&lt;H4&gt;Why context matters for redirection&lt;/H4&gt;
&lt;P&gt;Redirections control important data paths between the local device and the remote session. In BYOD scenarios, an unmanaged or noncompliant device may not meet the same security standard as a corporate-managed endpoint. Context-based redirections help admins align these data paths with policy intent: enable what users need when the session is trusted and restrict higher-risk redirections when the session is not.&lt;/P&gt;
&lt;P&gt;This builds on the existing Windows App and RDP security model where the more restrictive setting takes precedence. For example, if one policy allows a redirection but another security layer disables it, the redirection remains disabled. The most restrictive wins behavior, helping provide defense in depth and reducing the chance that a configuration gap becomes a data loss path.&lt;/P&gt;
&lt;H4&gt;What is in scope for public preview&lt;/H4&gt;
&lt;P&gt;In this public preview, the core scenarios are centered on:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Clipboard redirection: Control whether clipboard data can move between the local device and the remote Windows session.&lt;/LI&gt;
&lt;LI&gt;Drive and storage redirection: Control access to local fixed, removable, and network storage from the remote session.&lt;/LI&gt;
&lt;LI&gt;Printer redirection: Control whether users can print from the remote session to local printers.&lt;/LI&gt;
&lt;LI&gt;USB redirection: Control whether supported USB devices can be redirected into the remote session.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Context-based redirection will be supported across Windows, web, Android, iOS, and macOS Windows App clients and through a dedicated VM session.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; We are currently &lt;STRONG&gt;developing&lt;/STRONG&gt; the feature Resultant Set of Policy (RSOP) that will help users and IT admins determine which redirections settings were applied to this connection and which policy source produced this value.&lt;/P&gt;
&lt;H4&gt;Prerequisites&lt;/H4&gt;
&lt;P&gt;&lt;STRONG&gt;Note: &lt;/STRONG&gt;If you’re testing with a recent gallery image or already have policies in your environment that disable redirections, update those settings before testing, as the most restrictive policy always applies. For context-based redirection to function properly, configure the redirections you want to test as “Not Configured” or “Enabled.”&lt;/P&gt;
&lt;P&gt;To simplify testing and rollout, we recommend creating a dedicated device group for pilot Cloud PCs. This allows you to target only test devices with these settings and later reuse the same group when deploying your context-based redirection policy more broadly.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;For more information, please visit&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows-365/enterprise/manage-rdp-device-redirections#use-the-settings-catalog-to-manage-rdp-device-redirections" target="_blank" rel="noopener"&gt;Manage device RDP redirections for Cloud PCs. | Microsoft Learn&lt;/A&gt;.&lt;/P&gt;
&lt;H4&gt;Get started&lt;/H4&gt;
&lt;P&gt;To get started with context-based redirections, admins will first create an Entra authentication context, then create an Entra Conditional Access to issue the authentication context.&lt;/P&gt;
&lt;P&gt;Once the authentication context and Conditional Access policy are in place, admins can configure the Windows 365 Remote Connection Experience setting policy to require the specified authentication context for the targeted redirections.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;H4&gt;Validating the provisioned context-based redirection policy&lt;/H4&gt;
&lt;P&gt;To validate whether the provisioned context-based redirection policy is working as intended, test it from the user perspective by connecting to a Windows 365 Cloud PC/Azure Virtual Desktop VM that’s associated with the targeted device group:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Use any Windows App client. You can use the Windows web client by going to &lt;A class="lia-external-url" href="https://windows.cloud.microsoft" target="_blank" rel="noopener"&gt;windows.cloud.microsoft&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;Find the targeted, managed Windows 365 Cloud PC/Azure Virtual Desktop VM and click the "Connect" button.&lt;/LI&gt;
&lt;LI&gt;Once the remote session loads, verify the behavior of the 4 redirections. Please visit each redirection’s respective Microsoft Learn documentations for detailed testing instructions:
&lt;OL&gt;
&lt;LI&gt;Clipboard redirection: Verify whether copy and paste work between the local device and remote session.&lt;/LI&gt;
&lt;LI&gt;Drive redirection enabled: &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/azure/virtual-desktop/redirection-configure-drives-storage?tabs=intune&amp;amp;pivots=windows-365#test-drive-redirection" target="_blank" rel="noopener"&gt;Configure fixed, removable, and network drive redirection over the Remote Desktop Protocol | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Printer redirection: &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/azure/virtual-desktop/redirection-configure-printers?tabs=intune&amp;amp;pivots=windows-365#test-printer-redirection" target="_blank" rel="noopener"&gt;Configure printer redirection over the Remote Desktop Protocol | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;USB redirection enabled: &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/azure/virtual-desktop/redirection-configure-usb?tabs=intune&amp;amp;pivots=windows-365#test-usb-redirection" target="_blank" rel="noopener"&gt;Configure USB redirection on Windows over the Remote Desktop Protocol | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For more information, please visit the respective Microsoft Learn documents for each service:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Windows 365:&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/windows-365/enterprise/context-based-redirections" target="_blank"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Context-based redirections (Preview) | Microsoft Learn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Azure Virtual Desktop:&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/virtual-desktop/context-based-redirections-avd" target="_blank"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Context-based Redirections (Preview) - Azure Virtual Desktop | Microsoft Learn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:1080,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276,&amp;quot;469777462&amp;quot;:[360,1080],&amp;quot;469777927&amp;quot;:[0,0],&amp;quot;469777928&amp;quot;:[0,8]}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Continue the conversation. Find best practices. Bookmark the &lt;/SPAN&gt;&lt;A href="https://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Tech Community&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, then follow us&amp;nbsp;on &amp;nbsp;&lt;A href="https://www.linkedin.com/company/windows-it-pro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;or&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://twitter.com/mswindowsitpro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSWindowsITPro&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; for updates. Looking for support? Visit &lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows on Microsoft Q&amp;amp;A&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2026 20:31:33 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/adaptive-data-protection-with-context-based-redirections-in/ba-p/4521366</guid>
      <dc:creator>Derek_Su</dc:creator>
      <dc:date>2026-06-15T20:31:33Z</dc:date>
    </item>
    <item>
      <title>Reducing NTLM Dependency: IAKerb and LocalKDC in Windows Insider Preview</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/reducing-ntlm-dependency-iakerb-and-localkdc-in-windows-insider/ba-p/4524615</link>
      <description>&lt;P&gt;Today, Windows expands where Kerberos works—reducing the need for NT LAN Manager (NTLM) fallback with&lt;STRONG&gt; IAKerb&lt;/STRONG&gt; and &lt;STRONG&gt;LocalKDC&lt;/STRONG&gt;, coming to &lt;A class="lia-external-url" href="https://www.microsoft.com/en-us/windowsinsider/?msockid=1d672a5faaaf6d8d23183cf4abdb6cd9" target="_blank" rel="noopener"&gt;client&lt;/A&gt; and &lt;A class="lia-external-url" href="https://www.microsoft.com/en-us/software-download/windowsinsiderpreviewserver?msockid=1d672a5faaaf6d8d23183cf4abdb6cd9" target="_blank" rel="noopener"&gt;server&lt;/A&gt; &lt;STRONG&gt;public preview later this month&lt;/STRONG&gt; for &lt;STRONG&gt;Windows Insiders in the Canary Channel&lt;/STRONG&gt;. These capabilities extend Kerberos authentication to scenarios that previously required NTLM, helping organizations reduce their dependency on legacy protocols. For developers, this means more authentication flows can rely on modern, Kerberos-based identity (even in environments that previously required legacy protocols), reducing the need for application workarounds and helping ensure consistent behavior across managed and unmanaged environments.&lt;/P&gt;
&lt;H5&gt;With this release:&lt;/H5&gt;
&lt;UL&gt;
&lt;LI&gt;IAKerb will be enabled by default&lt;/LI&gt;
&lt;LI&gt;LocalKDC will be disabled by default&lt;/LI&gt;
&lt;LI&gt;Both features will be configurable through registry keys&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Note: For this public preview, configuration is exposed through registry settings so you can evaluate these capabilities in Insider environments. Management surfaces, such as Group Policies and MDM-based management, will be introduced as these capabilities mature.&lt;/P&gt;
&lt;H4&gt;Why this matters&lt;/H4&gt;
&lt;P&gt;For many organizations, moving away from NTLM is a security priority. But in practice, NTLM often remains in use because there are still real-world scenarios where traditional Kerberos cannot be used directly, such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Devices that do not have direct line-of-sight to a domain controller&lt;/LI&gt;
&lt;LI&gt;Authentication flows involving local accounts&lt;/LI&gt;
&lt;LI&gt;Standalone or workgroup environments&lt;/LI&gt;
&lt;LI&gt;Network topologies where Kerberos reachability is limited&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;IAKerb and LocalKDC address many of these gaps (though not all) by extending Kerberos support, reducing reliance on NTLM fallback across customer environments.&lt;/P&gt;
&lt;H4&gt;What is IAKerb?&lt;/H4&gt;
&lt;P&gt;&lt;STRONG&gt;IAKerb&lt;/STRONG&gt; (Initial and Pass-Through Authentication using Kerberos) enables Kerberos to work when the initiating device (Kerberos client) does not have direct connectivity to a domain controller. In a traditional Kerberos flow, the client must communicate directly with a domain controller to obtain the tickets needed for authentication. In some environments, that path is not available even though the client can still reach the target service. In those cases, IAKerb enables the target service to act as a proxy for the Kerberos exchange, allowing authentication to stay on a Kerberos-based path rather than falling back to NTLM.&lt;/P&gt;
&lt;P&gt;This makes IAKerb especially useful in environments with:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Network segmentation&lt;/LI&gt;
&lt;LI&gt;Restricted domain controller visibility&lt;/LI&gt;
&lt;LI&gt;Remote or cloud-connected access patterns&lt;/LI&gt;
&lt;LI&gt;Architectures where clients can reach services but not DCs directly&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;What is LocalKDC?&lt;/H4&gt;
&lt;P&gt;&lt;STRONG&gt;LocalKDC&lt;/STRONG&gt; is a local Key Distribution Center implementation in Windows that enables Kerberos-based authentication for local account scenarios. Historically, local account authentication across machines has often depended on NTLM. LocalKDC helps close that gap by allowing Windows to use Kerberos semantics for local identity scenarios that would otherwise require legacy authentication. This is especially relevant for scenarios such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Workgroup environments&lt;/LI&gt;
