<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Windows IT Pro Blog articles</title>
    <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/bg-p/Windows-ITPro-blog</link>
    <description>Windows IT Pro Blog articles</description>
    <pubDate>Mon, 08 Jun 2026 23:18:58 GMT</pubDate>
    <dc:creator>Windows-ITPro-blog</dc:creator>
    <dc:date>2026-06-08T23:18:58Z</dc:date>
    <item>
      <title>Teams Remote App/ Cloud App optimization for Windows 365 and Azure Virtual Desktop now GA</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/teams-remote-app-cloud-app-optimization-for-windows-365-and/ba-p/4515930</link>
      <description>&lt;P&gt;Today, we are announcing the general availability of Microsoft Teams for Remote App scenarios, expanding support for optimized Microsoft Teams experiences when connecting to Azure Virtual Desktop. Additionally, Cloud Apps for Windows 365 will also be supported. This update introduces a new media engine that replaces the legacy WebRTC-based optimization.&lt;/P&gt;
&lt;H4&gt;Optimized Teams experience for Remote App&lt;/H4&gt;
&lt;P&gt;The new optimization improves audio and video performance, reliability, and security, and simplifies ongoing support by enabling media engine updates without frequent upgrades to the infrastructure or client.&lt;/P&gt;
&lt;P&gt;This feature will be available to anyone using Microsoft Teams as a Remote App on Azure Virtual Desktop or Cloud Apps on Windows 365 from Windows endpoints.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Teams users running in Remote App will automatically transition to the new optimization: &lt;/LI&gt;
&lt;/UL&gt;
&lt;img /&gt;
&lt;UL&gt;
&lt;LI&gt;Audio and video performance and reliability are improved compared to the legacy WebRTC optimization.&lt;/LI&gt;
&lt;LI&gt;Media engine updates no longer require frequent upgrades to the VDI infrastructure or client.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Note: Give and Take control is not supported at this time.&lt;/P&gt;
&lt;H4&gt;Try the optimized Teams experience for Remote App and Cloud Apps today&lt;/H4&gt;
&lt;P&gt;If you are using Windows App on Windows, you can try it today by meeting the following requirements:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;On the user device, use Windows App for Windows version 2.0.964.0 or later&lt;/LI&gt;
&lt;LI&gt;On the remote VM, install Microsoft Teams version 26043.2016.4478.2773 or later&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Learn more: &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/microsoftteams/vdi-2#remoteapp" target="_blank" rel="noopener"&gt;New VDI solution for Teams | Microsoft Teams | Microsoft Learn&lt;/A&gt;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Continue the conversation. Find best practices. Bookmark the &lt;/SPAN&gt;&lt;A href="https://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Tech Community&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, then follow us on &lt;/SPAN&gt;&amp;nbsp;&lt;A href="https://www.linkedin.com/company/windows-it-pro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;or&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://twitter.com/mswindowsitpro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSWindowsITPro&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; for updates. Looking for support? Visit &lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows on Microsoft Q&amp;amp;A&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2026 18:45:09 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/teams-remote-app-cloud-app-optimization-for-windows-365-and/ba-p/4515930</guid>
      <dc:creator>PavithraT</dc:creator>
      <dc:date>2026-06-04T18:45:09Z</dc:date>
    </item>
    <item>
      <title>Adaptive data protection with context-based redirections in Windows 365, now in public preview</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/adaptive-data-protection-with-context-based-redirections-in/ba-p/4521366</link>
      <description>&lt;P&gt;Today, we are excited to announce the public preview of &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-conditional-access-cloud-apps?tabs=powershell#authentication-context" target="_blank" rel="noopener"&gt;context-based redirections&lt;/A&gt; for Windows App. This new capability helps organizations apply more granular controls to device and resource redirection based on contextual signals such as device management state, compliance posture, user or group membership, and network conditions. The result is a more adaptive way to help users stay productive while reducing the risk of data leaving the protected Windows environment.&lt;/P&gt;
&lt;P&gt;Context-based redirections are part of our broader secure bring-your-own-device (BYOD) strategy. Instead of relying only on a one-size-fits-all redirection policy, admins can use Microsoft Entra Conditional Access authentication context with Windows 365 and Azure Virtual Desktop redirection settings to make redirection decisions that better match the trust level of the session.&lt;/P&gt;
&lt;H4&gt;Why context matters for redirection&lt;/H4&gt;
&lt;P&gt;Redirections control important data paths between the local device and the remote session. In BYOD scenarios, an unmanaged or noncompliant device may not meet the same security standard as a corporate-managed endpoint. Context-based redirections help admins align these data paths with policy intent: enable what users need when the session is trusted and restrict higher-risk redirections when the session is not.&lt;/P&gt;
&lt;P&gt;This builds on the existing Windows App and RDP security model where the more restrictive setting takes precedence. For example, if one policy allows a redirection but another security layer disables it, the redirection remains disabled. The most restrictive wins behavior, helping provide defense in depth and reducing the chance that a configuration gap becomes a data loss path.&lt;/P&gt;
&lt;H4&gt;What is in scope for public preview&lt;/H4&gt;
&lt;P&gt;In this public preview, the core scenarios are centered on:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Clipboard redirection: Control whether clipboard data can move between the local device and the remote Windows session.&lt;/LI&gt;
&lt;LI&gt;Drive and storage redirection: Control access to local fixed, removable, and network storage from the remote session.&lt;/LI&gt;
&lt;LI&gt;Printer redirection: Control whether users can print from the remote session to local printers.&lt;/LI&gt;
&lt;LI&gt;USB redirection: Control whether supported USB devices can be redirected into the remote session.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Context-based redirection will be supported across Windows, web, Android, iOS, and macOS Windows App clients and through a dedicated VM session.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; We are currently &lt;STRONG&gt;developing&lt;/STRONG&gt; the feature Resultant Set of Policy (RSOP) that will help users and IT admins determine which redirections settings were applied to this connection and which policy source produced this value.&lt;/P&gt;
&lt;H4&gt;Prerequisites&lt;/H4&gt;
&lt;P&gt;&lt;STRONG&gt;Note: &lt;/STRONG&gt;If you’re testing with a recent gallery image or already have policies in your environment that disable redirections, update those settings before testing, as the most restrictive policy always applies. For context-based redirection to function properly, configure the redirections you want to test as “Not Configured” or “Enabled.”&lt;/P&gt;
&lt;P&gt;To simplify testing and rollout, we recommend creating a dedicated device group for pilot Cloud PCs. This allows you to target only test devices with these settings and later reuse the same group when deploying your context-based redirection policy more broadly.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;For more information, please visit&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows-365/enterprise/manage-rdp-device-redirections#use-the-settings-catalog-to-manage-rdp-device-redirections" target="_blank" rel="noopener"&gt;Manage device RDP redirections for Cloud PCs. | Microsoft Learn&lt;/A&gt;.&lt;/P&gt;
&lt;H4&gt;Get started&lt;/H4&gt;
&lt;P&gt;To get started with context-based redirections, admins will first create an Entra authentication context, then create an Entra Conditional Access to issue the authentication context.&lt;/P&gt;
&lt;P&gt;Once the authentication context and Conditional Access policy are in place, admins can configure the Windows 365 Remote Connection Experience setting policy to require the specified authentication context for the targeted redirections.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;H4&gt;Validating the provisioned context-based redirection policy&lt;/H4&gt;
&lt;P&gt;To validate whether the provisioned context-based redirection policy is working as intended, test it from the user perspective by connecting to a Windows 365 Cloud PC/Azure Virtual Desktop VM that’s associated with the targeted device group:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Use any Windows App client. You can use the Windows web client by going to &lt;A class="lia-external-url" href="https://windows.cloud.microsoft" target="_blank" rel="noopener"&gt;windows.cloud.microsoft&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;Find the targeted, managed Windows 365 Cloud PC/Azure Virtual Desktop VM and click the "Connect" button.&lt;/LI&gt;
&lt;LI&gt;Once the remote session loads, verify the behavior of the 4 redirections. Please visit each redirection’s respective Microsoft Learn documentations for detailed testing instructions:
&lt;OL&gt;
&lt;LI&gt;Clipboard redirection: Verify whether copy and paste work between the local device and remote session.&lt;/LI&gt;
&lt;LI&gt;Drive redirection enabled: &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/azure/virtual-desktop/redirection-configure-drives-storage?tabs=intune&amp;amp;pivots=windows-365#test-drive-redirection" target="_blank" rel="noopener"&gt;Configure fixed, removable, and network drive redirection over the Remote Desktop Protocol | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Printer redirection: &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/azure/virtual-desktop/redirection-configure-printers?tabs=intune&amp;amp;pivots=windows-365#test-printer-redirection" target="_blank" rel="noopener"&gt;Configure printer redirection over the Remote Desktop Protocol | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;USB redirection enabled: &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/azure/virtual-desktop/redirection-configure-usb?tabs=intune&amp;amp;pivots=windows-365#test-usb-redirection" target="_blank" rel="noopener"&gt;Configure USB redirection on Windows over the Remote Desktop Protocol | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Continue the conversation. Find best practices. Bookmark the &lt;/SPAN&gt;&lt;A href="https://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Tech Community&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, then follow us&amp;nbsp;on &amp;nbsp;&lt;A href="https://www.linkedin.com/company/windows-it-pro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;or&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://twitter.com/mswindowsitpro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSWindowsITPro&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; for updates. Looking for support? Visit &lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows on Microsoft Q&amp;amp;A&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2026 19:15:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/adaptive-data-protection-with-context-based-redirections-in/ba-p/4521366</guid>
      <dc:creator>Derek_Su</dc:creator>
      <dc:date>2026-06-02T19:15:00Z</dc:date>
    </item>
    <item>
      <title>Reducing NTLM Dependency: IAKerb and LocalKDC in Windows Insider Preview</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/reducing-ntlm-dependency-iakerb-and-localkdc-in-windows-insider/ba-p/4524615</link>
      <description>&lt;P&gt;Today, Windows expands where Kerberos works—reducing the need for NT LAN Manager (NTLM) fallback with&lt;STRONG&gt; IAKerb&lt;/STRONG&gt; and &lt;STRONG&gt;LocalKDC&lt;/STRONG&gt;, coming to &lt;A class="lia-external-url" href="https://www.microsoft.com/en-us/windowsinsider/?msockid=1d672a5faaaf6d8d23183cf4abdb6cd9" target="_blank" rel="noopener"&gt;client&lt;/A&gt; and &lt;A class="lia-external-url" href="https://www.microsoft.com/en-us/software-download/windowsinsiderpreviewserver?msockid=1d672a5faaaf6d8d23183cf4abdb6cd9" target="_blank" rel="noopener"&gt;server&lt;/A&gt; &lt;STRONG&gt;public preview later this month&lt;/STRONG&gt; for &lt;STRONG&gt;Windows Insiders in the Canary Channel&lt;/STRONG&gt;. These capabilities extend Kerberos authentication to scenarios that previously required NTLM, helping organizations reduce their dependency on legacy protocols. For developers, this means more authentication flows can rely on modern, Kerberos-based identity (even in environments that previously required legacy protocols), reducing the need for application workarounds and helping ensure consistent behavior across managed and unmanaged environments.&lt;/P&gt;
&lt;H5&gt;With this release:&lt;/H5&gt;
&lt;UL&gt;
&lt;LI&gt;IAKerb will be enabled by default&lt;/LI&gt;
&lt;LI&gt;LocalKDC will be disabled by default&lt;/LI&gt;
&lt;LI&gt;Both features will be configurable through registry keys&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Note: For this public preview, configuration is exposed through registry settings so you can evaluate these capabilities in Insider environments. Management surfaces, such as Group Policies and MDM-based management, will be introduced as these capabilities mature.&lt;/P&gt;
&lt;H4&gt;Why this matters&lt;/H4&gt;
&lt;P&gt;For many organizations, moving away from NTLM is a security priority. But in practice, NTLM often remains in use because there are still real-world scenarios where traditional Kerberos cannot be used directly, such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Devices that do not have direct line-of-sight to a domain controller&lt;/LI&gt;
&lt;LI&gt;Authentication flows involving local accounts&lt;/LI&gt;
&lt;LI&gt;Standalone or workgroup environments&lt;/LI&gt;
&lt;LI&gt;Network topologies where Kerberos reachability is limited&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;IAKerb and LocalKDC address many of these gaps (though not all) by extending Kerberos support, reducing reliance on NTLM fallback across customer environments.&lt;/P&gt;
&lt;H4&gt;What is IAKerb?&lt;/H4&gt;
&lt;P&gt;&lt;STRONG&gt;IAKerb&lt;/STRONG&gt; (Initial and Pass-Through Authentication using Kerberos) enables Kerberos to work when the initiating device (Kerberos client) does not have direct connectivity to a domain controller. In a traditional Kerberos flow, the client must communicate directly with a domain controller to obtain the tickets needed for authentication. In some environments, that path is not available even though the client can still reach the target service. In those cases, IAKerb enables the target service to act as a proxy for the Kerberos exchange, allowing authentication to stay on a Kerberos-based path rather than falling back to NTLM.&lt;/P&gt;
&lt;P&gt;This makes IAKerb especially useful in environments with:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Network segmentation&lt;/LI&gt;
&lt;LI&gt;Restricted domain controller visibility&lt;/LI&gt;
&lt;LI&gt;Remote or cloud-connected access patterns&lt;/LI&gt;
&lt;LI&gt;Architectures where clients can reach services but not DCs directly&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;What is LocalKDC?&lt;/H4&gt;
&lt;P&gt;&lt;STRONG&gt;LocalKDC&lt;/STRONG&gt; is a local Key Distribution Center implementation in Windows that enables Kerberos-based authentication for local account scenarios. Historically, local account authentication across machines has often depended on NTLM. LocalKDC helps close that gap by allowing Windows to use Kerberos semantics for local identity scenarios that would otherwise require legacy authentication. This is especially relevant for scenarios such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Workgroup environments&lt;/LI&gt;
&lt;LI&gt;Standalone devices&lt;/LI&gt;
&lt;LI&gt;Local account access to remote resources&lt;/LI&gt;
&lt;LI&gt;Peer-to-peer or small-scale environments without domain infrastructure&lt;/LI&gt;
&lt;LI&gt;Administrative or file access scenarios where local identities are used&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;How these features fit together&lt;/H4&gt;
&lt;P&gt;IAKerb and LocalKDC address different but complementary gaps in Windows authentication, reducing reliance on NTLM across both enterprise and local identity scenarios.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;IAKerb&lt;/STRONG&gt; is meant for enterprise and corporate environments, where domain credentials are used but Kerberos authentication cannot always complete because the client lacks direct line of sight to a domain controller. By allowing authentication to remain on a Kerberos-based path in these situations, IAKerb helps reduce NTLM usage for high-value corporate credentials . This is important because reducing the use of NTLM for enterprise credentials helps strengthen defenses against credential theft and relay-based attack paths, including forms of lateral movement that have historically relied on NTLM fallback.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;LocalKDC&lt;/STRONG&gt; addresses a different class of scenarios: local and non-domain identities, including workgroup, standalone, and local account access patterns. In these cases, LocalKDC helps bring Kerberos-based protections to scenarios that traditionally depended on NTLM for local credentials.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Together, these capabilities extend Kerberos in two directions: domain-based enterprise credentials, and local and consumer-style account scenarios, further reducing the exposure to credential theft and relay-based attacks. This matters because, as part of a broader shift toward modern and enforced authentication, simply disabling older protocols is not enough. Organizations also need secure, reliable authentication that works consistently, without falling back to legacy protocols. These features help deliver that by providing modern, compatible alternatives that reflect how customers operate today.&lt;/P&gt;