&lt;LI&gt;Standalone devices&lt;/LI&gt;
&lt;LI&gt;Local account access to remote resources&lt;/LI&gt;
&lt;LI&gt;Peer-to-peer or small-scale environments without domain infrastructure&lt;/LI&gt;
&lt;LI&gt;Administrative or file access scenarios where local identities are used&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;How these features fit together&lt;/H4&gt;
&lt;P&gt;IAKerb and LocalKDC address different but complementary gaps in Windows authentication, reducing reliance on NTLM across both enterprise and local identity scenarios.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;IAKerb&lt;/STRONG&gt; is meant for enterprise and corporate environments, where domain credentials are used but Kerberos authentication cannot always complete because the client lacks direct line of sight to a domain controller. By allowing authentication to remain on a Kerberos-based path in these situations, IAKerb helps reduce NTLM usage for high-value corporate credentials . This is important because reducing the use of NTLM for enterprise credentials helps strengthen defenses against credential theft and relay-based attack paths, including forms of lateral movement that have historically relied on NTLM fallback.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;LocalKDC&lt;/STRONG&gt; addresses a different class of scenarios: local and non-domain identities, including workgroup, standalone, and local account access patterns. In these cases, LocalKDC helps bring Kerberos-based protections to scenarios that traditionally depended on NTLM for local credentials.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Together, these capabilities extend Kerberos in two directions: domain-based enterprise credentials, and local and consumer-style account scenarios, further reducing the exposure to credential theft and relay-based attacks. This matters because, as part of a broader shift toward modern and enforced authentication, simply disabling older protocols is not enough. Organizations also need secure, reliable authentication that works consistently, without falling back to legacy protocols. These features help deliver that by providing modern, compatible alternatives that reflect how customers operate today.&lt;/P&gt;
&lt;H4&gt;Registry Configuration:&lt;/H4&gt;
&lt;P&gt;For this public preview, &lt;STRONG&gt;IAKerb&lt;/STRONG&gt; and &lt;STRONG&gt;LocalKDC&lt;/STRONG&gt; can be configured using registry settings under:&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;The supported values for this preview are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;DisableIAKerb&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;DisableLocalKDC&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Set the value to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;0&lt;/STRONG&gt; to enable the feature&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;1&lt;/STRONG&gt; to disable the feature&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Note: If a registry value is &lt;STRONG&gt;not present&lt;/STRONG&gt;, Windows uses the &lt;STRONG&gt;default behavior for that release&lt;/STRONG&gt;. In this preview, the defaults are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;IAKerb:&lt;/STRONG&gt; enabled by default (0)&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;LocalKDC: &lt;/STRONG&gt;disabled by default (1)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This gives you flexibility to evaluate the features in Insider environments while controlling rollout and validation according to your needs.&lt;/P&gt;
&lt;H4&gt;What you can do now&lt;/H4&gt;
&lt;P&gt;With this public preview, customers participating in the Canary Channel can test these capabilities in preview environments and validate the scenarios where NTLM is still commonly used. These features are designed to address important NTLM fallback scenarios but will not eliminate every remaining NTLM dependency in Windows environments; some scenarios may still require NTLM based on application behavior, infrastructure assumptions, or legacy dependencies. Our goal with this preview is to close some of the key gaps by extending Kerberos to more scenarios, while continuing broader work to reduce NTLM dependency across the platform over time. Once available, you can use this preview to help:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Identify scenarios already covered by IAKerb or LocalKDC&lt;/LI&gt;
&lt;LI&gt;Validate those scenarios in controlled environments, and use the documented configuration options to control enablement during testing&lt;/LI&gt;
&lt;LI&gt;Understand where NTLM dependencies still remain using our enhanced NTLM Auditing&lt;/LI&gt;
&lt;LI&gt;Check for dependencies such as name resolution, SPN configuration, or legacy assumptions&lt;/LI&gt;
&lt;LI&gt;Prepare for future improvements that will address additional cases&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;We also recommend evaluating the following areas:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Access to SMB shares&lt;/LI&gt;
&lt;LI&gt;Remote administration scenarios&lt;/LI&gt;
&lt;LI&gt;Environments with limited or no direct Domain Controller (DC) connectivity&lt;/LI&gt;
&lt;LI&gt;Workgroup or standalone device authentication&lt;/LI&gt;
&lt;LI&gt;Local account access patterns&lt;/LI&gt;
&lt;LI&gt;Scenarios being prepared for NTLM reduction or eventual NTLM blocking&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This preview is an opportunity to validate application compatibility, infrastructure dependencies, and operational readiness before broader rollout decisions are made. Learn more about upcoming work in this space here: &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/advancing-windows-security-disabling-ntlm-by-default/4489526" target="_blank" rel="noopener" data-lia-auto-title="Advancing Windows security: Disabling NTLM by default - Windows IT Pro Blog" data-lia-auto-title-active="0"&gt;Advancing Windows security: Disabling NTLM by default - Windows IT Pro Blog&lt;/A&gt;.&lt;/P&gt;
&lt;H4&gt;Troubleshooting and Feedback&lt;/H4&gt;
&lt;P&gt;As you evaluate IAKerb and LocalKDC in preview environments, you may encounter scenarios where authentication behaves differently than expected. Windows provides &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/troubleshoot/windows-server/windows-security/kerberos-authentication-troubleshooting-guidance" target="_blank" rel="noopener"&gt;built-in logging&lt;/A&gt; to help you understand what is happening and identify potential issues. These logs help you:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Verify whether Kerberos authentication is being used&lt;/LI&gt;
&lt;LI&gt;Identify cases where IAKerb or LocalKDC is involved&lt;/LI&gt;
&lt;LI&gt;Detect failures or fallback conditions&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;You can also leverage &lt;A class="lia-external-url" href="https://support.microsoft.com/en-us/topic/overview-of-ntlm-auditing-enhancements-in-windows-11-version-24h2-and-windows-server-2025-b7ead732-6fc5-46a3-a943-27a4571d9e7b" target="_blank" rel="noopener"&gt;NTLM operational logs&lt;/A&gt; to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Identify when NTLM is still being used&lt;/LI&gt;
&lt;LI&gt;Understand why fallback to NTLM is occurring&lt;/LI&gt;
&lt;LI&gt;Prioritize scenarios for further investigation&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Reviewing these logs together can help you determine whether authentication is staying on a Kerberos path (via IAKerb or LocalKDC) or falling back to NTLM and why.&lt;/P&gt;
&lt;H5&gt;When to expect fallback behavior&lt;/H5&gt;
&lt;P&gt;Because this is a preview release, some scenarios may still fall back to NTLM due to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Application-specific dependencies&lt;/LI&gt;
&lt;LI&gt;Environmental configuration (e.g., name resolution or SPN issues)&lt;/LI&gt;
&lt;LI&gt;Interactions between domain accounts and local accounts on the same machine&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;IAKerb and LocalKDC are designed to address a subset of common NTLM fallback scenarios, and continued improvements are planned to expand coverage over time.&lt;/P&gt;
&lt;H5&gt;Share feedback and scenarios&lt;/H5&gt;
&lt;P&gt;If you encounter a scenario that does not behave as expected, or if you have a unique authentication flow you would like us to evaluate, we encourage you to contact us at &lt;A class="lia-external-url" href="mailto:ntlm@microsoft.com" target="_blank" rel="noopener"&gt;ntlm@microsoft.com&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Please include details such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The scenario you are testing&lt;/LI&gt;
&lt;LI&gt;Expected vs. actual behavior&lt;/LI&gt;
&lt;LI&gt;Relevant event log entries (if available)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Your feedback is critical to helping us improve coverage and ensure these capabilities work reliably across real-world environments.&lt;/P&gt;
&lt;H4&gt;Securing today. Preparing for what’s next.&lt;/H4&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Security in Windows is built into the platform—continuously maintained and designed to evolve as threats change.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Learn more in the &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows/security/book/" target="_blank" rel="noopener"&gt;Windows Security book &lt;/A&gt;and &lt;A class="lia-external-url" href="https://aka.ms/ws2025securitybook" target="_blank" rel="noopener"&gt;Windows Server Security book&lt;/A&gt; or explore &lt;A class="lia-external-url" href="https://www.microsoft.com/en-us/windows/business" target="_blank" rel="noopener"&gt;Windows 11&lt;/A&gt;, &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows-server/" target="_blank" rel="noopener"&gt;Windows Server&lt;/A&gt;, and &lt;A class="lia-external-url" href="https://www.microsoft.com/en-us/windows/business/devices/copilot-plus-pcs" target="_blank" rel="noopener"&gt;Copilot+ PCs&lt;/A&gt;. For broader solutions, visit the &lt;A class="lia-external-url" href="https://www.microsoft.com/en-us/security/business" target="_blank" rel="noopener"&gt;Microsoft Security site&lt;/A&gt;, follow the Security blog, or connect with &lt;A class="lia-external-url" href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;Microsoft Security&lt;/A&gt; on LinkedIn and &lt;A class="lia-external-url" href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;@MSFTSecurity&lt;/A&gt;.   &lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2026 16:32:15 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/reducing-ntlm-dependency-iakerb-and-localkdc-in-windows-insider/ba-p/4524615</guid>
      <dc:creator>mariam_gewida</dc:creator>
      <dc:date>2026-06-02T16:32:15Z</dc:date>
    </item>
    <item>
      <title>Made for developers and agents, Windows 365 at Build 2026</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/made-for-developers-and-agents-windows-365-at-build-2026/ba-p/4519041</link>
      <description>&lt;P&gt;Build 2026 is here, and Windows 365 is showing up in a&lt;STRONG&gt; BIG&lt;/STRONG&gt; way. Over the past year, we’ve listened closely to developers and IT teams using Cloud PCs at scale. You told us that bringing a new developer onto a Cloud PC needs to be streamlined—that signing in should mean being ready to code, not spending hours on setup. We hear from you that compute choice matters, and that a one-size-fits-all approach doesn’t work for dev teams building everything from web apps to AI/ML workloads. In addition, you told us that agents are already in use—and they need a real place to run, backed by the same security, identity, and policy you trust. Today, we’re announcing our biggest release yet of developer and agent capabilities on Windows 365. It brings secure Cloud PCs preconfigured with common development tools, expanded compute options, a new platform for enterprise AI agents, and stronger security and connectivity—so you can build and scale from anywhere, on any device.&lt;/P&gt;
&lt;H4&gt;A development experience that starts ready&lt;/H4&gt;
&lt;P&gt;Every developer knows this story: a new machine, a fresh image—and hours lost to setup before a single line of code gets written. That friction repeats with every onboarding, project switch, and refresh. We’re solving it with ready-to-code Windows 365 Cloud PCs, enhanced image management, and flexible customization—so developers can get to coding faster.&lt;/P&gt;
&lt;P&gt;With &lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/dev-box/dev-box-roadmap" target="_blank" rel="noopener"&gt;Microsoft Dev Box now in maintenance mode&lt;/A&gt;, Windows 365 is the forward-looking path at Microsoft for teams seeking to standardize developer environments on Cloud PCs, backed by an investment roadmap focused on developer productivity, AI workloads, and enterprise scale.&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/windows-365/enterprise/device-images" target="_blank" rel="noopener"&gt;Windows 365 now supports Windows 11 developer configuration image&lt;/A&gt;, in public preview: It delivers a preconfigured, ready‑to‑code environment with tools developers already use, including Visual Studio Code, Git, GitHub CLI, Python, Node.js, and Windows Subsystem for Linux (WSL), available from first sign‑in. Developers can navigate across Windows and Linux (via WSL), local and cloud, and AI workloads, all from the same starting point.&lt;/P&gt;
&lt;DIV class="lia-embeded-content" contenteditable="false"&gt;&lt;IFRAME src="https://www.youtube.com/embed/3wNoOKTxxy0?si=_wwwidYDS4Min3lB" width="560" height="315" title="YouTube video player" allowfullscreen="allowfullscreen" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" frameborder="0" sandbox="allow-scripts allow-same-origin allow-forms"&gt;&lt;/IFRAME&gt;&lt;/DIV&gt;
&lt;P style="font-size: 0.85em; color: #666;"&gt;Video caption: With GitHub remote capabilities enabled on your Cloud PC, you can monitor and manage a running CLI session from another endpoint, such as your local device, as demonstrated in this video.&lt;/P&gt;
&lt;P&gt;Building on this,&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows-365/enterprise/autopilot-device-preparation" target="_blank" rel="noopener"&gt;autopilot device preparation&lt;/A&gt; now available for Windows 365, automates the installation of apps and scripts on Cloud PCs through Microsoft Intune before a user ever signs in. This helps ensure a ready-to-use, compliant environment without manual setup. Coming soon in preview, we will introduce expanded customization capabilities that give teams greater flexibility to tailor Cloud PC environments to their project needs, including configuring required SDKs, CLIs, packages, build tools, repositories, and onboarding workflows, all while remaining within enterprise guardrails and enabling developers to get productive immediately. In addition, &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows-365/enterprise/add-device-images" target="_blank" rel="noopener"&gt;Azure Compute Gallery&lt;/A&gt; support is now generally available. This enables organizations to store and manage custom images in Azure Compute Gallery and import them into Windows 365 to create Cloud PCs.&lt;/P&gt;
&lt;P&gt;For developers building AI‑powered apps, &lt;A class="lia-external-url" href="https://aka.ms/W365LMLocal" target="_blank" rel="noopener"&gt;select language models (LM) now run directly on your Windows 365 Cloud PC&lt;/A&gt;, extending this ready-to-code experience to advanced workloads. and enabling developers to build and iterate on LM-driven applications using Cloud PC compute.&lt;/P&gt;
&lt;H4&gt;Flexible plans to choose from&lt;/H4&gt;
&lt;P&gt;As part of ongoing Windows 365 portfolio update, &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/windows-365-and-azure-virtual-desktop-expanding-access/4515931" target="_blank" rel="noopener" data-lia-auto-title="Windows 365 Flex, formerly known as Windows 365 Frontline" data-lia-auto-title-active="0"&gt;Windows 365 Flex, formerly known as Windows 365 Frontline&lt;/A&gt;, fits how employees work, whether through shared access or cost-efficient dedicated experiences.&lt;/P&gt;
&lt;P&gt;And that flexibility shows up in compute choice. &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows-365/enterprise/cloud-pc-size-recommendations?source=recommendations" target="_blank" rel="noopener"&gt;32vCPU Windows 365 Cloud PCs&lt;/A&gt; are now available in Windows 365 Enterprise and Windows 365 Flex, supporting compute-intensive workloads like software development, data modeling, simulations, and AI/ML. Similarly, a new &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows-365/enterprise/gpu-cloud-pc" target="_blank" rel="noopener"&gt;Windows 365 GPU Select&lt;/A&gt; plan is now available, expanding the Windows 365 GPU-enabled Cloud PC portfolio and giving developers a more accessible GPU option alongside the existing Standard, Super, and Max plans. The new capabilities are optimized for smooth, low-latency visual performance across applications, multimedia, and hardware accelerated graphic workflows, providing developers with more ways to accelerate build and test scenarios. All GPU-enabled Cloud PCs are available across both Windows 365 Enterprise and Windows 365 Flex (in shared or dedicated mode).&lt;/P&gt;
&lt;H4&gt;Enterprise-managed execution environment for AI agents&lt;/H4&gt;
&lt;P&gt;As AI agents move from reasoning to execution, a key challenge is enabling them to take action across enterprise applications and systems, not just APIs. Many enterprise workflows still depend on browsers, desktop applications, and legacy tools, which require agents to operate beyond traditional integration points.&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="http://www.aka.ms/W365AHome" target="_blank" rel="noopener"&gt;Windows 365 for Agents&lt;/A&gt; is now generally available. Agent makers can use it as part of Agent 365 tools or through Microsoft Copilot Studio (preview). It enables enterprise AI automation by providing agents with secured, managed, and available Cloud PCs that run within real business environments. Agents can interact directly with applications and browsers, execute multi-step workflows, and operate across modern and legacy systems. Each Cloud PC is Entra-joined, Intune-managed, and policy-enforced, helping IT scale agents with consistent security, governance, and compliance. While Agent 365 secures and governs the agent, Windows 365 for Agents provides a dedicated workspace to support performance and security needs.&lt;/P&gt;
&lt;P&gt;Designed to support agent creators, Windows 365 for Agents works with agents built using both no-code and pro-code approaches. It's already powering agentic experiences across Microsoft, from computer-use scenarios in Researcher to Project Opal within Microsoft Copilot Studio, demonstrating enterprise readiness. Beyond Microsoft’s own experiences, the platform also supports third-party agents, including partner-provided examples such as Sai from Simular. This always-on AI coworker can operate applications on a Windows Cloud PC by interacting with the user interface through mouse and keyboard inputs, similar to a human.&lt;/P&gt;
&lt;P&gt;Watch Simular’s AI agent Sai in action in the demo below.&lt;/P&gt;
&lt;DIV class="lia-embeded-content" contenteditable="false"&gt;&lt;IFRAME src="https://www.youtube.com/embed/LQL6KA6lJus?si=2VBgbDVYHzasfkSu" width="560" height="315" title="YouTube video player" allowfullscreen="allowfullscreen" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" frameborder="0" sandbox="allow-scripts allow-same-origin allow-forms"&gt;&lt;/IFRAME&gt;&lt;/DIV&gt;
&lt;P style="font-size: 0.85em; color: #666;"&gt;Video caption: Using Windows 365 for Agents, Sai runs an overnight claims-processing workflow in a Contoso claims app with no APIs. Sai reads scanned claim forms, extracts key fields, verifies coverage, and enters results directly through the UI. &lt;/P&gt;
&lt;H4&gt;Secure access and reliable connectivity&lt;/H4&gt;
&lt;P&gt;Developers get consistent experience, agents run in a dedicated runtime, and IT maintains centralized control across both. Windows 365 brings these capabilities together, combining developer productivity with the provisioning, policy enforcement, and compliance controls organizations require. Building on this foundation, &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/adaptive-data-protection-with-context-based-redirections-in-windows-365-now-in-p/4521366" data-lia-auto-title="context-based redirection" data-lia-auto-title-active="0" target="_blank"&gt;context-based redirection&lt;/A&gt;, in public preview starting in June, adds more adaptive data protection. Organizations can apply granular redirection policies based on contextual signals, such as device management status, user network and location status to control how content is accessed and redirected.&lt;/P&gt;
&lt;P&gt;To improve connection reliability and user experience, Remote Desktop Protocol (RDP) multipath with redundant Transmission Control Protocol (TCP), now generally available (&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows-365/enterprise/rdp-multipath" target="_blank" rel="noopener"&gt;Windows 365&lt;/A&gt;/&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/azure/virtual-desktop/rdp-multipath" target="_blank" rel="noopener"&gt;Azure Virtual Desktop&lt;/A&gt;), enhances connection resiliency by maintaining multiple transport paths (UDP and TCP) between the client and session host. This dynamically selects the most reliable path, particularly in TCP-only or UDP-restricted environments- improving session reliability and continuity while reducing disruptions to enhance the overall user experience. In addition, &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows-app/health-checks?tabs=windows" target="_blank" rel="noopener"&gt;health checks in Windows App, now available on sovereign clouds&lt;/A&gt; (generally available) provides lightweight diagnostics that validate device readiness, network connectivity, and sovereign-specific endpoint reachability, enabling faster troubleshooting and more reliable connections in government cloud environments.&lt;/P&gt;
&lt;P&gt;For shared and controlled usage scenarios, &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows-365/enterprise/windows-365-flex-snapshot-based-reset" target="_blank" rel="noopener"&gt;Snapshot-based reset for Windows 365 Flex (in shared mode)&lt;/A&gt;, now in public preview, automatically reverts shared Windows 365 Flex Cloud PCs to a clean state after each user signs out. Every user starts with a clean Cloud PC, simplifying management and supporting the shared licensing model for Windows 365 Flex.&lt;/P&gt;
&lt;P&gt;Beyond organizational boundaries, using Azure Files and FSLogix as a user profile management solution for external identities in Azure Virtual Desktop is now generally available, enabling secure access for external users such as partners and vendors. To see more, check out our latest &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/azurevirtualdesktopblog/azure-virtual-desktop-supports-greater-application-and-identity-functionality-wi/4521365" data-lia-auto-title="blog" data-lia-auto-title-active="0" target="_blank"&gt;blog&lt;/A&gt;.&lt;/P&gt;
&lt;H4&gt;Get started today&lt;/H4&gt;