&lt;H4&gt;Registry Configuration:&lt;/H4&gt;
&lt;P&gt;For this public preview, &lt;STRONG&gt;IAKerb&lt;/STRONG&gt; and &lt;STRONG&gt;LocalKDC&lt;/STRONG&gt; can be configured using registry settings under:&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;The supported values for this preview are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;DisableIAKerb&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;DisableLocalKDC&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Set the value to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;0&lt;/STRONG&gt; to enable the feature&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;1&lt;/STRONG&gt; to disable the feature&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Note: If a registry value is &lt;STRONG&gt;not present&lt;/STRONG&gt;, Windows uses the &lt;STRONG&gt;default behavior for that release&lt;/STRONG&gt;. In this preview, the defaults are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;IAKerb:&lt;/STRONG&gt; enabled by default (0)&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;LocalKDC: &lt;/STRONG&gt;disabled by default (1)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This gives you flexibility to evaluate the features in Insider environments while controlling rollout and validation according to your needs.&lt;/P&gt;
&lt;H4&gt;What you can do now&lt;/H4&gt;
&lt;P&gt;With this public preview, customers participating in the Canary Channel can test these capabilities in preview environments and validate the scenarios where NTLM is still commonly used. These features are designed to address important NTLM fallback scenarios but will not eliminate every remaining NTLM dependency in Windows environments; some scenarios may still require NTLM based on application behavior, infrastructure assumptions, or legacy dependencies. Our goal with this preview is to close some of the key gaps by extending Kerberos to more scenarios, while continuing broader work to reduce NTLM dependency across the platform over time. Once available, you can use this preview to help:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Identify scenarios already covered by IAKerb or LocalKDC&lt;/LI&gt;
&lt;LI&gt;Validate those scenarios in controlled environments, and use the documented configuration options to control enablement during testing&lt;/LI&gt;
&lt;LI&gt;Understand where NTLM dependencies still remain using our enhanced NTLM Auditing&lt;/LI&gt;
&lt;LI&gt;Check for dependencies such as name resolution, SPN configuration, or legacy assumptions&lt;/LI&gt;
&lt;LI&gt;Prepare for future improvements that will address additional cases&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;We also recommend evaluating the following areas:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Access to SMB shares&lt;/LI&gt;
&lt;LI&gt;Remote administration scenarios&lt;/LI&gt;
&lt;LI&gt;Environments with limited or no direct Domain Controller (DC) connectivity&lt;/LI&gt;
&lt;LI&gt;Workgroup or standalone device authentication&lt;/LI&gt;
&lt;LI&gt;Local account access patterns&lt;/LI&gt;
&lt;LI&gt;Scenarios being prepared for NTLM reduction or eventual NTLM blocking&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This preview is an opportunity to validate application compatibility, infrastructure dependencies, and operational readiness before broader rollout decisions are made. Learn more about upcoming work in this space here: &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/advancing-windows-security-disabling-ntlm-by-default/4489526" target="_blank" rel="noopener" data-lia-auto-title="Advancing Windows security: Disabling NTLM by default - Windows IT Pro Blog" data-lia-auto-title-active="0"&gt;Advancing Windows security: Disabling NTLM by default - Windows IT Pro Blog&lt;/A&gt;.&lt;/P&gt;
&lt;H4&gt;Troubleshooting and Feedback&lt;/H4&gt;
&lt;P&gt;As you evaluate IAKerb and LocalKDC in preview environments, you may encounter scenarios where authentication behaves differently than expected. Windows provides &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/troubleshoot/windows-server/windows-security/kerberos-authentication-troubleshooting-guidance" target="_blank" rel="noopener"&gt;built-in logging&lt;/A&gt; to help you understand what is happening and identify potential issues. These logs help you:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Verify whether Kerberos authentication is being used&lt;/LI&gt;
&lt;LI&gt;Identify cases where IAKerb or LocalKDC is involved&lt;/LI&gt;
&lt;LI&gt;Detect failures or fallback conditions&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;You can also leverage &lt;A class="lia-external-url" href="https://support.microsoft.com/en-us/topic/overview-of-ntlm-auditing-enhancements-in-windows-11-version-24h2-and-windows-server-2025-b7ead732-6fc5-46a3-a943-27a4571d9e7b" target="_blank" rel="noopener"&gt;NTLM operational logs&lt;/A&gt; to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Identify when NTLM is still being used&lt;/LI&gt;
&lt;LI&gt;Understand why fallback to NTLM is occurring&lt;/LI&gt;
&lt;LI&gt;Prioritize scenarios for further investigation&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Reviewing these logs together can help you determine whether authentication is staying on a Kerberos path (via IAKerb or LocalKDC) or falling back to NTLM and why.&lt;/P&gt;
&lt;H5&gt;When to expect fallback behavior&lt;/H5&gt;
&lt;P&gt;Because this is a preview release, some scenarios may still fall back to NTLM due to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Application-specific dependencies&lt;/LI&gt;
&lt;LI&gt;Environmental configuration (e.g., name resolution or SPN issues)&lt;/LI&gt;
&lt;LI&gt;Interactions between domain accounts and local accounts on the same machine&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;IAKerb and LocalKDC are designed to address a subset of common NTLM fallback scenarios, and continued improvements are planned to expand coverage over time.&lt;/P&gt;
&lt;H5&gt;Share feedback and scenarios&lt;/H5&gt;
&lt;P&gt;If you encounter a scenario that does not behave as expected, or if you have a unique authentication flow you would like us to evaluate, we encourage you to contact us at &lt;A class="lia-external-url" href="mailto:ntlm@microsoft.com" target="_blank" rel="noopener"&gt;ntlm@microsoft.com&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Please include details such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The scenario you are testing&lt;/LI&gt;
&lt;LI&gt;Expected vs. actual behavior&lt;/LI&gt;
&lt;LI&gt;Relevant event log entries (if available)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Your feedback is critical to helping us improve coverage and ensure these capabilities work reliably across real-world environments.&lt;/P&gt;
&lt;H4&gt;Securing today. Preparing for what’s next.&lt;/H4&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Security in Windows is built into the platform—continuously maintained and designed to evolve as threats change.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Learn more in the &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows/security/book/" target="_blank" rel="noopener"&gt;Windows Security book &lt;/A&gt;and &lt;A class="lia-external-url" href="https://aka.ms/ws2025securitybook" target="_blank" rel="noopener"&gt;Windows Server Security book&lt;/A&gt; or explore &lt;A class="lia-external-url" href="https://www.microsoft.com/en-us/windows/business" target="_blank" rel="noopener"&gt;Windows 11&lt;/A&gt;, &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows-server/" target="_blank" rel="noopener"&gt;Windows Server&lt;/A&gt;, and &lt;A class="lia-external-url" href="https://www.microsoft.com/en-us/windows/business/devices/copilot-plus-pcs" target="_blank" rel="noopener"&gt;Copilot+ PCs&lt;/A&gt;. For broader solutions, visit the &lt;A class="lia-external-url" href="https://www.microsoft.com/en-us/security/business" target="_blank" rel="noopener"&gt;Microsoft Security site&lt;/A&gt;, follow the Security blog, or connect with &lt;A class="lia-external-url" href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;Microsoft Security&lt;/A&gt; on LinkedIn and &lt;A class="lia-external-url" href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;@MSFTSecurity&lt;/A&gt;.   &lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2026 16:32:15 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/reducing-ntlm-dependency-iakerb-and-localkdc-in-windows-insider/ba-p/4524615</guid>
      <dc:creator>mariam_gewida</dc:creator>
      <dc:date>2026-06-02T16:32:15Z</dc:date>
    </item>
    <item>
      <title>Made for developers and agents, Windows 365 at Build 2026</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/made-for-developers-and-agents-windows-365-at-build-2026/ba-p/4519041</link>
      <description>&lt;P&gt;Build 2026 is here, and Windows 365 is showing up in a&lt;STRONG&gt; BIG&lt;/STRONG&gt; way. Over the past year, we’ve listened closely to developers and IT teams using Cloud PCs at scale. You told us that bringing a new developer onto a Cloud PC needs to be streamlined—that signing in should mean being ready to code, not spending hours on setup. We hear from you that compute choice matters, and that a one-size-fits-all approach doesn’t work for dev teams building everything from web apps to AI/ML workloads. In addition, you told us that agents are already in use—and they need a real place to run, backed by the same security, identity, and policy you trust. Today, we’re announcing our biggest release yet of developer and agent capabilities on Windows 365. It brings secure Cloud PCs preconfigured with common development tools, expanded compute options, a new platform for enterprise AI agents, and stronger security and connectivity—so you can build and scale from anywhere, on any device.&lt;/P&gt;
&lt;H4&gt;A development experience that starts ready&lt;/H4&gt;
&lt;P&gt;Every developer knows this story: a new machine, a fresh image—and hours lost to setup before a single line of code gets written. That friction repeats with every onboarding, project switch, and refresh. We’re solving it with ready-to-code Windows 365 Cloud PCs, enhanced image management, and flexible customization—so developers can get to coding faster.&lt;/P&gt;
&lt;P&gt;With &lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/dev-box/dev-box-roadmap" target="_blank" rel="noopener"&gt;Microsoft Dev Box now in maintenance mode&lt;/A&gt;, Windows 365 is the forward-looking path at Microsoft for teams seeking to standardize developer environments on Cloud PCs, backed by an investment roadmap focused on developer productivity, AI workloads, and enterprise scale.&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/windows-365/enterprise/device-images" target="_blank" rel="noopener"&gt;Windows 365 now supports Windows 11 developer configuration image&lt;/A&gt;, in public preview: It delivers a preconfigured, ready‑to‑code environment with tools developers already use, including Visual Studio Code, Git, GitHub CLI, Python, Node.js, and Windows Subsystem for Linux (WSL), available from first sign‑in. Developers can navigate across Windows and Linux (via WSL), local and cloud, and AI workloads, all from the same starting point.&lt;/P&gt;
&lt;DIV class="lia-embeded-content" contenteditable="false"&gt;&lt;IFRAME src="https://www.youtube.com/embed/3wNoOKTxxy0?si=_wwwidYDS4Min3lB" width="560" height="315" title="YouTube video player" allowfullscreen="allowfullscreen" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" frameborder="0" sandbox="allow-scripts allow-same-origin allow-forms"&gt;&lt;/IFRAME&gt;&lt;/DIV&gt;
&lt;P style="font-size: 0.85em; color: #666;"&gt;Video caption: With GitHub remote capabilities enabled on your Cloud PC, you can monitor and manage a running CLI session from another endpoint, such as your local device, as demonstrated in this video.&lt;/P&gt;
&lt;P&gt;Building on this,&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows-365/enterprise/autopilot-device-preparation" target="_blank" rel="noopener"&gt;autopilot device preparation&lt;/A&gt; now available for Windows 365, automates the installation of apps and scripts on Cloud PCs through Microsoft Intune before a user ever signs in. This helps ensure a ready-to-use, compliant environment without manual setup. Coming soon in preview, we will introduce expanded customization capabilities that give teams greater flexibility to tailor Cloud PC environments to their project needs, including configuring required SDKs, CLIs, packages, build tools, repositories, and onboarding workflows, all while remaining within enterprise guardrails and enabling developers to get productive immediately. In addition, &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows-365/enterprise/add-device-images" target="_blank" rel="noopener"&gt;Azure Compute Gallery&lt;/A&gt; support is now generally available. This enables organizations to store and manage custom images in Azure Compute Gallery and import them into Windows 365 to create Cloud PCs.&lt;/P&gt;
&lt;P&gt;For developers building AI‑powered apps, &lt;A class="lia-external-url" href="https://aka.ms/W365LMLocal" target="_blank" rel="noopener"&gt;select language models (LM) now run directly on your Windows 365 Cloud PC&lt;/A&gt;, extending this ready-to-code experience to advanced workloads. and enabling developers to build and iterate on LM-driven applications using Cloud PC compute.&lt;/P&gt;
&lt;H4&gt;Flexible plans to choose from&lt;/H4&gt;
&lt;P&gt;As part of ongoing Windows 365 portfolio update, &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/windows-365-and-azure-virtual-desktop-expanding-access/4515931" target="_blank" rel="noopener" data-lia-auto-title="Windows 365 Flex, formerly known as Windows 365 Frontline" data-lia-auto-title-active="0"&gt;Windows 365 Flex, formerly known as Windows 365 Frontline&lt;/A&gt;, fits how employees work, whether through shared access or cost-efficient dedicated experiences.&lt;/P&gt;
&lt;P&gt;And that flexibility shows up in compute choice. &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows-365/enterprise/cloud-pc-size-recommendations?source=recommendations" target="_blank" rel="noopener"&gt;32vCPU Windows 365 Cloud PCs&lt;/A&gt; are now available in Windows 365 Enterprise and Windows 365 Flex, supporting compute-intensive workloads like software development, data modeling, simulations, and AI/ML. Similarly, a new &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows-365/enterprise/gpu-cloud-pc" target="_blank" rel="noopener"&gt;Windows 365 GPU Select&lt;/A&gt; plan is now available, expanding the Windows 365 GPU-enabled Cloud PC portfolio and giving developers a more accessible GPU option alongside the existing Standard, Super, and Max plans. The new capabilities are optimized for smooth, low-latency visual performance across applications, multimedia, and hardware accelerated graphic workflows, providing developers with more ways to accelerate build and test scenarios. All GPU-enabled Cloud PCs are available across both Windows 365 Enterprise and Windows 365 Flex (in shared or dedicated mode).&lt;/P&gt;
&lt;H4&gt;Enterprise-managed execution environment for AI agents&lt;/H4&gt;
&lt;P&gt;As AI agents move from reasoning to execution, a key challenge is enabling them to take action across enterprise applications and systems, not just APIs. Many enterprise workflows still depend on browsers, desktop applications, and legacy tools, which require agents to operate beyond traditional integration points.&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="http://www.aka.ms/W365AHome" target="_blank" rel="noopener"&gt;Windows 365 for Agents&lt;/A&gt; is now generally available. Agent makers can use it as part of Agent 365 tools or through Microsoft Copilot Studio (preview). It enables enterprise AI automation by providing agents with secured, managed, and available Cloud PCs that run within real business environments. Agents can interact directly with applications and browsers, execute multi-step workflows, and operate across modern and legacy systems. Each Cloud PC is Entra-joined, Intune-managed, and policy-enforced, helping IT scale agents with consistent security, governance, and compliance. While Agent 365 secures and governs the agent, Windows 365 for Agents provides a dedicated workspace to support performance and security needs.&lt;/P&gt;
&lt;P&gt;Designed to support agent creators, Windows 365 for Agents works with agents built using both no-code and pro-code approaches. It's already powering agentic experiences across Microsoft, from computer-use scenarios in Researcher to Project Opal within Microsoft Copilot Studio, demonstrating enterprise readiness. Beyond Microsoft’s own experiences, the platform also supports third-party agents, including partner-provided examples such as Sai from Simular. This always-on AI coworker can operate applications on a Windows Cloud PC by interacting with the user interface through mouse and keyboard inputs, similar to a human.&lt;/P&gt;
&lt;P&gt;Watch Simular’s AI agent Sai in action in the demo below.&lt;/P&gt;
&lt;DIV class="lia-embeded-content" contenteditable="false"&gt;&lt;IFRAME src="https://www.youtube.com/embed/LQL6KA6lJus?si=2VBgbDVYHzasfkSu" width="560" height="315" title="YouTube video player" allowfullscreen="allowfullscreen" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" frameborder="0" sandbox="allow-scripts allow-same-origin allow-forms"&gt;&lt;/IFRAME&gt;&lt;/DIV&gt;