&lt;P&gt;With these updates, Windows 365 moves into a new phase that further reduces setup friction, keeps developers in flow, and helps teams build, run, and scale across environments.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.microsoft.com/windows-365/windows-365-enterprise" target="_blank" rel="noopener"&gt;Windows 365 Enterprise&lt;/A&gt; and &lt;A class="lia-external-url" href="https://www.microsoft.com/windows-365/windows-365-frontline" target="_blank" rel="noopener"&gt;Windows 365 Flex&lt;/A&gt; now include new developer capabilities - &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2167907&amp;amp;clcid=0x409&amp;amp;culture=en-us&amp;amp;country=us" target="_blank" rel="noopener"&gt;buy&lt;/A&gt; or &lt;A class="lia-external-url" href="https://www.microsoft.com/en-us/windows-365/contact-sales" target="_blank" rel="noopener"&gt;contact sales&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.microsoft.com/windows-365/contact-sales" target="_blank" rel="noopener"&gt;Contact sales&lt;/A&gt; to try Windows 365 32 vCPU and Windows 365 GPU-enabled Cloud PCs today.&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://aka.ms/W365MCS" target="_blank" rel="noopener"&gt;Try 50 free hours&lt;/A&gt; of Windows 365 for Agents Cloud PC with Microsoft Copilot Studio.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;Learn more at Microsoft Build 2026&lt;/H4&gt;
&lt;P&gt;Join the Windows 365 sessions at Microsoft Build 2026 to learn more and see these capabilities in action. Microsoft Build in 2026 offers two full days of content, from keynotes, breakouts, hands-on labs, to on-demand sessions that you can join live or watch anytime. The digital experience is free to attend. &lt;A class="lia-external-url" href="https://build.microsoft.com/home" target="_blank" rel="noopener"&gt;Register today&lt;/A&gt; to explore the full schedule, discover featured partners, and save your must-see sessions.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Tuesday, June 2, 2026:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://build.microsoft.com/en-US/sessions/KEY01?source=sessions" target="_blank" rel="noopener"&gt;Microsoft Opening Keynote&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="http://aka.ms/Build26BRK261" target="_blank" rel="noopener"&gt;BRK261: Build and ship faster with a developer-optimized experience on Windows&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="http://aka.ms/Build26BRK262" target="_blank" rel="noopener"&gt;BRK262: AI &amp;amp; Agent – Augmented coding you can trust on Windows&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://build.microsoft.com/en-US/sessions/LAB550-R2?source=sessions" target="_blank" rel="noopener"&gt;LAB550-R2: Build, deploy, &amp;amp; scale agents with Windows 365&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://build.microsoft.com/en-US/sessions/LAB550?source=sessions" target="_blank" rel="noopener"&gt;LAB550: Build, deploy, &amp;amp; scale agents with Windows 365&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://build.microsoft.com/en-US/sessions/LAB550-R1?source=sessions" target="_blank" rel="noopener"&gt;LAB550-R1: Build, deploy, &amp;amp; scale agents with Windows 365&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Wednesday, June 3, 2026:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="http://aka.ms/Build26BRK260" target="_blank" rel="noopener"&gt;BRK260: Build apps with Local AI for unmetered intelligence on every Windows PC&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://build.microsoft.com/en-US/sessions/LAB550-R3?source=sessions" target="_blank" rel="noopener"&gt;LAB550-R3: Build, deploy, &amp;amp; scale agents with Windows 365&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Build on-demand sessions available beginning June 2:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="http://www.aka.ms/Build26OD855" target="_blank" rel="noopener"&gt;OD855: Architecting computer-using agents with Windows 365 as an agent runtime&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="http://aka.ms/Build26OD852" target="_blank" rel="noopener"&gt;OD852: Accelerating developer productivity with Windows 365&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://build.microsoft.com/en-US/sessions/LAB550D?source=sessions" target="_blank" rel="noopener"&gt;LAB550D: Build, deploy, &amp;amp; scale agents with Windows 365&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Continue the conversation. Find best practices. Bookmark the &lt;/SPAN&gt;&lt;A href="https://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Tech Community&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, then follow us on &lt;/SPAN&gt;&amp;nbsp;&lt;A href="https://www.linkedin.com/company/windows-it-pro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;or&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://twitter.com/mswindowsitpro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSWindowsITPro&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; for updates. Looking for support? Visit &lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows on Microsoft Q&amp;amp;A&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2026 00:38:24 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/made-for-developers-and-agents-windows-365-at-build-2026/ba-p/4519041</guid>
      <dc:creator>BhavyaChopra</dc:creator>
      <dc:date>2026-06-03T00:38:24Z</dc:date>
    </item>
    <item>
      <title>Windows news you can use: May 2026</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-news-you-can-use-may-2026/ba-p/4516353</link>
      <description>&lt;P&gt;First, as we head into June and the first set of Secure Boot certificates start to expire, there will be another &lt;A href="https://techcommunity.microsoft.com/event/windowsevents/ask-microsoft-anything-secure-boot---june-2026/4522056" data-lia-auto-title="Secure Boot Ask Microsoft Anything (AMA) on Thursday, June 4" data-lia-auto-title-active="0" target="_blank"&gt;Secure Boot Ask Microsoft Anything (AMA) on Thursday, June 4&lt;/A&gt;. Do save the date and post your questions early or at any time during the live stream if you need assistance. You can also &lt;A href="https://techcommunity.microsoft.com/event/windowsevents/ask-microsoft-anything-secure-boot---may-2026/4513524" target="_blank"&gt;watch the May edition on demand&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;For more general questions around Windows deployment, updates, and management, you can join the chat-based Windows Office Hours every third Thursday. The next event will be &lt;A href="https://techcommunity.microsoft.com/event/windowsevents/windows-office-hours-june-18-2026/4458465" target="_blank"&gt;June 18 at 8:00 AM PDT&lt;/A&gt;.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Now let's dive in to more Windows news you can use you might have missed this past month.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;New in Windows update and device management&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;[AUTOPATCH] [GCC] – Windows Autopatch is now included automatically for Government Community Cloud (GCC) customers using Microsoft 365 G3 GCC, Microsoft 365 GCC G5, or Microsoft 365 GCC G5 without WDATP/CAS Unified. The $0 Windows Enterprise (OLS) activation SKU is no longer required. For guidance on how to get started, read &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/windows-autopatch-for-the-us-government-how-to-get-started/4467570/replies/4472671" target="_blank"&gt;Windows Autopatch for the US government&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;[HOTPATCH] – Starting with the May 2026 Windows security update, hotpatch updates are &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/securing-devices-faster-with-hotpatch-updates-on-by-default/4500066" target="_blank"&gt;now on by default&lt;/A&gt; for those using Windows Autopatch through Microsoft Intune or the Windows updates API in Microsoft Graph. The default tenant setting; however, is only applied to devices that aren't members of a quality update policy. Windows Autopatch respects your configuration of quality update policies.&lt;/LI&gt;
&lt;LI&gt;[BACKUP] – Start managing &lt;A href="https://learn.microsoft.com/windows/configuration/windows-backup/catalog-esr?pivots=windows-11" target="_blank"&gt;Enterprise State Roaming (ESR)&lt;/A&gt; through Windows Backup for Organizations policies. By the end of June, you'll no longer be able to access ESR policies through the Microsoft Entra portal and will instead need to use Microsoft Intune.&lt;/LI&gt;
&lt;LI&gt;[W365] – &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/admin-insights-for-windows-365-stay-on-top-of-what-needs-attention-%E2%80%94-now-in-publ/4517570" target="_blank"&gt;Admin Insights for Windows 365&lt;/A&gt;, now in public preview, brings together important signals from existing reporting, monitoring, and alerting from Intune. Quickly understand what's happening in your environment and where to focus.&lt;/LI&gt;
&lt;LI&gt;[ARM] – Does your organization use, or plan to adopt, Arm-based Windows devices? Check out a snapshot of companies that have recently delivered or expanded &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/advancing-print-readiness-across-the-windows-on-arm-ecosystem/4515926" target="_blank"&gt;print solutions supporting Windows on Arm&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;[SKILLING] – Still have devices running Windows 10? Need advice on optimizing how you roll out new versions of Windows and Microsoft 365 apps in your organization? Use the updated &lt;A href="https://learn.microsoft.com/en-us/training/paths/stay-current-with-windows/" target="_blank"&gt;Stay current with Windows learning path&lt;/A&gt; to plan, prepare for, and deploy for updates across your organization.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;New in Windows security&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;[SECURE BOOT] – The &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/updated-secure-boot-status-report-in-windows-autopatch/4517920" target="_blank"&gt;updated Secure Boot status report in Windows Autopatch&lt;/A&gt; provides better device-level visibility into certificate status, trust configuration, and readiness for Secure Boot certificate updates. New interactive certificate-level details fit directly into your certificate rollout workflow.&lt;/LI&gt;
&lt;LI&gt;[SECURE BOOT] – Microsoft Defender now provides centralized visibility into Secure Boot 2023 certificate readiness across your device fleet. &lt;A href="https://aka.ms/secureboot-mde" target="_blank"&gt;A new assessment&lt;/A&gt; categorizes your devices automatically as exposed, compliant, and not applicable.&lt;/LI&gt;
&lt;LI&gt;[FIREWALL] [NETWORKING] – Have devices that experience difficulties receiving updates? &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/configuring-firewall-and-proxies-for-smooth-windows-updates/4517913" target="_blank"&gt;New guidance&lt;/A&gt; is available to help you identify potential causes and implement solutions to ensure updates roll out smoothly moving forward.&lt;/LI&gt;
&lt;LI&gt;[PRINTING] – A new icon appears on the &lt;STRONG&gt;Printers &amp;amp; scanners&lt;/STRONG&gt; settings page. It helps you easily understand which devices support a more secure printing experience with &lt;A href="https://learn.microsoft.com/windows/modern-print/windows-protected-print-mode/windows-protected-print-mode" target="_blank"&gt;Windows protected print mode&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;[PASSKEYS] – World Passkey Day was May 7. Learn how Microsoft is &lt;A href="https://www.microsoft.com/en-us/security/blog/2026/05/07/world-passkey-day-advancing-passwordless-authentication/?msockid=12a7b86c8089634f2b24ae70817162cf" target="_blank"&gt;Advancing passwordless authentication&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;To explore what's new in security across the Microsoft platform, see &lt;A href="https://www.microsoft.com/en-us/security/blog/2026/05/21/whats-new-in-microsoft-security-may-2026/" target="_blank"&gt;What's new in Microsoft Security: May 2026&lt;/A&gt;.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;New in AI&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;[DEVELOPERS] – Microsoft Build runs June 2-3! It features &lt;A href="https://build.microsoft.com/en-US/sessions?search=windows&amp;amp;sortBy=relevance" target="_blank"&gt;sessions on building, modernizing, and optimizing Windows apps and developer experiences&lt;/A&gt;. Check out especially AI-powered capabilities, cloud integration, and next‑gen tooling like Copilot, WinUI, and GitHub Copilot.&lt;/LI&gt;
&lt;LI&gt;[AGENTS] – Windows is adding a new way to monitor your agents from the taskbar. This experience supports agents across first- and third-party apps, with &lt;A href="https://learn.microsoft.com/microsoft-365/copilot/researcher-agent" target="_blank"&gt;Researcher in the Microsoft 365 Copilot app&lt;/A&gt;as the first adopter.&lt;/LI&gt;
&lt;LI&gt;[COPILOT] [M365] – The &lt;A href="https://www.microsoft.com/en-us/microsoft-365/blog/2026/05/28/introducing-a-new-design-for-microsoft-365-copilot/" target="_blank"&gt;Copilot app has been redesigned&lt;/A&gt; to be faster and more responsive. What do you think about the way Copilot shows up across Microsoft 365 apps?&lt;/LI&gt;
&lt;LI&gt;[COPILOT] [M365] – New &lt;A href="https://adoption.microsoft.com/en-us/copilot/" target="_blank"&gt;Microsoft 365 Copilot&lt;/A&gt; resources are now available to help you get started with adopting Copilot capabilities across your organization.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;To learn about latest capabilities for Copilot+ PCs, visit the &lt;A href="https://www.microsoft.com/windows/business/roadmap" target="_blank"&gt;Windows Roadmap&lt;/A&gt; and filter Platform by “Copilot+ PC Exclusives.”&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;New in Windows Server&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;For the latest features and improvements for Windows Server, see the &lt;A href="https://support.microsoft.com/topic/windows-server-2025-update-history-10f58da7-e57b-4a9d-9c16-9f1dcd72d7d7" target="_blank"&gt;Windows Server 2025 release notes&lt;/A&gt; and &lt;A href="https://support.microsoft.com/topic/windows-server-version-23h2-update-history-68c851ff-825a-4dbc-857b-51c5aa0ab248" target="_blank"&gt;Windows Server, version 23H2 release notes&lt;/A&gt;.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;[HOTPATCH] – Hotpatch updates enabled by Azure Arc are now available at no additional cost for Windows Server 2025. &lt;A href="https://techcommunity.microsoft.com/blog/AzureArcBlog/simplified-access-to-hotpatching-enabled-by-azure-arc-for-windows-server-2025/4521251" target="_blank"&gt;Read the announcement&lt;/A&gt; for details on eligibility and guidance on how to get started.&lt;/LI&gt;
&lt;LI&gt;[SKILLING] – All 19 sessions from &lt;A href="https://techcommunity.microsoft.com/event/windowsserver-events/windows-server-summit-2026/4501032" target="_blank"&gt;Windows Server Summit 2026&lt;/A&gt; are now available on demand. Learn and improve your skills on your schedule.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;New in productivity and collaboration&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Install the May 2026 security update for &lt;A href="https://support.microsoft.com/topic/may-12-2026-kb5089549-os-builds-26200-8457-and-26100-8457-28ec2a99-4bbe-481d-a340-5c6cf18d9acb" target="_blank"&gt;Windows 11, versions 25H2 and 24H2&lt;/A&gt; to get these and other capabilities, which will be rolling out gradually:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;[FILE EXPLORER] – View and Sort preferences are now preserved in folders such as Downloads and Documents when apps launch File Explorer directly to those locations. File Explorer also now supports uu, cpio, xar, and NuGet Packages (nupkg) archive formats.&lt;/LI&gt;
&lt;LI&gt;[INPUT] – Voice typing on the touch keyboard now looks simpler and more intuitive. The updated design removes the full‑screen overlay and shows voice typing animations directly on the dictation key.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;New features and improvements are coming in the June 2026 security update. You can preview them by installing the May 2026 optional non-security update for &lt;A href="https://support.microsoft.com/topic/may-26-2026-kb5089573-os-builds-26200-8524-and-26100-8524-preview-f378c8ae-0170-47c9-a1e9-dfef978c8e17" target="_blank"&gt;Windows 11, versions 25H2 and 24H2&lt;/A&gt;. This update includes the gradual rollout of:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;[AUDIO] – Shared audio enables two people to listen to the same audio from a single Windows 11 PC at the same time.&lt;/LI&gt;
&lt;LI&gt;[CAMERA] – Windows 11's Multi-App Camera feature allows multiple applications to access your camera stream at the same time.&lt;/LI&gt;
&lt;LI&gt;[MAGNIFIER] – Magnifier now provides clearer and more consistent announcements when working with a screen reader. You'll hear helpful announcements when you zoom in or out, switch views, turn color inversion on or off, or turn Magnifier on or off. In addition, Magnifier now supports magnification of permitted protected content.&lt;/LI&gt;
&lt;LI&gt;[SEARCH] – Windows Search will now find and prioritize files with as few as two characters.&lt;/LI&gt;
&lt;LI&gt;[PERFORMANCE] – Task Manager now provides enhanced visibility into NPU usage, including new metrics and AI activity insights.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Lifecycle reminders&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Check out our lifecycle documentation for the latest updates on &lt;A href="https://learn.microsoft.com/windows/whats-new/deprecated-features" target="_blank"&gt;Deprecated features in the Windows client&lt;/A&gt; and &lt;A href="https://learn.microsoft.com/windows-server/get-started/removed-deprecated-features-windows-server-2025" target="_blank"&gt;Features removed or no longer developed starting with Windows Server 2025&lt;/A&gt;.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Additional resources&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Looking for the latest news and previews for Windows, Copilot, Copilot+ PCs, the Windows and Windows Server Insider Programs, and more? Check out these resources:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/windows/business/roadmap" target="_blank"&gt;Windows Roadmap&lt;/A&gt; for new Copilot+ PCs and Windows features – filter by platform, version, status, and channel or search by feature name&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/copilot/microsoft-365/release-notes?tabs=all" target="_blank"&gt;Microsoft 365 Copilot release notes&lt;/A&gt; for latest features and improvements&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://blogs.windows.com/windows-insider/" target="_blank"&gt;Windows Insider Blog&lt;/A&gt; for what's available in the Beta and Experimental channels&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/windows-server/discussions/windowsserverinsiders" target="_blank"&gt;Windows Server Insider&lt;/A&gt; for feature preview opportunities&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://support.microsoft.com/topic/understanding-update-history-for-windows-insider-preview-features-fixes-and-changes-bb9dd4b1-9d2b-4753-8b23-ce90e62f6845" target="_blank"&gt;Understanding update history for Windows Insider preview features, fixes, and changes&lt;/A&gt; to learn about the types of updates for Windows Insiders&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Join the conversation&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;We are always looking to improve this monthly summary. Drop us a note in the Comments and let us know what we can do to make this more useful for you!&lt;/P&gt;
&lt;HR /&gt;
&lt;P style="font-size: 14px;"&gt;Continue the conversation. Find best practices. Bookmark the &lt;A href="http://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;Windows Tech Community&lt;/A&gt;, then follow us &lt;A href="https://x.com/mswindowsitpro" target="_self"&gt;@MSWindowsITPro&lt;/A&gt; on X and on &lt;A href="https://www.linkedin.com/company/windows-it-pro" target="_blank" rel="noopener"&gt;LinkedIn&lt;/A&gt;. Looking for support? Visit &lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;Windows on Microsoft Q&amp;amp;A&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2026 21:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-news-you-can-use-may-2026/ba-p/4516353</guid>
      <dc:creator>Chris_Morrissey</dc:creator>
      <dc:date>2026-06-01T21:00:00Z</dc:date>
    </item>
    <item>
      <title>Updated Secure Boot status report in Windows Autopatch</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/updated-secure-boot-status-report-in-windows-autopatch/ba-p/4517920</link>
      <description>&lt;P&gt;Do more with the improved Secure boot status report in Windows Autopatch. Now, you can gain better device-level visibility into certificate status, trust configuration, and readiness for Secure Boot certificate updates. New interactive certificate-level details fit directly into your certificate rollout workflow:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;A href="#community--1-_identify" target="_self"&gt;Identify devices that aren't up to date.&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="#community--1-_trust" target="_self"&gt;Use trust configuration and certificate details to understand applicability.&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="#community--1-_confidence" target="_self"&gt;Check confidence level to determine your rollout strategy.&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="#community--1-_alerts" target="_self"&gt;Use alerts and timestamps to validate reporting freshness and prioritize action.&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="#community--1-_remediation" target="_self"&gt;Plan targeted remediation instead of broad deployments.&lt;/A&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;From policy deployment to actual Secure Boot readiness&lt;/H2&gt;
&lt;P&gt;Secure Boot is a core Windows security feature that helps ensure devices start up using only trusted, digitally signed components. It helps protect against boot-level malware and enforces a root of trust during startup. As Secure Boot certificates evolve and older certificates approach expiration, visibility into device readiness becomes critical.&lt;/P&gt;
&lt;P&gt;To deploy Secure Boot certificate updates, the recommended option is to enable the &lt;A href="https://learn.microsoft.com/windows/client-management/mdm/policy-csp-secureboot#enablesecurebootcertificateupdates" target="_blank" rel="noopener"&gt;EnableSecurebootCertificateUpdates policy&lt;/A&gt;. When active, the policy automatically sends certificate updates to supported and eligible devices but requires a device restart to complete the process.&lt;/P&gt;
&lt;P&gt;However, before enabling a Secure Boot policy, it's important to understand:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Which devices have updated their certificates and are protected&lt;/LI&gt;
&lt;LI&gt;Whether firmware configuration blocks updates&lt;/LI&gt;
&lt;LI&gt;Whether devices are ready for rollout&lt;/LI&gt;
&lt;LI&gt;When to take action&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The &lt;A href="https://learn.microsoft.com/windows/deployment/windows-autopatch/monitor/secure-boot-status-report" target="_blank" rel="noopener"&gt;Secure Boot status report&lt;/A&gt; addresses this gap by giving you a data-informed view of device readiness, not just policy assignment status. The report provides a device-level view of Secure Boot across your Windows Autopatch-managed devices. Let's walk through how to quickly understand your fleet's readiness.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Note: &lt;/STRONG&gt;Certificate readiness presupposes devices with Secure Boot enabled. Devices with Secure Boot disabled are included for visibility only. They don't require any action.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;How to use the Secure Boot status report&lt;/H2&gt;
&lt;P&gt;The report includes several key signals designed to help you make informed decisions.&lt;/P&gt;