&lt;P style="font-size: 0.85em; color: #666;"&gt;Video caption: Using Windows 365 for Agents, Sai runs an overnight claims-processing workflow in a Contoso claims app with no APIs. Sai reads scanned claim forms, extracts key fields, verifies coverage, and enters results directly through the UI. &lt;/P&gt;
&lt;H4&gt;Secure access and reliable connectivity&lt;/H4&gt;
&lt;P&gt;Developers get consistent experience, agents run in a dedicated runtime, and IT maintains centralized control across both. Windows 365 brings these capabilities together, combining developer productivity with the provisioning, policy enforcement, and compliance controls organizations require. Building on this foundation, &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/adaptive-data-protection-with-context-based-redirections-in-windows-365-now-in-p/4521366" data-lia-auto-title="context-based redirection" data-lia-auto-title-active="0" target="_blank"&gt;context-based redirection&lt;/A&gt;, in public preview starting in June, adds more adaptive data protection. Organizations can apply granular redirection policies based on contextual signals, such as device management status, user network and location status to control how content is accessed and redirected.&lt;/P&gt;
&lt;P&gt;To improve connection reliability and user experience, Remote Desktop Protocol (RDP) multipath with redundant Transmission Control Protocol (TCP), now generally available (&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows-365/enterprise/rdp-multipath" target="_blank" rel="noopener"&gt;Windows 365&lt;/A&gt;/&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/azure/virtual-desktop/rdp-multipath" target="_blank" rel="noopener"&gt;Azure Virtual Desktop&lt;/A&gt;), enhances connection resiliency by maintaining multiple transport paths (UDP and TCP) between the client and session host. This dynamically selects the most reliable path, particularly in TCP-only or UDP-restricted environments- improving session reliability and continuity while reducing disruptions to enhance the overall user experience. In addition, &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows-app/health-checks?tabs=windows" target="_blank" rel="noopener"&gt;health checks in Windows App, now available on sovereign clouds&lt;/A&gt; (generally available) provides lightweight diagnostics that validate device readiness, network connectivity, and sovereign-specific endpoint reachability, enabling faster troubleshooting and more reliable connections in government cloud environments.&lt;/P&gt;
&lt;P&gt;For shared and controlled usage scenarios, &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows-365/enterprise/windows-365-flex-snapshot-based-reset" target="_blank" rel="noopener"&gt;Snapshot-based reset for Windows 365 Flex (in shared mode)&lt;/A&gt;, now in public preview, automatically reverts shared Windows 365 Flex Cloud PCs to a clean state after each user signs out. Every user starts with a clean Cloud PC, simplifying management and supporting the shared licensing model for Windows 365 Flex.&lt;/P&gt;
&lt;P&gt;Beyond organizational boundaries, using Azure Files and FSLogix as a user profile management solution for external identities in Azure Virtual Desktop is now generally available, enabling secure access for external users such as partners and vendors. To see more, check out our latest &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/azurevirtualdesktopblog/azure-virtual-desktop-supports-greater-application-and-identity-functionality-wi/4521365" data-lia-auto-title="blog" data-lia-auto-title-active="0" target="_blank"&gt;blog&lt;/A&gt;.&lt;/P&gt;
&lt;H4&gt;Get started today&lt;/H4&gt;
&lt;P&gt;With these updates, Windows 365 moves into a new phase that further reduces setup friction, keeps developers in flow, and helps teams build, run, and scale across environments.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.microsoft.com/windows-365/windows-365-enterprise" target="_blank" rel="noopener"&gt;Windows 365 Enterprise&lt;/A&gt; and &lt;A class="lia-external-url" href="https://www.microsoft.com/windows-365/windows-365-frontline" target="_blank" rel="noopener"&gt;Windows 365 Flex&lt;/A&gt; now include new developer capabilities - &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2167907&amp;amp;clcid=0x409&amp;amp;culture=en-us&amp;amp;country=us" target="_blank" rel="noopener"&gt;buy&lt;/A&gt; or &lt;A class="lia-external-url" href="https://www.microsoft.com/en-us/windows-365/contact-sales" target="_blank" rel="noopener"&gt;contact sales&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.microsoft.com/windows-365/contact-sales" target="_blank" rel="noopener"&gt;Contact sales&lt;/A&gt; to try Windows 365 32 vCPU and Windows 365 GPU-enabled Cloud PCs today.&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://aka.ms/W365MCS" target="_blank" rel="noopener"&gt;Try 50 free hours&lt;/A&gt; of Windows 365 for Agents Cloud PC with Microsoft Copilot Studio.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;Learn more at Microsoft Build 2026&lt;/H4&gt;
&lt;P&gt;Join the Windows 365 sessions at Microsoft Build 2026 to learn more and see these capabilities in action. Microsoft Build in 2026 offers two full days of content, from keynotes, breakouts, hands-on labs, to on-demand sessions that you can join live or watch anytime. The digital experience is free to attend. &lt;A class="lia-external-url" href="https://build.microsoft.com/home" target="_blank" rel="noopener"&gt;Register today&lt;/A&gt; to explore the full schedule, discover featured partners, and save your must-see sessions.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Tuesday, June 2, 2026:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://build.microsoft.com/en-US/sessions/KEY01?source=sessions" target="_blank" rel="noopener"&gt;Microsoft Opening Keynote&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="http://aka.ms/Build26BRK261" target="_blank" rel="noopener"&gt;BRK261: Build and ship faster with a developer-optimized experience on Windows&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="http://aka.ms/Build26BRK262" target="_blank" rel="noopener"&gt;BRK262: AI &amp;amp; Agent – Augmented coding you can trust on Windows&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://build.microsoft.com/en-US/sessions/LAB550-R2?source=sessions" target="_blank" rel="noopener"&gt;LAB550-R2: Build, deploy, &amp;amp; scale agents with Windows 365&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://build.microsoft.com/en-US/sessions/LAB550?source=sessions" target="_blank" rel="noopener"&gt;LAB550: Build, deploy, &amp;amp; scale agents with Windows 365&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://build.microsoft.com/en-US/sessions/LAB550-R1?source=sessions" target="_blank" rel="noopener"&gt;LAB550-R1: Build, deploy, &amp;amp; scale agents with Windows 365&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Wednesday, June 3, 2026:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="http://aka.ms/Build26BRK260" target="_blank" rel="noopener"&gt;BRK260: Build apps with Local AI for unmetered intelligence on every Windows PC&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://build.microsoft.com/en-US/sessions/LAB550-R3?source=sessions" target="_blank" rel="noopener"&gt;LAB550-R3: Build, deploy, &amp;amp; scale agents with Windows 365&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Build on-demand sessions available beginning June 2:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="http://www.aka.ms/Build26OD855" target="_blank" rel="noopener"&gt;OD855: Architecting computer-using agents with Windows 365 as an agent runtime&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="http://aka.ms/Build26OD852" target="_blank" rel="noopener"&gt;OD852: Accelerating developer productivity with Windows 365&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://build.microsoft.com/en-US/sessions/LAB550D?source=sessions" target="_blank" rel="noopener"&gt;LAB550D: Build, deploy, &amp;amp; scale agents with Windows 365&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Continue the conversation. Find best practices. Bookmark the &lt;/SPAN&gt;&lt;A href="https://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Tech Community&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, then follow us on &lt;/SPAN&gt;&amp;nbsp;&lt;A href="https://www.linkedin.com/company/windows-it-pro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;or&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://twitter.com/mswindowsitpro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSWindowsITPro&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; for updates. Looking for support? Visit &lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows on Microsoft Q&amp;amp;A&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2026 00:38:24 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/made-for-developers-and-agents-windows-365-at-build-2026/ba-p/4519041</guid>
      <dc:creator>BhavyaChopra</dc:creator>
      <dc:date>2026-06-03T00:38:24Z</dc:date>
    </item>
    <item>
      <title>Windows news you can use: May 2026</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-news-you-can-use-may-2026/ba-p/4516353</link>
      <description>&lt;P&gt;First, as we head into June and the first set of Secure Boot certificates start to expire, there will be another &lt;A href="https://techcommunity.microsoft.com/event/windowsevents/ask-microsoft-anything-secure-boot---june-2026/4522056" data-lia-auto-title="Secure Boot Ask Microsoft Anything (AMA) on Thursday, June 4" data-lia-auto-title-active="0" target="_blank"&gt;Secure Boot Ask Microsoft Anything (AMA) on Thursday, June 4&lt;/A&gt;. Do save the date and post your questions early or at any time during the live stream if you need assistance. You can also &lt;A href="https://techcommunity.microsoft.com/event/windowsevents/ask-microsoft-anything-secure-boot---may-2026/4513524" target="_blank"&gt;watch the May edition on demand&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;For more general questions around Windows deployment, updates, and management, you can join the chat-based Windows Office Hours every third Thursday. The next event will be &lt;A href="https://techcommunity.microsoft.com/event/windowsevents/windows-office-hours-june-18-2026/4458465" target="_blank"&gt;June 18 at 8:00 AM PDT&lt;/A&gt;.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Now let's dive in to more Windows news you can use you might have missed this past month.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;New in Windows update and device management&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;[AUTOPATCH] [GCC] – Windows Autopatch is now included automatically for Government Community Cloud (GCC) customers using Microsoft 365 G3 GCC, Microsoft 365 GCC G5, or Microsoft 365 GCC G5 without WDATP/CAS Unified. The $0 Windows Enterprise (OLS) activation SKU is no longer required. For guidance on how to get started, read &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/windows-autopatch-for-the-us-government-how-to-get-started/4467570/replies/4472671" target="_blank"&gt;Windows Autopatch for the US government&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;[HOTPATCH] – Starting with the May 2026 Windows security update, hotpatch updates are &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/securing-devices-faster-with-hotpatch-updates-on-by-default/4500066" target="_blank"&gt;now on by default&lt;/A&gt; for those using Windows Autopatch through Microsoft Intune or the Windows updates API in Microsoft Graph. The default tenant setting; however, is only applied to devices that aren't members of a quality update policy. Windows Autopatch respects your configuration of quality update policies.&lt;/LI&gt;
&lt;LI&gt;[BACKUP] – Start managing &lt;A href="https://learn.microsoft.com/windows/configuration/windows-backup/catalog-esr?pivots=windows-11" target="_blank"&gt;Enterprise State Roaming (ESR)&lt;/A&gt; through Windows Backup for Organizations policies. By the end of June, you'll no longer be able to access ESR policies through the Microsoft Entra portal and will instead need to use Microsoft Intune.&lt;/LI&gt;
&lt;LI&gt;[W365] – &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/admin-insights-for-windows-365-stay-on-top-of-what-needs-attention-%E2%80%94-now-in-publ/4517570" target="_blank"&gt;Admin Insights for Windows 365&lt;/A&gt;, now in public preview, brings together important signals from existing reporting, monitoring, and alerting from Intune. Quickly understand what's happening in your environment and where to focus.&lt;/LI&gt;
&lt;LI&gt;[ARM] – Does your organization use, or plan to adopt, Arm-based Windows devices? Check out a snapshot of companies that have recently delivered or expanded &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/advancing-print-readiness-across-the-windows-on-arm-ecosystem/4515926" target="_blank"&gt;print solutions supporting Windows on Arm&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;[SKILLING] – Still have devices running Windows 10? Need advice on optimizing how you roll out new versions of Windows and Microsoft 365 apps in your organization? Use the updated &lt;A href="https://learn.microsoft.com/en-us/training/paths/stay-current-with-windows/" target="_blank"&gt;Stay current with Windows learning path&lt;/A&gt; to plan, prepare for, and deploy for updates across your organization.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;New in Windows security&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;[SECURE BOOT] – The &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/updated-secure-boot-status-report-in-windows-autopatch/4517920" target="_blank"&gt;updated Secure Boot status report in Windows Autopatch&lt;/A&gt; provides better device-level visibility into certificate status, trust configuration, and readiness for Secure Boot certificate updates. New interactive certificate-level details fit directly into your certificate rollout workflow.&lt;/LI&gt;
&lt;LI&gt;[SECURE BOOT] – Microsoft Defender now provides centralized visibility into Secure Boot 2023 certificate readiness across your device fleet. &lt;A href="https://aka.ms/secureboot-mde" target="_blank"&gt;A new assessment&lt;/A&gt; categorizes your devices automatically as exposed, compliant, and not applicable.&lt;/LI&gt;
&lt;LI&gt;[FIREWALL] [NETWORKING] – Have devices that experience difficulties receiving updates? &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/configuring-firewall-and-proxies-for-smooth-windows-updates/4517913" target="_blank"&gt;New guidance&lt;/A&gt; is available to help you identify potential causes and implement solutions to ensure updates roll out smoothly moving forward.&lt;/LI&gt;
&lt;LI&gt;[PRINTING] – A new icon appears on the &lt;STRONG&gt;Printers &amp;amp; scanners&lt;/STRONG&gt; settings page. It helps you easily understand which devices support a more secure printing experience with &lt;A href="https://learn.microsoft.com/windows/modern-print/windows-protected-print-mode/windows-protected-print-mode" target="_blank"&gt;Windows protected print mode&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;[PASSKEYS] – World Passkey Day was May 7. Learn how Microsoft is &lt;A href="https://www.microsoft.com/en-us/security/blog/2026/05/07/world-passkey-day-advancing-passwordless-authentication/?msockid=12a7b86c8089634f2b24ae70817162cf" target="_blank"&gt;Advancing passwordless authentication&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;To explore what's new in security across the Microsoft platform, see &lt;A href="https://www.microsoft.com/en-us/security/blog/2026/05/21/whats-new-in-microsoft-security-may-2026/" target="_blank"&gt;What's new in Microsoft Security: May 2026&lt;/A&gt;.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;New in AI&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;[DEVELOPERS] – Microsoft Build runs June 2-3! It features &lt;A href="https://build.microsoft.com/en-US/sessions?search=windows&amp;amp;sortBy=relevance" target="_blank"&gt;sessions on building, modernizing, and optimizing Windows apps and developer experiences&lt;/A&gt;. Check out especially AI-powered capabilities, cloud integration, and next‑gen tooling like Copilot, WinUI, and GitHub Copilot.&lt;/LI&gt;
&lt;LI&gt;[AGENTS] – Windows is adding a new way to monitor your agents from the taskbar. This experience supports agents across first- and third-party apps, with &lt;A href="https://learn.microsoft.com/microsoft-365/copilot/researcher-agent" target="_blank"&gt;Researcher in the Microsoft 365 Copilot app&lt;/A&gt;as the first adopter.&lt;/LI&gt;
&lt;LI&gt;[COPILOT] [M365] – The &lt;A href="https://www.microsoft.com/en-us/microsoft-365/blog/2026/05/28/introducing-a-new-design-for-microsoft-365-copilot/" target="_blank"&gt;Copilot app has been redesigned&lt;/A&gt; to be faster and more responsive. What do you think about the way Copilot shows up across Microsoft 365 apps?&lt;/LI&gt;
&lt;LI&gt;[COPILOT] [M365] – New &lt;A href="https://adoption.microsoft.com/en-us/copilot/" target="_blank"&gt;Microsoft 365 Copilot&lt;/A&gt; resources are now available to help you get started with adopting Copilot capabilities across your organization.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;To learn about latest capabilities for Copilot+ PCs, visit the &lt;A href="https://www.microsoft.com/windows/business/roadmap" target="_blank"&gt;Windows Roadmap&lt;/A&gt; and filter Platform by “Copilot+ PC Exclusives.”&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;New in Windows Server&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;For the latest features and improvements for Windows Server, see the &lt;A href="https://support.microsoft.com/topic/windows-server-2025-update-history-10f58da7-e57b-4a9d-9c16-9f1dcd72d7d7" target="_blank"&gt;Windows Server 2025 release notes&lt;/A&gt; and &lt;A href="https://support.microsoft.com/topic/windows-server-version-23h2-update-history-68c851ff-825a-4dbc-857b-51c5aa0ab248" target="_blank"&gt;Windows Server, version 23H2 release notes&lt;/A&gt;.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;[HOTPATCH] – Hotpatch updates enabled by Azure Arc are now available at no additional cost for Windows Server 2025. &lt;A href="https://techcommunity.microsoft.com/blog/AzureArcBlog/simplified-access-to-hotpatching-enabled-by-azure-arc-for-windows-server-2025/4521251" target="_blank"&gt;Read the announcement&lt;/A&gt; for details on eligibility and guidance on how to get started.&lt;/LI&gt;