&lt;P&gt;Ready to see it in action? Start here:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Go to the &lt;A href="https://go.microsoft.com/fwlink/?linkid=2109431" target="_blank" rel="noopener"&gt;Intune admin center&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;Open &lt;STRONG&gt;Reports &lt;/STRONG&gt;&amp;gt; &lt;STRONG&gt;Windows Autopatch&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Windows quality updates&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Select &lt;STRONG&gt;Reports&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Open &lt;STRONG&gt;Secure Boot status&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/OL&gt;
&lt;img /&gt;
&lt;P&gt;&lt;a id="community--1-#_identify" class="lia-anchor"&gt;&lt;/a&gt;&lt;/P&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;Identify devices that aren't up to date by certificate status&lt;/H3&gt;
&lt;P&gt;Find the new column called &lt;STRONG&gt;Certificate status&lt;/STRONG&gt;. See which certificates require action based on an aggregate view. Here's what each status means:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Up to date:&lt;/STRONG&gt; No action is required.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Not up to date:&lt;/STRONG&gt; Devices require certificate updates.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Not applicable:&lt;/STRONG&gt; Secure Boot isn't enabled.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Drill into this field to see per-certificate details. No need for custom scripts or manual validation. Select the status cell for any device to see whether Secure Boot is enabled, its trust setting, and status for each of the four required certificates.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;a id="community--1-#_trust" class="lia-anchor"&gt;&lt;/a&gt;&lt;/P&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;Use trust configuration and certificate details to understand applicability&lt;/H3&gt;
&lt;P&gt;Not all devices require the same set of Secure Boot certificates. The &lt;STRONG&gt;Secure Boot trust setting&lt;/STRONG&gt; column shows whether a device trusts:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Microsoft-only components&lt;/LI&gt;
&lt;LI&gt;Both Microsoft and non-Microsoft components&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This is important because certificate applicability depends on how the device is configured, not just what exists on disk. For example, a device may be fully compliant even if certain certificates aren't present. This happens if certificates aren't required for that configuration.&lt;/P&gt;
&lt;P&gt;&lt;a id="community--1-#_confidence" class="lia-anchor"&gt;&lt;/a&gt;&lt;/P&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;Check confidence level to determine your rollout strategy&lt;/H3&gt;
&lt;P&gt;This is one of the most important additions in the new version of the report. The &lt;STRONG&gt;Confidence level &lt;/STRONG&gt;column helps guide deployment decisions based on Microsoft-observed data across similar devices and firmware configurations. Select any cell to see a flyout summary for that device. Review the description of the status and the recommended action. It also states whether the high-confidence deployment policy is allowed.&lt;/P&gt;
&lt;P&gt;Use this data to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Confidently auto-deploy updates to high-confidence devices.&lt;/LI&gt;
&lt;LI&gt;Manually validate devices with limited or no data.&lt;/LI&gt;
&lt;LI&gt;Pause rollout where known issues exist.&lt;/LI&gt;
&lt;/UL&gt;
&lt;img /&gt;
&lt;P&gt;Here are recommendations based on confidence level labels:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;High confidence: &lt;/STRONG&gt;Deploy the certificates depending on the policy setting:
&lt;UL&gt;
&lt;LI&gt;If the high-confidence policy is allowed: No action is required. Devices will automatically receive Secure Boot certificate updates through Windows Update.&lt;/LI&gt;
&lt;LI&gt;If the high-confidence policy isn't allowed: Deploy certificate updates manually when ready.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&amp;nbsp;&lt;STRONG&gt;Under observation:&lt;/STRONG&gt; Test certificate updates in controlled rollout.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;No data observed:&lt;/STRONG&gt; Carefully validate certificate updates before broad deployment. Microsoft hasn't observed this type of device in Secure Boot update data.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;Temporarily paused:&lt;/STRONG&gt; Don't deploy. Devices in this group are affected by a known issue. Consult with your OEM for possible firmware updates.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;Not supported:&lt;/STRONG&gt; Exclude these devices from automation.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Use the confidence level data to take out guesswork from your Secure Boot certificate rollout strategy and turn it into data-informed deployment.&lt;/P&gt;
&lt;P&gt;&lt;a id="community--1-#_alerts" class="lia-anchor"&gt;&lt;/a&gt;&lt;/P&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;Use alerts and timestamps to prioritize action&lt;/H3&gt;
&lt;P&gt;A new &lt;STRONG&gt;Alerts &lt;/STRONG&gt;column helps you validate reporting freshness and prioritize action. The report surfaces the following operational signals:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Devices missing diagnostic data&lt;/LI&gt;
&lt;LI&gt;Devices requiring action&lt;/LI&gt;
&lt;LI&gt;Timestamp of last reported diagnostic data&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Important! &lt;/STRONG&gt;To avoid false assumptions when validating rollout progress, note these important limitations:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Status updates can take up to 12 hours after restart to be reflected.&lt;/LI&gt;
&lt;LI&gt;Devices must send required diagnostic data to appear correctly in the report.&lt;/LI&gt;
&lt;LI&gt;Inactive devices might show up as &lt;EM&gt;Unknown&lt;/EM&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;a id="community--1-_remediation" class="lia-anchor"&gt;&lt;/a&gt;&lt;/P&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;Plan targeted remediation of Secure Boot certificates&lt;/H3&gt;
&lt;P&gt;Secure Boot certificate updates are not uniform across devices. They depend on firmware, configuration, and trust models. Due to this variation, applying Secure Boot updates sometimes sees unexpected results.&lt;/P&gt;
&lt;P&gt;Without clear visibility, organizations risk:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Missing required updates&lt;/LI&gt;
&lt;LI&gt;Deploying updates too broadly&lt;/LI&gt;
&lt;LI&gt;Misinterpreting device readiness&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The Secure Boot status report gives you a more precise, device-level understanding of readiness, so you can act confidently and help reduce risk across your estate. Together, these improvements focus on one thing: making the data actionable. If needed, make data-informed decisions on targeted remediations instead of broad deployments.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Note on Secure Boot updates and hotpatch updates&lt;/H2&gt;
&lt;P&gt;If you're using hotpatch updates, plan for a one-time change in strategy. More devices become eligible for Secure Boot certificate updates over time based on high-confidence diagnostic data. High-confidence deployment relies on data included in monthly non-security preview updates, which are typically released the fourth week of the month. By definition, devices receiving hotpatch updates don't receive these preview updates. As such, these devices might &lt;EM&gt;not &lt;/EM&gt;progress at the same rate as other devices. Here's the implication:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Devices might &lt;EM&gt;not &lt;/EM&gt;receive updated high-confidence data in May or June.&lt;/LI&gt;
&lt;LI&gt;Some devices might &lt;EM&gt;not &lt;/EM&gt;become eligible for automatic deployment during that time.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In addition, applying Secure Boot updates requires device restarts to complete changes to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Secure Boot certificates&lt;/LI&gt;
&lt;LI&gt;The Windows Boot Manager&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;As a result of this design, devices receiving hotpatch updates will only receive updates automatically during the next baseline month (for example, April or July).&lt;/P&gt;
&lt;P&gt;To move forward sooner, your organization can:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Install the latest monthly non-security preview update (instead of a hotpatch update) to pick up updated high-confidence data.&lt;/LI&gt;
&lt;LI&gt;Restart the devices to complete the update process.&lt;/LI&gt;
&lt;LI&gt;Optional: Temporarily pause hotpatch updates and plan maintenance windows during Secure Boot rollout. Then resume hotpatch updates.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Learn more or bookmark these resources:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/windows/deployment/windows-autopatch/monitor/secure-boot-status-report" target="_blank" rel="noopener"&gt;Secure Boot status report in Windows Autopatch&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://support.microsoft.com/topic/windows-secure-boot-certificate-expiration-and-ca-updates-7ff40d33-95dc-4c3c-8725-a9b95457578e" target="_blank" rel="noopener"&gt;Windows Secure Boot certificate expiration and CA updates&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/secure-boot-playbook-for-certificates-expiring-in-2026/4469235" target="_blank" rel="noopener"&gt;Secure Boot playbook for certificates expiring in 2026&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/windowsservernewsandbestpractices/windows-server-secure-boot-playbook-for-certificates-expiring-in-2026/4495789" target="_blank" rel="noopener"&gt;Windows Server Secure Boot playbook for certificates expiring in 2026&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;P style="font-size: 14px;"&gt;Continue the conversation. Find best practices. Bookmark the &lt;A href="http://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;Windows Tech Community&lt;/A&gt;. Looking for support? Visit &lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;Windows on Microsoft Q&amp;amp;A&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2026 19:50:26 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/updated-secure-boot-status-report-in-windows-autopatch/ba-p/4517920</guid>
      <dc:creator>Harman_Thind</dc:creator>
      <dc:date>2026-05-19T19:50:26Z</dc:date>
    </item>
    <item>
      <title>Admin Insights for Windows 365: Stay on top of what needs attention — now in public preview</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/admin-insights-for-windows-365-stay-on-top-of-what-needs/ba-p/4517570</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;When IT administrators are looking for the most critical actions to take, being able to quickly understand what is happening in their environment can make a big difference.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;With this in mind, we’re excited to announce Admin Insights for Windows 365, now in public preview, designed to help IT administrators quickly understand what’s happening in their environment and where to focus.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To learn more and access technical guidance, visit the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/windows-365/enterprise/admin-insights" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Admin Insights for Windows 365 documentation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Understanding your environment,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;faster&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;IT administrators managing Windows 365 Cloud PCs rely on a range of signals—including reports, alerts, and device views—across the Microsoft Intune admin center to understand the health of their environment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;These signals provide valuable visibility across the Windows 365 environment. As environments scale,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;quickly surfacing what needs attention—and acting on it—becomes more important&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Bringing key signals together&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;in one place&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;img&gt;Insight cards surface signals for review when thresholds are met.&lt;/img&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Admin Insights builds on existing reporting, monitoring, and alerting by bringing important signals together directly into the Windows 365 experience.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;With Admin Insights, IT administrators can:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Identify what needs attention&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;across their Cloud PC environment&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Understand environment health at a glance&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, without digging through multiple reports&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Spot unexpected changes and outliers&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, such as spikes in failures or degraded performance&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Focus on what to do next&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, using signals surfaced in one place&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What powers Admin Insights&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Admin Insights surfaces dynamic insight cards in the Windows 365 management portal in Intune, based on changes and patterns across your Cloud PC environment:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Insight cards are generated automatically&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, based on activity across your environment&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Up to 15 insight cards may be displayed&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, covering general health and outlier conditions&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Cards appear contextually&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, highlighting what needs attention as changes are detected&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Each card maps to a specific scenario&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, such as unhealthy Cloud PCs or connectivity failures&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Get started with Admin Insights&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Admin Insights are available on the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Cloud PC Overview &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;page. Insight cards appear when defined thresholds are met, surfacing key signals.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To learn more, visit the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/windows-365/enterprise/admin-insights" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Admin Insights &lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;for Windows 365 &lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;documentation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;. The feature will continue to extend to new scenarios and Windows 365 surfaces in the Intune portal, providing IT administrators with the information they need, where they need it.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Continue the conversation. Find best practices. Bookmark the &lt;/SPAN&gt;&lt;A href="https://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Tech Community&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, then follow us on &lt;/SPAN&gt; &lt;A href="https://www.linkedin.com/company/windows-it-pro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;or&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://twitter.com/mswindowsitpro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSWindowsITPro&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; for updates. Looking for support? Visit &lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows on Microsoft Q&amp;amp;A&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/admin-insights-for-windows-365-stay-on-top-of-what-needs/ba-p/4517570</guid>
      <dc:creator>madelinecarr</dc:creator>
      <dc:date>2026-05-19T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Easily identify Windows protected print mode compatible devices</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/easily-identify-windows-protected-print-mode-compatible-devices/ba-p/4516897</link>
      <description>&lt;P&gt;As organizations work to modernize their print environments and reduce reliance on legacy drivers, &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows/modern-print/windows-protected-print-mode/windows-protected-print-mode" target="_blank" rel="noopener"&gt;Windows protected print (WPP) mode&lt;/A&gt; helps improve system security by enforcing the use of the &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2362106" target="_blank" rel="noopener"&gt;Windows modern print stack&lt;/A&gt; and introducing &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2361898" target="_blank" rel="noopener"&gt;additional security features&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;To help IT admins and users easily understand which devices are compatible with this more secure printing experience, Windows is introducing a new icon that can be found in &lt;STRONG&gt;Settings &amp;gt; Bluetooth &amp;amp; devices &amp;gt; Printers &amp;amp; scanners&lt;/STRONG&gt;:&lt;/P&gt;
&lt;img&gt;Printer with compatibility icon indicating support for Windows protected print mode.&lt;/img&gt;
&lt;P&gt;This icon appears next to each installed printer that supports Windows protected print mode, which requires IPP-capable printers.&lt;/P&gt;
&lt;P&gt;This update helps IT administrators quickly evaluate printer readiness for Windows protected print mode before enabling it across managed devices. If your environment’s printers support WPP, we highly recommend enabling it to create a more secure print ecosystem.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2362082" target="_blank" rel="noopener"&gt;How to enable WPP locally&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2362800" target="_blank" rel="noopener"&gt;How to enable WPP as group policy&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;Continue the conversation. Find best practices. Bookmark the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Tech Community&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;, then follow us on&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/company/windows-it-pro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;or&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://twitter.com/mswindowsitpro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSWindowsITPro &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;for updates. Looking for support? Visit&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows on Microsoft Q&amp;amp;A&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/easily-identify-windows-protected-print-mode-compatible-devices/ba-p/4516897</guid>
      <dc:creator>elliesekine</dc:creator>
      <dc:date>2026-05-14T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Configuring firewall and proxies for smooth Windows updates</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/configuring-firewall-and-proxies-for-smooth-windows-updates/ba-p/4517913</link>
      <description>&lt;P&gt;Having trouble connecting to Windows Update? If your devices experience difficulties getting updates, you're likely just one step away from the solution. The key is in the configuration of your network endpoints for firewalls and proxies. This post provides actionable guidance on how to identify the cause of the issue and remedy the situation.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;How the Windows Update service and networking interact&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;The Windows Update service makes use of Internet hosted services to widely distribute updates to Windows devices. Windows devices connect to Windows Update services to check for various updates, including monthly security and non-security updates, driver and .NET Framework updates, machine learning (ML) model updates, and more.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Typically, a Windows Update scan occurs automatically or when triggered manually by the user. Once started, the process scans for updates, downloads, and installs them. However, some network configurations obscure this process, leading to errors or the inability to update a device. Luckily, there are measures you can take to avoid this.&lt;/P&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;Security is embedded in the Windows Update experience&lt;/H3&gt;
&lt;P style="margin-top: 16px;"&gt;Security is paramount for Windows Update. Its whole purpose is to help keep your devices protected and productive. Therefore, there are &lt;A href="https://learn.microsoft.com/windows/deployment/update/windows-update-security#securing-metadata-connections" target="_blank"&gt;multiple protections&lt;/A&gt; to ensure that your device connects to authentic Windows Update services. However, there's one specific networking security consideration we'll focus on: &lt;A href="https://learn.microsoft.com/windows-server/security/tls/transport-layer-security-protocol" target="_blank"&gt;Transport Layer Security (TLS)&lt;/A&gt;.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;You probably know TLS (sometimes referred to by an older protocol known as SSL) as the https:// element you type into your browser. This moniker instructs your browser to connect to a web server using HTTP over a TLS connection. Doing so helps ensure the following between your device and a web server:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;The connection is protected from eavesdropping.&lt;/STRONG&gt; It encrypts the data between your device and the server.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;The connection can detect changes made to your data over the network.&lt;/STRONG&gt; It provides integrity checks that your device can validate.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;The connection is trusted.&lt;/STRONG&gt; Your device inspects a TLS “certificate of authenticity” that the server provides to prove who it is.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;When Windows interacts with the Windows Update service, it performs all of these checks. Additionally, it double-checks that the server isn't only trusted, but it's what it claims to be. This is done by verifying that the server's TLS certificate is chained up to a specific certificate authority (CA). Windows refers to this as a Windows Update trust anchor.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;If the TLS certificate isn't issued by an actual Windows Update trust anchor, Windows won't trust that the server is a genuine Windows Update server and immediately disconnects. That's good news until you accidentally lock yourself out of accessing trustworthy Windows Update services.&lt;/P&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;Proxy server and firewall configurations to watch&lt;/H3&gt;