&lt;LI&gt;[SKILLING] – All 19 sessions from &lt;A href="https://techcommunity.microsoft.com/event/windowsserver-events/windows-server-summit-2026/4501032" target="_blank"&gt;Windows Server Summit 2026&lt;/A&gt; are now available on demand. Learn and improve your skills on your schedule.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;New in productivity and collaboration&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Install the May 2026 security update for &lt;A href="https://support.microsoft.com/topic/may-12-2026-kb5089549-os-builds-26200-8457-and-26100-8457-28ec2a99-4bbe-481d-a340-5c6cf18d9acb" target="_blank"&gt;Windows 11, versions 25H2 and 24H2&lt;/A&gt; to get these and other capabilities, which will be rolling out gradually:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;[FILE EXPLORER] – View and Sort preferences are now preserved in folders such as Downloads and Documents when apps launch File Explorer directly to those locations. File Explorer also now supports uu, cpio, xar, and NuGet Packages (nupkg) archive formats.&lt;/LI&gt;
&lt;LI&gt;[INPUT] – Voice typing on the touch keyboard now looks simpler and more intuitive. The updated design removes the full‑screen overlay and shows voice typing animations directly on the dictation key.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;New features and improvements are coming in the June 2026 security update. You can preview them by installing the May 2026 optional non-security update for &lt;A href="https://support.microsoft.com/topic/may-26-2026-kb5089573-os-builds-26200-8524-and-26100-8524-preview-f378c8ae-0170-47c9-a1e9-dfef978c8e17" target="_blank"&gt;Windows 11, versions 25H2 and 24H2&lt;/A&gt;. This update includes the gradual rollout of:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;[AUDIO] – Shared audio enables two people to listen to the same audio from a single Windows 11 PC at the same time.&lt;/LI&gt;
&lt;LI&gt;[CAMERA] – Windows 11's Multi-App Camera feature allows multiple applications to access your camera stream at the same time.&lt;/LI&gt;
&lt;LI&gt;[MAGNIFIER] – Magnifier now provides clearer and more consistent announcements when working with a screen reader. You'll hear helpful announcements when you zoom in or out, switch views, turn color inversion on or off, or turn Magnifier on or off. In addition, Magnifier now supports magnification of permitted protected content.&lt;/LI&gt;
&lt;LI&gt;[SEARCH] – Windows Search will now find and prioritize files with as few as two characters.&lt;/LI&gt;
&lt;LI&gt;[PERFORMANCE] – Task Manager now provides enhanced visibility into NPU usage, including new metrics and AI activity insights.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Lifecycle reminders&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Check out our lifecycle documentation for the latest updates on &lt;A href="https://learn.microsoft.com/windows/whats-new/deprecated-features" target="_blank"&gt;Deprecated features in the Windows client&lt;/A&gt; and &lt;A href="https://learn.microsoft.com/windows-server/get-started/removed-deprecated-features-windows-server-2025" target="_blank"&gt;Features removed or no longer developed starting with Windows Server 2025&lt;/A&gt;.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Additional resources&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Looking for the latest news and previews for Windows, Copilot, Copilot+ PCs, the Windows and Windows Server Insider Programs, and more? Check out these resources:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/windows/business/roadmap" target="_blank"&gt;Windows Roadmap&lt;/A&gt; for new Copilot+ PCs and Windows features – filter by platform, version, status, and channel or search by feature name&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/copilot/microsoft-365/release-notes?tabs=all" target="_blank"&gt;Microsoft 365 Copilot release notes&lt;/A&gt; for latest features and improvements&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://blogs.windows.com/windows-insider/" target="_blank"&gt;Windows Insider Blog&lt;/A&gt; for what's available in the Beta and Experimental channels&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/windows-server/discussions/windowsserverinsiders" target="_blank"&gt;Windows Server Insider&lt;/A&gt; for feature preview opportunities&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://support.microsoft.com/topic/understanding-update-history-for-windows-insider-preview-features-fixes-and-changes-bb9dd4b1-9d2b-4753-8b23-ce90e62f6845" target="_blank"&gt;Understanding update history for Windows Insider preview features, fixes, and changes&lt;/A&gt; to learn about the types of updates for Windows Insiders&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Join the conversation&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;We are always looking to improve this monthly summary. Drop us a note in the Comments and let us know what we can do to make this more useful for you!&lt;/P&gt;
&lt;HR /&gt;
&lt;P style="font-size: 14px;"&gt;Continue the conversation. Find best practices. Bookmark the &lt;A href="http://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;Windows Tech Community&lt;/A&gt;, then follow us &lt;A href="https://x.com/mswindowsitpro" target="_self"&gt;@MSWindowsITPro&lt;/A&gt; on X and on &lt;A href="https://www.linkedin.com/company/windows-it-pro" target="_blank" rel="noopener"&gt;LinkedIn&lt;/A&gt;. Looking for support? Visit &lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;Windows on Microsoft Q&amp;amp;A&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2026 21:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-news-you-can-use-may-2026/ba-p/4516353</guid>
      <dc:creator>Chris_Morrissey</dc:creator>
      <dc:date>2026-06-01T21:00:00Z</dc:date>
    </item>
    <item>
      <title>Updated Secure Boot status report in Windows Autopatch</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/updated-secure-boot-status-report-in-windows-autopatch/ba-p/4517920</link>
      <description>&lt;P&gt;Do more with the improved Secure boot status report in Windows Autopatch. Now, you can gain better device-level visibility into certificate status, trust configuration, and readiness for Secure Boot certificate updates. New interactive certificate-level details fit directly into your certificate rollout workflow:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;A href="#community--1-_identify" target="_self"&gt;Identify devices that aren't up to date.&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="#community--1-_trust" target="_self"&gt;Use trust configuration and certificate details to understand applicability.&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="#community--1-_confidence" target="_self"&gt;Check confidence level to determine your rollout strategy.&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="#community--1-_alerts" target="_self"&gt;Use alerts and timestamps to validate reporting freshness and prioritize action.&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="#community--1-_remediation" target="_self"&gt;Plan targeted remediation instead of broad deployments.&lt;/A&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;From policy deployment to actual Secure Boot readiness&lt;/H2&gt;
&lt;P&gt;Secure Boot is a core Windows security feature that helps ensure devices start up using only trusted, digitally signed components. It helps protect against boot-level malware and enforces a root of trust during startup. As Secure Boot certificates evolve and older certificates approach expiration, visibility into device readiness becomes critical.&lt;/P&gt;
&lt;P&gt;To deploy Secure Boot certificate updates, the recommended option is to enable the &lt;A href="https://learn.microsoft.com/windows/client-management/mdm/policy-csp-secureboot#enablesecurebootcertificateupdates" target="_blank" rel="noopener"&gt;EnableSecurebootCertificateUpdates policy&lt;/A&gt;. When active, the policy automatically sends certificate updates to supported and eligible devices but requires a device restart to complete the process.&lt;/P&gt;
&lt;P&gt;However, before enabling a Secure Boot policy, it's important to understand:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Which devices have updated their certificates and are protected&lt;/LI&gt;
&lt;LI&gt;Whether firmware configuration blocks updates&lt;/LI&gt;
&lt;LI&gt;Whether devices are ready for rollout&lt;/LI&gt;
&lt;LI&gt;When to take action&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The &lt;A href="https://learn.microsoft.com/windows/deployment/windows-autopatch/monitor/secure-boot-status-report" target="_blank" rel="noopener"&gt;Secure Boot status report&lt;/A&gt; addresses this gap by giving you a data-informed view of device readiness, not just policy assignment status. The report provides a device-level view of Secure Boot across your Windows Autopatch-managed devices. Let's walk through how to quickly understand your fleet's readiness.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Note: &lt;/STRONG&gt;Certificate readiness presupposes devices with Secure Boot enabled. Devices with Secure Boot disabled are included for visibility only. They don't require any action.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;How to use the Secure Boot status report&lt;/H2&gt;
&lt;P&gt;The report includes several key signals designed to help you make informed decisions.&lt;/P&gt;
&lt;P&gt;Ready to see it in action? Start here:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Go to the &lt;A href="https://go.microsoft.com/fwlink/?linkid=2109431" target="_blank" rel="noopener"&gt;Intune admin center&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;Open &lt;STRONG&gt;Reports &lt;/STRONG&gt;&amp;gt; &lt;STRONG&gt;Windows Autopatch&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Windows quality updates&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Select &lt;STRONG&gt;Reports&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Open &lt;STRONG&gt;Secure Boot status&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/OL&gt;
&lt;img /&gt;
&lt;P&gt;&lt;a id="community--1-#_identify" class="lia-anchor"&gt;&lt;/a&gt;&lt;/P&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;Identify devices that aren't up to date by certificate status&lt;/H3&gt;
&lt;P&gt;Find the new column called &lt;STRONG&gt;Certificate status&lt;/STRONG&gt;. See which certificates require action based on an aggregate view. Here's what each status means:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Up to date:&lt;/STRONG&gt; No action is required.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Not up to date:&lt;/STRONG&gt; Devices require certificate updates.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Not applicable:&lt;/STRONG&gt; Secure Boot isn't enabled.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Drill into this field to see per-certificate details. No need for custom scripts or manual validation. Select the status cell for any device to see whether Secure Boot is enabled, its trust setting, and status for each of the four required certificates.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;a id="community--1-#_trust" class="lia-anchor"&gt;&lt;/a&gt;&lt;/P&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;Use trust configuration and certificate details to understand applicability&lt;/H3&gt;
&lt;P&gt;Not all devices require the same set of Secure Boot certificates. The &lt;STRONG&gt;Secure Boot trust setting&lt;/STRONG&gt; column shows whether a device trusts:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Microsoft-only components&lt;/LI&gt;
&lt;LI&gt;Both Microsoft and non-Microsoft components&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This is important because certificate applicability depends on how the device is configured, not just what exists on disk. For example, a device may be fully compliant even if certain certificates aren't present. This happens if certificates aren't required for that configuration.&lt;/P&gt;
&lt;P&gt;&lt;a id="community--1-#_confidence" class="lia-anchor"&gt;&lt;/a&gt;&lt;/P&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;Check confidence level to determine your rollout strategy&lt;/H3&gt;
&lt;P&gt;This is one of the most important additions in the new version of the report. The &lt;STRONG&gt;Confidence level &lt;/STRONG&gt;column helps guide deployment decisions based on Microsoft-observed data across similar devices and firmware configurations. Select any cell to see a flyout summary for that device. Review the description of the status and the recommended action. It also states whether the high-confidence deployment policy is allowed.&lt;/P&gt;
&lt;P&gt;Use this data to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Confidently auto-deploy updates to high-confidence devices.&lt;/LI&gt;
&lt;LI&gt;Manually validate devices with limited or no data.&lt;/LI&gt;
&lt;LI&gt;Pause rollout where known issues exist.&lt;/LI&gt;
&lt;/UL&gt;
&lt;img /&gt;
&lt;P&gt;Here are recommendations based on confidence level labels:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;High confidence: &lt;/STRONG&gt;Deploy the certificates depending on the policy setting:
&lt;UL&gt;
&lt;LI&gt;If the high-confidence policy is allowed: No action is required. Devices will automatically receive Secure Boot certificate updates through Windows Update.&lt;/LI&gt;
&lt;LI&gt;If the high-confidence policy isn't allowed: Deploy certificate updates manually when ready.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&amp;nbsp;&lt;STRONG&gt;Under observation:&lt;/STRONG&gt; Test certificate updates in controlled rollout.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;No data observed:&lt;/STRONG&gt; Carefully validate certificate updates before broad deployment. Microsoft hasn't observed this type of device in Secure Boot update data.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;Temporarily paused:&lt;/STRONG&gt; Don't deploy. Devices in this group are affected by a known issue. Consult with your OEM for possible firmware updates.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;Not supported:&lt;/STRONG&gt; Exclude these devices from automation.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Use the confidence level data to take out guesswork from your Secure Boot certificate rollout strategy and turn it into data-informed deployment.&lt;/P&gt;
&lt;P&gt;&lt;a id="community--1-#_alerts" class="lia-anchor"&gt;&lt;/a&gt;&lt;/P&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;Use alerts and timestamps to prioritize action&lt;/H3&gt;
&lt;P&gt;A new &lt;STRONG&gt;Alerts &lt;/STRONG&gt;column helps you validate reporting freshness and prioritize action. The report surfaces the following operational signals:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Devices missing diagnostic data&lt;/LI&gt;
&lt;LI&gt;Devices requiring action&lt;/LI&gt;
&lt;LI&gt;Timestamp of last reported diagnostic data&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Important! &lt;/STRONG&gt;To avoid false assumptions when validating rollout progress, note these important limitations:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Status updates can take up to 12 hours after restart to be reflected.&lt;/LI&gt;
&lt;LI&gt;Devices must send required diagnostic data to appear correctly in the report.&lt;/LI&gt;
&lt;LI&gt;Inactive devices might show up as &lt;EM&gt;Unknown&lt;/EM&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;a id="community--1-_remediation" class="lia-anchor"&gt;&lt;/a&gt;&lt;/P&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;Plan targeted remediation of Secure Boot certificates&lt;/H3&gt;
&lt;P&gt;Secure Boot certificate updates are not uniform across devices. They depend on firmware, configuration, and trust models. Due to this variation, applying Secure Boot updates sometimes sees unexpected results.&lt;/P&gt;
&lt;P&gt;Without clear visibility, organizations risk:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Missing required updates&lt;/LI&gt;
&lt;LI&gt;Deploying updates too broadly&lt;/LI&gt;
&lt;LI&gt;Misinterpreting device readiness&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The Secure Boot status report gives you a more precise, device-level understanding of readiness, so you can act confidently and help reduce risk across your estate. Together, these improvements focus on one thing: making the data actionable. If needed, make data-informed decisions on targeted remediations instead of broad deployments.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Note on Secure Boot updates and hotpatch updates&lt;/H2&gt;
&lt;P&gt;If you're using hotpatch updates, plan for a one-time change in strategy. More devices become eligible for Secure Boot certificate updates over time based on high-confidence diagnostic data. High-confidence deployment relies on data included in monthly non-security preview updates, which are typically released the fourth week of the month. By definition, devices receiving hotpatch updates don't receive these preview updates. As such, these devices might &lt;EM&gt;not &lt;/EM&gt;progress at the same rate as other devices. Here's the implication:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Devices might &lt;EM&gt;not &lt;/EM&gt;receive updated high-confidence data in May or June.&lt;/LI&gt;
&lt;LI&gt;Some devices might &lt;EM&gt;not &lt;/EM&gt;become eligible for automatic deployment during that time.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In addition, applying Secure Boot updates requires device restarts to complete changes to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Secure Boot certificates&lt;/LI&gt;
&lt;LI&gt;The Windows Boot Manager&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;As a result of this design, devices receiving hotpatch updates will only receive updates automatically during the next baseline month (for example, April or July).&lt;/P&gt;
&lt;P&gt;To move forward sooner, your organization can:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Install the latest monthly non-security preview update (instead of a hotpatch update) to pick up updated high-confidence data.&lt;/LI&gt;
&lt;LI&gt;Restart the devices to complete the update process.&lt;/LI&gt;
&lt;LI&gt;Optional: Temporarily pause hotpatch updates and plan maintenance windows during Secure Boot rollout. Then resume hotpatch updates.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Learn more or bookmark these resources:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/windows/deployment/windows-autopatch/monitor/secure-boot-status-report" target="_blank" rel="noopener"&gt;Secure Boot status report in Windows Autopatch&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://support.microsoft.com/topic/windows-secure-boot-certificate-expiration-and-ca-updates-7ff40d33-95dc-4c3c-8725-a9b95457578e" target="_blank" rel="noopener"&gt;Windows Secure Boot certificate expiration and CA updates&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/secure-boot-playbook-for-certificates-expiring-in-2026/4469235" target="_blank" rel="noopener"&gt;Secure Boot playbook for certificates expiring in 2026&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/windowsservernewsandbestpractices/windows-server-secure-boot-playbook-for-certificates-expiring-in-2026/4495789" target="_blank" rel="noopener"&gt;Windows Server Secure Boot playbook for certificates expiring in 2026&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;P style="font-size: 14px;"&gt;Continue the conversation. Find best practices. Bookmark the &lt;A href="http://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;Windows Tech Community&lt;/A&gt;. Looking for support? Visit &lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;Windows on Microsoft Q&amp;amp;A&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2026 19:50:26 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/updated-secure-boot-status-report-in-windows-autopatch/ba-p/4517920</guid>
      <dc:creator>Harman_Thind</dc:creator>
      <dc:date>2026-05-19T19:50:26Z</dc:date>
    </item>
    <item>
      <title>Admin Insights for Windows 365: Stay on top of what needs attention — now in public preview</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/admin-insights-for-windows-365-stay-on-top-of-what-needs/ba-p/4517570</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;When IT administrators are looking for the most critical actions to take, being able to quickly understand what is happening in their environment can make a big difference.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;With this in mind, we’re excited to announce Admin Insights for Windows 365, now in public preview, designed to help IT administrators quickly understand what’s happening in their environment and where to focus.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To learn more and access technical guidance, visit the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/windows-365/enterprise/admin-insights" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Admin Insights for Windows 365 documentation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Understanding your environment,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;faster&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;IT administrators managing Windows 365 Cloud PCs rely on a range of signals—including reports, alerts, and device views—across the Microsoft Intune admin center to understand the health of their environment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;These signals provide valuable visibility across the Windows 365 environment. As environments scale,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;quickly surfacing what needs attention—and acting on it—becomes more important&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Bringing key signals together&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;in one place&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;img&gt;Insight cards surface signals for review when thresholds are met.&lt;/img&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Admin Insights builds on existing reporting, monitoring, and alerting by bringing important signals together directly into the Windows 365 experience.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;With Admin Insights, IT administrators can:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Identify what needs attention&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;across their Cloud PC environment&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Understand environment health at a glance&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, without digging through multiple reports&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Spot unexpected changes and outliers&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, such as spikes in failures or degraded performance&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Focus on what to do next&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, using signals surfaced in one place&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What powers Admin Insights&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Admin Insights surfaces dynamic insight cards in the Windows 365 management portal in Intune, based on changes and patterns across your Cloud PC environment:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Insight cards are generated automatically&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, based on activity across your environment&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Up to 15 insight cards may be displayed&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, covering general health and outlier conditions&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Cards appear contextually&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, highlighting what needs attention as changes are detected&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Each card maps to a specific scenario&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, such as unhealthy Cloud PCs or connectivity failures&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Get started with Admin Insights&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Admin Insights are available on the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Cloud PC Overview &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;page. Insight cards appear when defined thresholds are met, surfacing key signals.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To learn more, visit the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/windows-365/enterprise/admin-insights" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Admin Insights &lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;for Windows 365 &lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;documentation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;. The feature will continue to extend to new scenarios and Windows 365 surfaces in the Intune portal, providing IT administrators with the information they need, where they need it.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Continue the conversation. Find best practices. Bookmark the &lt;/SPAN&gt;&lt;A href="https://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Tech Community&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, then follow us on &lt;/SPAN&gt; &lt;A href="https://www.linkedin.com/company/windows-it-pro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;or&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://twitter.com/mswindowsitpro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSWindowsITPro&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; for updates. Looking for support? Visit &lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows on Microsoft Q&amp;amp;A&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/admin-insights-for-windows-365-stay-on-top-of-what-needs/ba-p/4517570</guid>
      <dc:creator>madelinecarr</dc:creator>
      <dc:date>2026-05-19T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Easily identify Windows protected print mode compatible devices</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/easily-identify-windows-protected-print-mode-compatible-devices/ba-p/4516897</link>
      <description>&lt;P&gt;As organizations work to modernize their print environments and reduce reliance on legacy drivers, &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/windows/modern-print/windows-protected-print-mode/windows-protected-print-mode" target="_blank" rel="noopener"&gt;Windows protected print (WPP) mode&lt;/A&gt; helps improve system security by enforcing the use of the &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2362106" target="_blank" rel="noopener"&gt;Windows modern print stack&lt;/A&gt; and introducing &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2361898" target="_blank" rel="noopener"&gt;additional security features&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;To help IT admins and users easily understand which devices are compatible with this more secure printing experience, Windows is introducing a new icon that can be found in &lt;STRONG&gt;Settings &amp;gt; Bluetooth &amp;amp; devices &amp;gt; Printers &amp;amp; scanners&lt;/STRONG&gt;:&lt;/P&gt;
&lt;img&gt;Printer with compatibility icon indicating support for Windows protected print mode.&lt;/img&gt;
&lt;P&gt;This icon appears next to each installed printer that supports Windows protected print mode, which requires IPP-capable printers.&lt;/P&gt;
&lt;P&gt;This update helps IT administrators quickly evaluate printer readiness for Windows protected print mode before enabling it across managed devices. If your environment’s printers support WPP, we highly recommend enabling it to create a more secure print ecosystem.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2362082" target="_blank" rel="noopener"&gt;How to enable WPP locally&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2362800" target="_blank" rel="noopener"&gt;How to enable WPP as group policy&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;Continue the conversation. Find best practices. Bookmark the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Tech Community&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;, then follow us on&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/company/windows-it-pro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;or&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://twitter.com/mswindowsitpro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSWindowsITPro &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;for updates. Looking for support? Visit&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows on Microsoft Q&amp;amp;A&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/easily-identify-windows-protected-print-mode-compatible-devices/ba-p/4516897</guid>
      <dc:creator>elliesekine</dc:creator>
      <dc:date>2026-05-14T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Configuring firewall and proxies for smooth Windows updates</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/configuring-firewall-and-proxies-for-smooth-windows-updates/ba-p/4517913</link>
      <description>&lt;P&gt;Having trouble connecting to Windows Update? If your devices experience difficulties getting updates, you're likely just one step away from the solution. The key is in the configuration of your network endpoints for firewalls and proxies. This post provides actionable guidance on how to identify the cause of the issue and remedy the situation.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;How the Windows Update service and networking interact&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;The Windows Update service makes use of Internet hosted services to widely distribute updates to Windows devices. Windows devices connect to Windows Update services to check for various updates, including monthly security and non-security updates, driver and .NET Framework updates, machine learning (ML) model updates, and more.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Typically, a Windows Update scan occurs automatically or when triggered manually by the user. Once started, the process scans for updates, downloads, and installs them. However, some network configurations obscure this process, leading to errors or the inability to update a device. Luckily, there are measures you can take to avoid this.&lt;/P&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;Security is embedded in the Windows Update experience&lt;/H3&gt;
&lt;P style="margin-top: 16px;"&gt;Security is paramount for Windows Update. Its whole purpose is to help keep your devices protected and productive. Therefore, there are &lt;A href="https://learn.microsoft.com/windows/deployment/update/windows-update-security#securing-metadata-connections" target="_blank"&gt;multiple protections&lt;/A&gt; to ensure that your device connects to authentic Windows Update services. However, there's one specific networking security consideration we'll focus on: &lt;A href="https://learn.microsoft.com/windows-server/security/tls/transport-layer-security-protocol" target="_blank"&gt;Transport Layer Security (TLS)&lt;/A&gt;.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;You probably know TLS (sometimes referred to by an older protocol known as SSL) as the https:// element you type into your browser. This moniker instructs your browser to connect to a web server using HTTP over a TLS connection. Doing so helps ensure the following between your device and a web server:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;The connection is protected from eavesdropping.&lt;/STRONG&gt; It encrypts the data between your device and the server.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;The connection can detect changes made to your data over the network.&lt;/STRONG&gt; It provides integrity checks that your device can validate.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;The connection is trusted.&lt;/STRONG&gt; Your device inspects a TLS “certificate of authenticity” that the server provides to prove who it is.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;When Windows interacts with the Windows Update service, it performs all of these checks. Additionally, it double-checks that the server isn't only trusted, but it's what it claims to be. This is done by verifying that the server's TLS certificate is chained up to a specific certificate authority (CA). Windows refers to this as a Windows Update trust anchor.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;If the TLS certificate isn't issued by an actual Windows Update trust anchor, Windows won't trust that the server is a genuine Windows Update server and immediately disconnects. That's good news until you accidentally lock yourself out of accessing trustworthy Windows Update services.&lt;/P&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;Proxy server and firewall configurations to watch&lt;/H3&gt;
&lt;P style="margin-top: 16px;"&gt;Some networking environments implement special firewalls or proxies that intercept TLS connections. They typically perform TLS inspection, validating that the request to a server is legitimate and adheres to an organization's security and other policies. This is how some firewalls and proxies might block access to forbidden content.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;When TLS inspection occurs in this way, the firewall or proxy server generates its very own certificate. Even though it is generated by the firewall or proxy, it appears to be legitimate (containing SAN entries for the URL's fully qualified domain name) and is trusted by the client's browser. Typically, this involves generating a TLS certificate to match the requested URL and signing it by the organization deploying these firewall/proxy services. Since the client device is a member of the organization, it inherently trusts these certificates signed by the same organization.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;When this occurs, the Windows Update client detects that the TLS certificate issuer isn't a genuine Windows Update issuer. By design, the client only trusts certificates issued by the Windows Update service. This feature of “pinning” solely to TLS certificates issued by the Windows Update service protects the distribution and delivery channels from man-in-the-middle (MITM) attacks. Again, this is good news for your security posture, except when exceptions are needed.&lt;/P&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;The role of VPNs&lt;/H3&gt;
&lt;P style="margin-top: 16px;"&gt;Some virtual private network (VPN) providers block access or DNS lookups to prevent overloading the VPN network with high-volume traffic downloads. That's another potential cause of blocked access for Windows devices. If you're experiencing Windows Update issues over a VPN connection, contact your VPN provider.&lt;/P&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;Care with scripting&lt;/H3&gt;