&lt;P style="margin-top: 16px;"&gt;Some networking environments implement special firewalls or proxies that intercept TLS connections. They typically perform TLS inspection, validating that the request to a server is legitimate and adheres to an organization's security and other policies. This is how some firewalls and proxies might block access to forbidden content.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;When TLS inspection occurs in this way, the firewall or proxy server generates its very own certificate. Even though it is generated by the firewall or proxy, it appears to be legitimate (containing SAN entries for the URL's fully qualified domain name) and is trusted by the client's browser. Typically, this involves generating a TLS certificate to match the requested URL and signing it by the organization deploying these firewall/proxy services. Since the client device is a member of the organization, it inherently trusts these certificates signed by the same organization.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;When this occurs, the Windows Update client detects that the TLS certificate issuer isn't a genuine Windows Update issuer. By design, the client only trusts certificates issued by the Windows Update service. This feature of “pinning” solely to TLS certificates issued by the Windows Update service protects the distribution and delivery channels from man-in-the-middle (MITM) attacks. Again, this is good news for your security posture, except when exceptions are needed.&lt;/P&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;The role of VPNs&lt;/H3&gt;
&lt;P style="margin-top: 16px;"&gt;Some virtual private network (VPN) providers block access or DNS lookups to prevent overloading the VPN network with high-volume traffic downloads. That's another potential cause of blocked access for Windows devices. If you're experiencing Windows Update issues over a VPN connection, contact your VPN provider.&lt;/P&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;Care with scripting&lt;/H3&gt;
&lt;P style="margin-top: 16px;"&gt;If you're an avid PowerShell administrator, you might be forcing Windows Update to scan using scripts that call into the Windows Update public API. In this case, these calls might return one of the error codes listed below and add an entry for the error to the Windows Update log. If this happens, remediation steps are the same as if you found them in the Windows Update log.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Note:&amp;nbsp;&lt;/STRONG&gt;The Windows Update protocol is complex and consists of multiple different connections and endpoints. Simply connecting to one of the Windows Update servers doesn't tell the bigger picture of end-to-end protocol success. Rely on API result codes and/or the Windows Update log to determine success.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;How to tell if you're blocked&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;If your Windows device is not receiving Windows updates as you expect, check if your connections are being blocked. Whether the source of the issue is a proxy server, firewall, or VPN, you can use the following steps to troubleshoot and move forward.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;The first thing to check is the &lt;A href="https://learn.microsoft.com/powershell/module/windowsupdate/get-windowsupdatelog?view=windowsserver2025-ps" target="_blank"&gt;Windows Update audit log&lt;/A&gt;. Generate it from PowerShell, running the &lt;STRONG&gt;Get-WindowsUpdateLogs&lt;/STRONG&gt; command:&lt;/P&gt;
&lt;PRE style="margin-top: 16px;"&gt;$output = "$env:TEMP\WindowsUpdate.log"&lt;BR /&gt;Get-WindowsUpdateLog -LogPath $output&lt;BR /&gt;Write-Host "Windows Update log written to $output"&lt;/PRE&gt;
&lt;P style="margin-top: 16px;"&gt;Once you have the log file, look for any of the following error codes:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;0x8024402c&lt;/STRONG&gt; (decimal: -2145107924)&lt;BR /&gt;This is the &lt;STRONG&gt;WU_E_PT_WINHTTP_NAME_NOT_RESOLVED&lt;/STRONG&gt; error. It means that the Windows device was unable to resolve the Windows Update server DNS name to an IP address. Your organization might be blocking Fully Qualified Domain Name (FQDN) to IP address resolution.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;0x80240438&lt;/STRONG&gt; (decimal: -2145123272)&lt;BR /&gt;This is the &lt;STRONG&gt;WU_E_PT_ENDPOINT_UNREACHABLE&lt;/STRONG&gt; error. You receive this if the FQDN has been properly resolved to an IP address, but the Windows device is unable to connect to the server. This is probably due to a firewall or proxy blocking access.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;0x80245006&lt;/STRONG&gt; (decimal: -2145103866)&lt;BR /&gt;This is the &lt;STRONG&gt;WU_E_REDIRECTOR_INVALID_RESPONSE&lt;/STRONG&gt; error. This can show up for several reasons. For the sake of this discussion, it typically means one of the following:
&lt;UL&gt;
&lt;LI&gt;Your connection with the Windows Update service was unable to procure data it needs. For example, your connection might have dropped during the client-server interaction. In this case, check that your connection to the Internet is stable and not dropping.&lt;/LI&gt;
&lt;LI&gt;Your device was unable to validate the server's TLS certificate via trust anchor certificate pinning. This is most likely the case if your firewall or proxy is performing TLS inspection.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;0x80240437&lt;/STRONG&gt; (decimal: -2145123273)&lt;BR /&gt;This is the &lt;STRONG&gt;WU_E_PT_SECURITY_VERIFICATION_FAILURE&lt;/STRONG&gt; error. Your device was unable to prove that the connected server is legitimate and genuine Windows Update. Similar to the WU_E_REDIRECTOR_INVALID_RESPONSE error, your device couldn't validate the server's TLS certificate via trust anchor certificate pinning. Again, check if your firewall or proxy is performing TLS inspection.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;If your log shows any of these error codes, work with your IT team to help ensure that firewalls and proxies are properly allowing Windows Update connections. In some cases, VPNs may be blocking FQDN resolutions or connections to the Windows Update service. If you're using a VPN, check with the VPN provider.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Recommended configurations and exceptions&lt;/H2&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;A trusted connection requires trusted subdomains&lt;/H3&gt;
&lt;P style="margin-top: 16px;"&gt;To ensure that Windows devices can properly access genuine Windows Update services, firewalls and proxies need to allow those connections to pass through uninterrupted. That is to say, without generating and using its own TLS certificate.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;To do this, proxies and firewalls need to create “pass through” exceptions for these Windows Update connections. This is typically done by allow-listing specific Windows-Update-related DNS host names. There are several of these qualified DNS names (FQDN) that you need to accommodate. You can learn more about the FQDNs requiring these exceptions in the Windows Update sections of the following:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/windows/privacy/manage-windows-11-endpoints" target="_blank"&gt;Connection endpoints for Windows 11 Enterprise&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/windows/privacy/windows-11-endpoints-non-enterprise-editions" target="_blank"&gt;Windows 11 connection endpoints for non-Enterprise editions&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;Note that for the FQDNs related to Windows Update, the * wildcard is recursive. For security and scalability purposes, host and DNS subdomain names might need to periodically change.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;For example, here's a recommended DNS host name:&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;&lt;STRONG&gt;*.update.microsoft.com&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;It represents all of the following hosts and subdomains:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;update.microsoft.com&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;sls.&lt;STRONG&gt;update.microsoft.com&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;tas02.sls.&lt;STRONG&gt;update.microsoft.com&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;This means that you should trust all the DNS hosts and subdomains related to wildcard FQDN for the connection to work properly. Check if these subdomains are missing. In many cases, it should only take you a few minutes to update your proxy and firewall configurations to include them.&lt;/P&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;A special case of WSUS servers&lt;/H3&gt;
&lt;P style="margin-top: 16px;"&gt;Do you use Windows Server Update Services (WSUS) in your networks? In this environment, instead of connecting to the Windows Update service directly, Windows devices connect to an IT-managed WSUS server. If you're a server administrator, you orchestrate which updates are available on the WSUS server for your devices to update. And since these devices don't need to traverse a proxy or firewall for a genuine Windows Update server, the FQDN exceptions aren't necessary.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;You can require TLS connections between your devices and the WSUS server. Additionally, you have the option to certificate-pin the WSUS server to your TLS certificates, much like you do with Windows Update. To use this option, you might need to make proper proxy or firewall exceptions for any device connecting to your TLS, certificate-pinned WSUS server. To learn more about WSUS certificate pinning, see:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/scan-changes-and-certificates-add-security-for-windows-devices-using-wsus-for-up/2053668" target="_blank"&gt;Scan changes and certificates add security for Windows devices using WSUS for updates&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/intune/configmgr/sum/get-started/software-update-point-ssl" target="_blank"&gt;Configure a software update point to use TLS/SSL with a PKI certificate&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;An easy fix is good news&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Difficulties keeping Windows devices up to date with the latest updates might have to do with the embedded network security design. Windows Update doesn't trust servers that don't have TLS certificates issued by an actual Windows Update trust anchor. Your firewalls and proxies might block access to the trustworthy and necessary Windows Update service if your configuration is either intercepting TLS connections or isn't passing TLS requests through for the necessary DNS subdomains. The good news is that there's normally an easy fix for Windows Update connection issues. Essentially, make sure to trust FQDN subdomains of the recommended DNS subdomains.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Here are some resources to help you learn even more:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/windows/security/book/operating-system-security-network-security" target="_blank"&gt;Windows 11 Security Book: Network security&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/windows-server/networking/dns/dns-overview" target="_blank"&gt;What is Domain Name System (DNS)?&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/windows/deployment/update/how-windows-update-works" target="_blank"&gt;How Windows Update works&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;P style="font-size: 14px;"&gt;Continue the conversation. Find best practices. Bookmark the &lt;A href="http://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;Windows Tech Community&lt;/A&gt;. Looking for support? Visit &lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;Windows on Microsoft Q&amp;amp;A&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/configuring-firewall-and-proxies-for-smooth-windows-updates/ba-p/4517913</guid>
      <dc:creator>Dave_Roth</dc:creator>
      <dc:date>2026-05-11T16:00:00Z</dc:date>
    </item>
  </channel>
</rss>