&lt;P style="margin-top: 16px;"&gt;If you're an avid PowerShell administrator, you might be forcing Windows Update to scan using scripts that call into the Windows Update public API. In this case, these calls might return one of the error codes listed below and add an entry for the error to the Windows Update log. If this happens, remediation steps are the same as if you found them in the Windows Update log.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Note:&amp;nbsp;&lt;/STRONG&gt;The Windows Update protocol is complex and consists of multiple different connections and endpoints. Simply connecting to one of the Windows Update servers doesn't tell the bigger picture of end-to-end protocol success. Rely on API result codes and/or the Windows Update log to determine success.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;How to tell if you're blocked&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;If your Windows device is not receiving Windows updates as you expect, check if your connections are being blocked. Whether the source of the issue is a proxy server, firewall, or VPN, you can use the following steps to troubleshoot and move forward.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;The first thing to check is the &lt;A href="https://learn.microsoft.com/powershell/module/windowsupdate/get-windowsupdatelog?view=windowsserver2025-ps" target="_blank"&gt;Windows Update audit log&lt;/A&gt;. Generate it from PowerShell, running the &lt;STRONG&gt;Get-WindowsUpdateLogs&lt;/STRONG&gt; command:&lt;/P&gt;
&lt;PRE style="margin-top: 16px;"&gt;$output = "$env:TEMP\WindowsUpdate.log"&lt;BR /&gt;Get-WindowsUpdateLog -LogPath $output&lt;BR /&gt;Write-Host "Windows Update log written to $output"&lt;/PRE&gt;
&lt;P style="margin-top: 16px;"&gt;Once you have the log file, look for any of the following error codes:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;0x8024402c&lt;/STRONG&gt; (decimal: -2145107924)&lt;BR /&gt;This is the &lt;STRONG&gt;WU_E_PT_WINHTTP_NAME_NOT_RESOLVED&lt;/STRONG&gt; error. It means that the Windows device was unable to resolve the Windows Update server DNS name to an IP address. Your organization might be blocking Fully Qualified Domain Name (FQDN) to IP address resolution.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;0x80240438&lt;/STRONG&gt; (decimal: -2145123272)&lt;BR /&gt;This is the &lt;STRONG&gt;WU_E_PT_ENDPOINT_UNREACHABLE&lt;/STRONG&gt; error. You receive this if the FQDN has been properly resolved to an IP address, but the Windows device is unable to connect to the server. This is probably due to a firewall or proxy blocking access.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;0x80245006&lt;/STRONG&gt; (decimal: -2145103866)&lt;BR /&gt;This is the &lt;STRONG&gt;WU_E_REDIRECTOR_INVALID_RESPONSE&lt;/STRONG&gt; error. This can show up for several reasons. For the sake of this discussion, it typically means one of the following:
&lt;UL&gt;
&lt;LI&gt;Your connection with the Windows Update service was unable to procure data it needs. For example, your connection might have dropped during the client-server interaction. In this case, check that your connection to the Internet is stable and not dropping.&lt;/LI&gt;
&lt;LI&gt;Your device was unable to validate the server's TLS certificate via trust anchor certificate pinning. This is most likely the case if your firewall or proxy is performing TLS inspection.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;0x80240437&lt;/STRONG&gt; (decimal: -2145123273)&lt;BR /&gt;This is the &lt;STRONG&gt;WU_E_PT_SECURITY_VERIFICATION_FAILURE&lt;/STRONG&gt; error. Your device was unable to prove that the connected server is legitimate and genuine Windows Update. Similar to the WU_E_REDIRECTOR_INVALID_RESPONSE error, your device couldn't validate the server's TLS certificate via trust anchor certificate pinning. Again, check if your firewall or proxy is performing TLS inspection.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;If your log shows any of these error codes, work with your IT team to help ensure that firewalls and proxies are properly allowing Windows Update connections. In some cases, VPNs may be blocking FQDN resolutions or connections to the Windows Update service. If you're using a VPN, check with the VPN provider.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Recommended configurations and exceptions&lt;/H2&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;A trusted connection requires trusted subdomains&lt;/H3&gt;
&lt;P style="margin-top: 16px;"&gt;To ensure that Windows devices can properly access genuine Windows Update services, firewalls and proxies need to allow those connections to pass through uninterrupted. That is to say, without generating and using its own TLS certificate.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;To do this, proxies and firewalls need to create “pass through” exceptions for these Windows Update connections. This is typically done by allow-listing specific Windows-Update-related DNS host names. There are several of these qualified DNS names (FQDN) that you need to accommodate. You can learn more about the FQDNs requiring these exceptions in the Windows Update sections of the following:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/windows/privacy/manage-windows-11-endpoints" target="_blank"&gt;Connection endpoints for Windows 11 Enterprise&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/windows/privacy/windows-11-endpoints-non-enterprise-editions" target="_blank"&gt;Windows 11 connection endpoints for non-Enterprise editions&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;Note that for the FQDNs related to Windows Update, the * wildcard is recursive. For security and scalability purposes, host and DNS subdomain names might need to periodically change.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;For example, here's a recommended DNS host name:&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;&lt;STRONG&gt;*.update.microsoft.com&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;It represents all of the following hosts and subdomains:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;update.microsoft.com&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;sls.&lt;STRONG&gt;update.microsoft.com&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;tas02.sls.&lt;STRONG&gt;update.microsoft.com&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;This means that you should trust all the DNS hosts and subdomains related to wildcard FQDN for the connection to work properly. Check if these subdomains are missing. In many cases, it should only take you a few minutes to update your proxy and firewall configurations to include them.&lt;/P&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;A special case of WSUS servers&lt;/H3&gt;
&lt;P style="margin-top: 16px;"&gt;Do you use Windows Server Update Services (WSUS) in your networks? In this environment, instead of connecting to the Windows Update service directly, Windows devices connect to an IT-managed WSUS server. If you're a server administrator, you orchestrate which updates are available on the WSUS server for your devices to update. And since these devices don't need to traverse a proxy or firewall for a genuine Windows Update server, the FQDN exceptions aren't necessary.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;You can require TLS connections between your devices and the WSUS server. Additionally, you have the option to certificate-pin the WSUS server to your TLS certificates, much like you do with Windows Update. To use this option, you might need to make proper proxy or firewall exceptions for any device connecting to your TLS, certificate-pinned WSUS server. To learn more about WSUS certificate pinning, see:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/scan-changes-and-certificates-add-security-for-windows-devices-using-wsus-for-up/2053668" target="_blank"&gt;Scan changes and certificates add security for Windows devices using WSUS for updates&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/intune/configmgr/sum/get-started/software-update-point-ssl" target="_blank"&gt;Configure a software update point to use TLS/SSL with a PKI certificate&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;An easy fix is good news&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Difficulties keeping Windows devices up to date with the latest updates might have to do with the embedded network security design. Windows Update doesn't trust servers that don't have TLS certificates issued by an actual Windows Update trust anchor. Your firewalls and proxies might block access to the trustworthy and necessary Windows Update service if your configuration is either intercepting TLS connections or isn't passing TLS requests through for the necessary DNS subdomains. The good news is that there's normally an easy fix for Windows Update connection issues. Essentially, make sure to trust FQDN subdomains of the recommended DNS subdomains.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Here are some resources to help you learn even more:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/windows/security/book/operating-system-security-network-security" target="_blank"&gt;Windows 11 Security Book: Network security&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/windows-server/networking/dns/dns-overview" target="_blank"&gt;What is Domain Name System (DNS)?&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/windows/deployment/update/how-windows-update-works" target="_blank"&gt;How Windows Update works&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;P style="font-size: 14px;"&gt;Continue the conversation. Find best practices. Bookmark the &lt;A href="http://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;Windows Tech Community&lt;/A&gt;. Looking for support? Visit &lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;Windows on Microsoft Q&amp;amp;A&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/configuring-firewall-and-proxies-for-smooth-windows-updates/ba-p/4517913</guid>
      <dc:creator>Dave_Roth</dc:creator>
      <dc:date>2026-05-11T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Advancing print readiness across the Windows on Arm ecosystem</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/advancing-print-readiness-across-the-windows-on-arm-ecosystem/ba-p/4515926</link>
      <description>&lt;P&gt;Momentum across the Windows on Arm ecosystem continues to build as more commercial and retail customers adopt Arm-based Windows devices for everyday work. Customers are realizing tangible benefits such as improved performance per watt, longer battery life, quieter devices, and more consistent responsiveness across native Arm64 application workflows. As adoption grows, however, success depends not only on application availability, but on the readiness of foundational systems that customers rely on regardless of device or architecture. Printing, deeply embedded in business operations, remains one of the critical workflows that must keep pace.&lt;/P&gt;
&lt;P&gt;Microsoft’s &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/building-a-modern-secure-and-seamless-print-experience-for-windows/4499051" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Modern Print Strategy&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt; provides an important foundation for this transition, modernizing printing on Windows through standardized protocols, inbox class drivers, and extensible Print Support Apps. This approach aligns closely with the needs of Windows on Arm by reducing complexity and enabling consistent, secure printing across architectures. At the same time, Microsoft recognizes that many commercial customers depend on established print workflows, and that hardware partners continue to support these needs through universal and native print drivers. Together, these models enable both software developers and hardware partners to extend reliable print solutions to Windows on Arm, consistently and reliably.&lt;/P&gt;
&lt;P&gt;Below is a snapshot of print companies that have recently delivered or expanded solutions supporting Windows on Arm, demonstrating how the modern print ecosystem is evolving to meet customer expectations as Windows devices and the workloads they power continue to modernize.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; height: 3490.44px; border-width: 1px;"&gt;&lt;colgroup&gt;&lt;col style="width: 50%" /&gt;&lt;col style="width: 50%" /&gt;&lt;/colgroup&gt;&lt;tbody&gt;&lt;tr style="height: 216.621px;"&gt;&lt;td style="height: 216.621px;"&gt;&amp;nbsp;&lt;img /&gt;&lt;/td&gt;&lt;td style="height: 216.621px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://support.hp.com/us-en/product/details/hp-universal-print-driver-series-for-windows/503548" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;HP Universal Print Solutions&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;HP provides universal print driver solutions that streamline support across diverse HP device fleets.&amp;nbsp; &lt;/SPAN&gt;&lt;A href="https://support.hp.com/us-en/help/smartupd" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;The HP Universal Print Driver (UPD)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://support.hp.com/us-en/product/details/hp-universal-print-driver-series-for-windows/503548" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;HP Smart Universal Print Driver (SUPD)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;enable consistent printing without requiring model-specific drivers. HP offers Windows 11 Arm64 support enabling Windows on Arm devices to print reliably to&amp;nbsp;supported&amp;nbsp;HP printers using a unified driver platform.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 272.59px;"&gt;&lt;td style="height: 272.59px;"&gt;&lt;img /&gt;&amp;nbsp;&lt;/td&gt;&lt;td style="height: 272.59px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://apps.microsoft.com/detail/9n1kvpcjp303?hl=en-US&amp;amp;gl=US" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;HP Print Support Application&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The HP Print Support Application, previously known as the HP Universal Print Application, enhances the printing experience for HP devices configured with the Microsoft IPP Class Driver. Developed on the Windows Print Support App (PSA) framework, it works seamlessly with Microsoft’s modern IPP-based print architecture to deliver features and functionality beyond the standard class driver. The application is compatible with Windows 11, including Arm64 systems, and supports a broad range of HP printers, with additional models being added regularly.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 244.605px;"&gt;&lt;td style="height: 244.605px;"&gt;&amp;nbsp;&lt;img /&gt;&lt;/td&gt;&lt;td style="height: 244.605px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://www.uniflow.global/en/products/uniflow-online/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;uniFLOW Online&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;uniFLOW Online is a cloud native print and scan management solution built on Microsoft Azure that eliminates on-premises print servers while providing centralized control, security, and cost visibility across distributed environments. With support for Windows 11 devices on both AMD64 and Arm64 (including Copilot+ PCs), uniFLOW Online enables secure, consistent printing and scanning across modern Windows hardware using Microsoft Modern Print and Zero Trust cloud workflows.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 244.605px;"&gt;&lt;td style="height: 244.605px;"&gt;&amp;nbsp;&lt;img /&gt;&lt;/td&gt;&lt;td style="height: 244.605px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://www.uniflow.global/en/products/uniflow/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;uniFLOW&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;uniFLOW is an enterprise print, scan, and device management platform supporting server&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;based and hybrid deployments, enabling secure workflows across complex, mixed&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;fleet environments. With the uniFLOW 2025 LTS release, the platform adds support for Windows Protected Print and Windows 11 Arm64 PCs, so organizations can integrate modern Windows on Arm devices into existing on&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;premises&amp;nbsp;and hybrid print infrastructures.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 216.621px;"&gt;&lt;td style="height: 216.621px;"&gt;&amp;nbsp;&lt;img /&gt;&lt;/td&gt;&lt;td style="height: 216.621px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://www.papercut.com/products/mf/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;PaperCut MF&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;PaperCut MF is an enterprise print management solution providing centralized control and security across printing, copying, and scanning. It bridges the gap when manufacturers lack native Arm drivers by supporting Windows on Arm devices with compatible clients. This enables organizations to manage mixed-architecture fleets while ensuring secure, policy-driven printing across modern Windows hardware. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 216.621px;"&gt;&lt;td style="height: 216.621px;"&gt;&amp;nbsp;&lt;img /&gt;&lt;/td&gt;&lt;td style="height: 216.621px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://www.papercut.com/products/hive/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;PaperCut Hive&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;PaperCut Hive is a cloud-native print management solution that provides centralized control and secure printing without the need for on-prem infrastructure. Where manufacturers do not have Arm drivers, it helps ensure seamless printing across Arm64 and x64 systems. This enables organizations to confidently deploy modern Windows hardware while maintaining consistent policy enforcement across distributed fleets. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 328.559px;"&gt;&lt;td style="height: 328.559px;"&gt;&amp;nbsp;&lt;img /&gt;&lt;/td&gt;&lt;td style="height: 328.559px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://www.pharos.com/products/cloud-platform/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Pharos Cloud&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Pharos Cloud is a secure, cloud-based print management platform that helps organizations reduce costs, eliminate print servers, and simplify IT operations. It enables direct IP and secure release printing from any location and streamlines management of enterprise printing across multi-vendor fleets. Pharos Cloud supports Copilot+ PCs, Windows on Arm, and Windows Protected Print using the Microsoft IPP Class Driver rather than legacy manufacturer drivers. This approach to cloud-based printing provides a supported path for enterprises introducing Arm-based Windows devices and Windows Protected Print while maintaining centralized control.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 272.59px;"&gt;&lt;td style="height: 272.59px;"&gt;&amp;nbsp;&lt;img /&gt;&lt;/td&gt;&lt;td style="height: 272.59px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://www.ricoh.com/products/ricoh-print-support-application" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;RICOH Print Support Application&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Ricoh Print Support Application enables advanced, printer&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;specific functionality for Ricoh devices on modern Windows systems by restoring vendor features on top of Microsoft’s driverless IPP printing model. The application runs on both 64&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;bit Windows and Windows on Arm, supporting Windows 11 Arm64 PCs while aligning with Windows Protected Print and Microsoft’s move away from third&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;party printer drivers. Organizations can use secure and authenticated printing with Ricoh printers without installing traditional device drivers.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 310.57px;"&gt;&lt;td style="height: 310.57px;"&gt;&amp;nbsp;&lt;img /&gt;&lt;/td&gt;&lt;td style="height: 310.57px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://knowledge.tungstenautomation.com/bundle/z-kb-articles-salesforce9/page/36859.html" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Printix Client for Windows&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Tungsten Printix is a cloud-based, serverless print management solution designed to streamline printing across distributed and hybrid environments. With support for Windows on Arm devices through the Printix client, organizations can seamlessly manage print queues, drivers, and policies across both Arm64 and x64 Windows systems. This eliminates the need for on-premises print servers or VPN dependencies, providing robust security in a cloud-managed infrastructure with authenticated access ensuring, a reliable and efficient printing experience.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 272.59px;"&gt;&lt;td style="height: 272.59px;"&gt;&amp;nbsp;&lt;img /&gt;&lt;/td&gt;&lt;td style="height: 272.59px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://vasion.com/print/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Vasion Print&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Vasion Print delivers Intelligent Print Automation for commercial and enterprise organizations: modernizing print infrastructure, consolidating print environments, and automating print and document workflows across distributed Windows environments. Built on a cloud-native, serverless architecture, Vasion Print eliminates traditional print servers through centralized, direct-IP printing and automated driver deployment. Native support for Windows on Arm means organizations can manage Arm64 and x64 devices seamlessly from a single SaaS console.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 188.637px;"&gt;&lt;td style="height: 188.637px;"&gt;&amp;nbsp;&lt;img /&gt;&lt;/td&gt;&lt;td style="height: 188.637px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://www.xerox.com/en-us/software-solutions/global-printer-driver" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Xerox Global Print Driver&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Universal PCL and PostScript print driver that enables consistent printing across mixed device fleets without model&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;specific drivers. Xerox provides Windows 11 Arm64 versions of the Global Print Driver, allowing Windows on Arm devices to print to supported Xerox and compatible printers using a single universal driver.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 272.59px;"&gt;&lt;td style="height: 272.59px;"&gt;&amp;nbsp;&lt;img /&gt;&lt;/td&gt;&lt;td style="height: 272.59px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://www.xerox.com/en-us/office/software-solutions/xerox-print-and-scan-experience-app" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Xerox Print and Scan Experience App&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This desktop application delivers advanced print and scan features for Xerox and Lexmark devices using Microsoft’s modern IPP&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;based printing model. The app includes Xerox Print Support Application (PSA), restoring device&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;specific&amp;nbsp;functionality when using Microsoft IPP Class Driver or Universal Print Class Driver queues, and supports Windows 11 systems including Arm64 devices. This enables secure, driverless printing and scanning aligned with Windows Protected Print without relying on traditional&amp;nbsp;third&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;party drivers.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 244.605px;"&gt;&lt;td style="height: 244.605px;"&gt;&amp;nbsp;&lt;img /&gt;&lt;/td&gt;&lt;td style="height: 244.605px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://www.xerox.com/en-us/office/software-solutions/xerox-workplace-cloud" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Xerox Workp&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;l&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;ace Cloud&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Xerox® Workplace Cloud is a cloud&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;based&amp;nbsp;print management solution that centralizes printer discovery, secure release, and usage tracking across distributed environments. It provides native client support for Windows on Arm devices, with&amp;nbsp;Arm&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;compatible Workplace Cloud clients available for managed deployment, enabling organizations to manage printing consistently across Arm64 and x64 Windows fleets without on&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;premises print servers.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 188.637px;"&gt;&lt;td style="height: 188.637px;"&gt;&amp;nbsp;&lt;img /&gt;&lt;/td&gt;&lt;td style="height: 188.637px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://www.zebra.com/us/en/support-downloads/printers/printer-drivers.html?nocache=&amp;amp;downloadId=4fd677df-5ae1-4e2f-89ce-f33134dc1e70" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Zebra ZDesigner Printer Driver&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Zebra ZDesigner Printer Driver v10 is a modern, Windows&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;based&amp;nbsp;ZPL printer driver meant for&amp;nbsp;Link&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;OS Zebra label printers. It enables full-featured printing, configuration, and management on supported Zebra devices using Windows operating systems running on machines with x86 / x64 or Arm processors.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;As more organizations adopt Windows on Arm, the opportunity for print and device software vendors continues to grow. At the same time, enabling support across architectures can introduce real engineering challenges,&amp;nbsp;from validating compatibility to modernizing legacy components.&amp;nbsp;Microsoft App Assure, through its&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://blogs.windows.com/windowsdeveloper/2024/03/13/announcing-worldwide-availability-of-arm-advisory-service-for-developers/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Arm Advisory Service&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, is available to help navigate these transitions.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Listen to what some partners have to say about working with us:&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;colgroup&gt;&lt;col style="width: 35.7755%" /&gt;&lt;col style="width: 64.294%" /&gt;&lt;/colgroup&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-align-center"&gt;&lt;img /&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Matthew Coad, &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Head of Self Hosted Software / Sales and Channel APAC, PaperCut&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;“Working with Microsoft’s App Assure team enabled us to support customers moving to ARM64 devices while&amp;nbsp;maintaining&amp;nbsp;print continuity and resolving driver compatibility challenges. This collaboration allowed us to deliver PaperCut Hive and PaperCut MF as reliable solutions for mixed x64 and ARM64 environments, ensuring consistent,&amp;nbsp;high&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;quality printing as organizations modernize their Windows fleets.”&lt;/SPAN&gt;&lt;/EM&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-align-center"&gt;&lt;img /&gt;&lt;SPAN data-contrast="auto"&gt;Julian Sharpe, Worldwide VP Engineering, Pharos Systems International&lt;/SPAN&gt;&lt;/td&gt;&lt;td&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;“Working with Microsoft’s App Assure team helped us to support customers adopting Windows on Arm and Windows Protected Print by&amp;nbsp;validating&amp;nbsp;cloud printing across mixed fleet environments. Through our close collaboration, shared customers can now standardize on Pharos Cloud to enhance security and centralize print insights, all built on a modern, IPP-based foundation.”&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The App Assure team&amp;nbsp;works directly with developers to reduce friction, resolve compatibility issues, and accelerate readiness for Arm-based Windows devices,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;through direct engineering support.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; Whether&amp;nbsp;you’re&amp;nbsp;modernizing an existing print solution or building something new,&amp;nbsp;we’re&amp;nbsp;here to help you deliver fast, reliable, and high-quality experiences on Windows.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;If you’re a company looking to support Windows on Arm or extend your solution using modern print capabilities, reach out via our &lt;/SPAN&gt;&lt;A href="https://aka.ms/AppAssureRequest" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;intake form&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;to get started.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;Continue the conversation. Find best practices. Bookmark the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Tech Community&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;, then follow us on&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/company/windows-it-pro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;or&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://twitter.com/mswindowsitpro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSWindowsITPro&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;for updates. Looking for support? Visit&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows on Microsoft Q&amp;amp;A&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/advancing-print-readiness-across-the-windows-on-arm-ecosystem/ba-p/4515926</guid>
      <dc:creator>Phani_Krishna_Maringanti</dc:creator>
      <dc:date>2026-05-06T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Windows news you can use: April 2026</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-news-you-can-use-april-2026/ba-p/4516352</link>
      <description>&lt;P&gt;This month, the Windows Accessibility team delivered its first interactive deep dive on the Tech Community featuring demos of the latest improvements in Narrator and live Q&amp;amp;A. &lt;A href="https://techcommunity.microsoft.com/event/windowsevents/get-more-done-with-narrator/4508931" target="_blank" rel="noopener"&gt;Watch it on demand&lt;/A&gt; to help ensure your organization is taking advantage of the latest Windows 11 accessibility features. Create a digital environment where everyone is empowered to achieve more. &lt;BR /&gt;&lt;BR /&gt;We also continue to host Ask Microsoft Anything (AMA) here on the Tech Community to help you plan for older Secure Boot certificates starting to expire in June. &lt;A href="https://techcommunity.microsoft.com/event/windowsevents/ask-microsoft-anything-secure-boot---april-2026/4501308" target="_blank" rel="noopener"&gt;Watch this month's AMA on demand&lt;/A&gt;—and save the date for the &lt;A href="https://techcommunity.microsoft.com/event/windowsevents/ask-microsoft-anything-secure-boot---may-2026/4513524" target="_blank" rel="noopener"&gt;next Secure Boot AMA on May 18&lt;/A&gt; if you have any outstanding questions.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Now on to more highlights from April with this month's edition of Windows news you can use.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;New in Windows update and device management&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;[APPS] [STORE] – You can now &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/dynamically-remove-apps-from-managed-windows-11-devices/4516291" target="_blank" rel="noopener"&gt;use policy to remove select pre-installed Microsoft Store apps&lt;/A&gt; on devices running Windows 11, version 25H2 or version 24H2. In addition, a new dynamic app removal list lets you remove any preinstalled MSIX/APPX app by referencing its Package Family Name (PFN).&lt;/LI&gt;
&lt;LI&gt;[APPS] [INTUNE] – App inventory in Microsoft Intune now updates Windows apps on a more frequent schedule. It only uploads changes since the last sync, which can help limit additional network usage. To take advantage of this capability, you'll need to set a new &lt;A href="https://learn.microsoft.com/intune/device-configuration/settings-catalog/?tabs=sc-search-filter%2Csc-reporting" target="_blank" rel="noopener"&gt;device configuration policy&lt;/A&gt; and assign that policy to desired corporate-owned Windows 11 devices enrolled in Microsoft Entra ID.&lt;/LI&gt;
&lt;LI&gt;[W365] – A &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/introducing-the-new-windows-365-monitoring-and-reporting-platform-%E2%80%94-now-in-publi/4505355" target="_blank" rel="noopener"&gt;new Windows 365 monitoring and reporting platform&lt;/A&gt;, now in public preview, consolidates Cloud PC health, performance, and configuration data into integrated dashboards in Intune.&lt;/LI&gt;
&lt;LI&gt;[W365] – &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/public-preview-user-initiated-provisioning-for-windows-365-reserve/4512474" target="_blank" rel="noopener"&gt;User-initiated provisioning for Windows 365 Reserve&lt;/A&gt; is now in public preview. This IT-enabled setting allows users to initiate provisioning themselves, within existing policy and security controls, from Windows App.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;New in Windows security&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;[AUTOPATCH] – A &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/protect-your-estate-reassess-your-windows-update-policies/4515228" target="_blank" rel="noopener"&gt;new Windows Autopatch report&lt;/A&gt; reflects updated recommendations on patch compliance. It also highlights risk exposure based on configured policies and update rollout status across your estate.&lt;/LI&gt;
&lt;LI&gt;[HARDENING] [ADMIN] – Administrative actions are undergoing &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/hardening-administrative-actions-what-it-pros-need-to-know/4503956" target="_blank" rel="noopener"&gt;hardening changes&lt;/A&gt; that reduce the risk of privilege escalation and unauthorized access on Windows devices. Specifically, Windows now detects and blocks authentication attempts between machines that share duplicate SIDs.&lt;/LI&gt;
&lt;LI&gt;[HOTPATCH] – Need to explain the security architecture advantage behind hotpatch updates? &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/how-hotpatch-updates-help-keep-windows-secure-by-design/4508188" target="_blank" rel="noopener"&gt;Explore a concise explanation&lt;/A&gt; of how they support continuous protection, accelerate patch compliance, and reduce operational disruption.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;New in AI&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;The following AI-powered capabilities are gradually rolling out beginning with the &lt;A href="https://support.microsoft.com/topic/april-14-2026-kb5083769-os-builds-26200-8246-and-26100-8246-22f90ae5-9f26-40ac-9134-6a586a71163b" target="_blank" rel="noopener"&gt;April 2026 security update&lt;/A&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;[NARRATOR] – Narrator now works with Copilot on all Windows 11 devices. Get instant, on‑device descriptions and the ability to select &lt;STRONG&gt;Ask Copilot&lt;/STRONG&gt; for more detail.&lt;/LI&gt;
&lt;LI&gt;[INPUT] – With updates to the Pen settings page, users can now enable the pen tail button to open the same app as the Copilot key.&lt;/LI&gt;
&lt;LI&gt;[COPILOT] - A new &lt;A href="https://learn.microsoft.com/windows/client-management/mdm/policy-csp-windowsai?source=docs#removemicrosoftcopilotapp" target="_blank" rel="noopener"&gt;RemoveMicrosoftCopilotApp policy&lt;/A&gt; setting allows you to uninstall Copilot from devices in your organization in a non-disruptive way.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;To learn about latest capabilities for Copilot+ PCs, visit the &lt;A href="https://www.microsoft.com/en-us/windows/business/roadmap" target="_blank" rel="noopener"&gt;Windows Roadmap&lt;/A&gt; and filter Platform by “Copilot+ PC Exclusives.”&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;New in Windows Server&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;For the latest features and improvements for Windows Server, see the &lt;A href="https://support.microsoft.com/topic/windows-server-2025-update-history-10f58da7-e57b-4a9d-9c16-9f1dcd72d7d7" target="_blank" rel="noopener"&gt;Windows Server 2025 release notes&lt;/A&gt; and &lt;A href="https://support.microsoft.com/topic/windows-server-version-23h2-update-history-68c851ff-825a-4dbc-857b-51c5aa0ab248" target="_blank" rel="noopener"&gt;Windows Server, version 23H2 release notes&lt;/A&gt;.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;[FEATURE UPDATES] – Running Windows Server 2022 or Windows Server 2019? You can now &lt;A href="https://techcommunity.microsoft.com/blog/windowsservernewsandbestpractices/opt-in-windows-server-2025-feature-update-from-the-ws-2022-and-ws-2019-settings-/4515961" target="_blank" rel="noopener"&gt;opt in to the Windows Server 2025 feature update&lt;/A&gt; from the Settings dialog.&lt;/LI&gt;
&lt;LI&gt;[EVENT] – The &lt;A href="https://techcommunity.microsoft.com/blog/windowsservernewsandbestpractices/save-the-date-windows-server-summit-%E2%80%93-may-11-13-2026/4501057" target="_blank" rel="noopener"&gt;Windows Server Summit&lt;/A&gt; starts next Monday and runs May 11-13, 2026 from 7:00 a.m. to 12:00 p.m. PDT. If you haven't already, make sure to add sessions of interest to your calendar and &lt;A href="https://aka.ms/WindowsServerSummit/VIP" target="_blank" rel="noopener"&gt;register for the VIP experience&lt;/A&gt;. As a VIP, you'll receive access to the presentation decks and a chance to participate in a private virtual roundtable with the Windows Server product team.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;New in productivity and collaboration&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Install the April 2026 security update for &lt;A href="https://support.microsoft.com/help/5083769" target="_blank" rel="noopener"&gt;Windows 11, versions 25H2 and 24H2&lt;/A&gt; to get these and other capabilities, which will be rolling out gradually:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;[FILE EXPLORER] – You can use Voice Typing (&lt;STRONG&gt;Windows logo key + H&lt;/STRONG&gt;) when renaming a file in File Explorer.&lt;/LI&gt;
&lt;LI&gt;[SETTINGS] – The device information card on the Settings Home page simplifies key device specifications. Experience the improved consistency across the end-to-end flow from the Home Card to the &lt;STRONG&gt;Settings &lt;/STRONG&gt;&amp;gt; &lt;STRONG&gt;System &lt;/STRONG&gt;&amp;gt; &lt;STRONG&gt;About &lt;/STRONG&gt;page. It should now be easier to scan and understand information.&lt;/LI&gt;
&lt;LI&gt;[DISPLAY] – When you use a native USB4 monitor connection, the USB controller can now enter its lowest power level while the PC is sleeping, which helps save battery life.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;New features and improvements are coming in the May 2026 security update. You can preview them by installing the April 2026 optional non-security update for &lt;A href="https://support.microsoft.com/topic/april-30-2026-kb5083631-os-builds-26200-8328-and-26100-8328-preview-db6b5d64-ff7e-4fea-8f47-bde66c97d759" target="_blank" rel="noopener"&gt;Windows 11, versions 25H2 and 24H2&lt;/A&gt;. This update includes the gradual rollout of:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;[FILE EXPLORER] – View and Sort preferences are preserved in folders such as Downloads and Documents when apps launch File Explorer directly to those locations. Archive formats now include uu, cpio, xar, and NuGet Packages (nupkg).&lt;/LI&gt;
&lt;LI&gt;[INPUT] – Voice typing animations on the touch keyboard now appear directly on the dictation key, helping you stay focused without extra visual distractions.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;Also, take note that the Windows Insider Program team is &lt;A href="https://blogs.windows.com/windows-insider/2026/04/10/improving-your-windows-insider-experience/" target="_blank" rel="noopener"&gt;simplifying the Insider experience&lt;/A&gt; by moving to two primary channels: Experimental and Beta. Other changes to the program include making changes behind-the-scenes to enable Insiders to use an in-place upgrade to hop between versions.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Lifecycle reminders&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Check out our lifecycle documentation for the latest updates on &lt;A href="https://learn.microsoft.com/windows/whats-new/deprecated-features" target="_blank" rel="noopener"&gt;Deprecated features in the Windows client&lt;/A&gt; and &lt;A href="https://learn.microsoft.com/windows-server/get-started/removed-deprecated-features-windows-server-2025" target="_blank" rel="noopener"&gt;Features removed or no longer developed starting with Windows Server 2025&lt;/A&gt;.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Additional resources&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Looking for the latest news and previews for Windows, Copilot, Copilot+ PCs, the Windows and Windows Server Insider Programs, and more? Check out these resources:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/windows/business/roadmap" target="_blank" rel="noopener"&gt;Windows Roadmap&lt;/A&gt; for new Copilot+ PCs and Windows features – filter by platform, version, status, and channel or search by feature name&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/copilot/microsoft-365/release-notes?tabs=all" target="_blank" rel="noopener"&gt;Microsoft 365 Copilot release notes&lt;/A&gt; for latest features and improvements&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://blogs.windows.com/windows-insider/" target="_blank" rel="noopener"&gt;Windows Insider Blog&lt;/A&gt; for what's available in the Canary, Dev, Beta, or Release Preview Channels&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/windows-server/discussions/windowsserverinsiders" target="_blank" rel="noopener"&gt;Windows Server Insider&lt;/A&gt; for feature preview opportunities&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://support.microsoft.com/topic/understanding-update-history-for-windows-insider-preview-features-fixes-and-changes-bb9dd4b1-9d2b-4753-8b23-ce90e62f6845" target="_blank" rel="noopener"&gt;Understanding update history for Windows Insider preview features, fixes, and changes&lt;/A&gt; to learn about the types of updates for Windows Insiders&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Join the conversation&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;If you're an IT admin with questions about managing and updating Windows, add our monthly &lt;A href="https://aka.ms/Windows/OfficeHours" target="_blank" rel="noopener"&gt;Windows Office Hours&lt;/A&gt; to your calendar. We assemble a crew of Windows, Windows 365, security, and Intune experts to help answer your questions and provide tips on tools, best practices, and troubleshooting.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Finally, we're always looking to improve this monthly summary. Drop us a note in the Comments and let us know what we can do to make this more useful for you!&lt;/P&gt;
&lt;HR /&gt;
&lt;P style="font-size: 14px;"&gt;Continue the conversation. Find best practices. Bookmark the &lt;A href="http://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;Windows Tech Community&lt;/A&gt;. Looking for support? Visit &lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;Windows on Microsoft Q&amp;amp;A&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2026 04:24:59 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-news-you-can-use-april-2026/ba-p/4516352</guid>
      <dc:creator>Chris_Morrissey</dc:creator>
      <dc:date>2026-05-08T04:24:59Z</dc:date>
    </item>
    <item>
      <title>Windows 365 and Azure Virtual Desktop: Expanding access</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-365-and-azure-virtual-desktop-expanding-access/ba-p/4515931</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The way people work continues to evolve—and so do the ways organizations use Windows delivered from the cloud. From small businesses without dedicated IT teams, to enterprises modernizing existing virtualization deployments, to shift workers who need flexibility without a dedicated device, the range of scenarios continues to grow. Today’s updates build on that momentum—expanding how Windows 365 and Azure Virtual Desktop support more environments, more customers, and more ways of working.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Windows 365 and Azure Virtual Desktop have always been built to meet customers where they are and support their future ambitions.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Today, we’re announcing updates that extend that flexibility even further—helping more customers adopt cloud-powered Windows experiences in ways that fit their reality.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;Making Cloud PCs more accessible for small and medium businesses&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Small-to-medium-sized businesses don’t buy or use technology the way large enterprises do. Windows 365 Business is designed for smaller organizations (up to 300 seats) that want ready-to-use Cloud PCs with simple management—without needing other Microsoft licenses to get started. To make Windows 365 Business even more accessible, &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;we're&amp;nbsp;reducing the list price of Windows 365 Business by 20%&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;across all Cloud PC configurations as of May 1, 2026.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;In addition to our permanent price drop,&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;eligible new customers can&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/windows-365/what-is-windows-365" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;save an additional 20% off&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; the new lower price through June&amp;nbsp;30&lt;SUP&gt;1&lt;/SUP&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This price change helps reduce the&amp;nbsp;&amp;nbsp;barriers to getting started with Windows 365. Cloud PCs are now even more accessible to smaller organizations, helping them give their people a full, secured Windows experience from the cloud.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-contrast="none"&gt;A new name for Windows 365 Frontline—and a broader mission&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Shift workers, part-time employees, and others who only need a computing device for periodic use have historically shared physical PCs at a desk on-site. In a workplace that's increasingly distributed, that model breaks down: workers can't easily share a device they no longer sit next to. And for many organizations, equipping workers with a dedicated PC isn't economically feasible—especially when many only need access for a few hours a day.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;That's the gap &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Windows 365 Flex &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;(formerly Windows 365 Frontline) is built to close.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Designed for organizations of any size, Windows 365 Flex&lt;SPAN class="lia-text-color-8"&gt;&amp;nbsp;&lt;/SPAN&gt;is a secured, flexible solution that enables organizations to deliver Cloud PCs in ways that fit how employees work, whether through shared access or cost-efficient dedicated experiences.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;It gives organizations the flexibility to extend cost-effective, personalized technology access to any employee who doesn't require a dedicated PC of their own. Once employees sign in, they have immediate access to all their personalized resources—apps, data, desktops, and settings—so they can hit the ground running. Windows 365 Flex can also be deployed in shared mode, where the Cloud PC can be reset to a fresh state between each use, or optionally persists a user’s settings and application data across sessions. Windows 365 Flex&lt;SPAN class="lia-text-color-8"&gt;&amp;nbsp;&lt;/SPAN&gt;in shared mode also serves as the foundation for Windows 365 Cloud Apps—an app-only experience that provides users with access to individual applications without requiring a dedicated Cloud PC. Windows 365 Flex can also be provisioned in configurations that support the requirements of developers.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Since Windows 365 Frontline was first launched, we have seen it adopted more broadly across organizations with part-time employees, seasonal staff, contractors, and roles that require occasional or task-based PC access. The new name, Windows 365 Flex, better represents this flexibility. It reflects a broader shift—from solving a niche scenario to enabling workers of all types to participate in the modern organization in the way that works best for them.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The name change does not affect how the service works or how it is purchased.&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;Azure Virtual Desktop Hybrid now in public preview&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For many organizations, the journey to the cloud isn’t a single step—it’s a path shaped by regulatory needs, existing investments, and operational realities. For customers who can't move every workload to the public cloud overnight, &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Azure Virtual Desktop Hybrid&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;opens a new door. Now in public preview, it extends the Microsoft cloud-managed Virtual Desktop Infrastructure (VDI) service to on-premises environments—without requiring customers to replace existing infrastructure.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;With Azure Virtual Desktop Hybrid, customers can run Azure Virtual Desktop session hosts on-premises using their existing hardware and preferred hypervisor connected through Microsoft Azure Arc. The Azure Virtual Desktop service remains in Azure, while session hosts can be deployed anywhere on-premises Azure Arc-enabled servers are supported. Users can access their desktops through the familiar Windows App.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This matters because it gives customers a phased, lower-risk path to cloud adoption:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Modernize legacy VDI environments at their own pace&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;,&lt;/STRONG&gt; preserving investments in datacenters, hardware, and operational tools.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Adopt cloud-managed desktops incrementally&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;, &lt;/STRONG&gt;with a clear path to migrate session hosts to Azure when the time is right.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Keep existing partner integrations&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;for virtual machine management and provisioning.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In other words, customers now have a way to bring the simplicity of cloud-managed desktops to workloads that still need to live on-premises. Azure Virtual Desktop Hybrid is available to customers with an Azure subscription as part of the public preview. For instructions on how to get started with the Azure Virtual Desktop Hybrid public preview, please visit this &lt;A class="lia-external-url" href="http://aka.ms/AVDHybridDocs" target="_blank" rel="noopener"&gt;link&lt;/A&gt;. &lt;SPAN data-teams="true"&gt;You can also learn more about Azure Virtual Desktop Hybrid by contacting our launch partners LoginVSI, Nerdio, and Nutanix.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;A complete Windows cloud portfolio for every scenario&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Windows 365 was built on a simple idea: the familiar Windows experience, securely streamed from the Microsoft Cloud to any device, anywhere. Azure Virtual Desktop was built to give organizations the power and customizability of cloud VDI on their own terms. Together, these Windows cloud solutions are how Microsoft supports the full breadth of how people work.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;A 20% list price reduction makes Windows 365 Business a better fit for the SMBs it's designed for. And renaming Windows 365 Frontline to Windows 365 Flex&lt;SPAN class="lia-text-color-8"&gt;&amp;nbsp;&lt;/SPAN&gt;reflects an expanded mission: closing the digital divide for the periodic-use workers who have been left out too often. Public preview of Azure Virtual Desktop Hybrid brings cloud-managed VDI to environments that need to stay on premises.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Different audiences. Different segments. Different starting points. One portfolio that expands to meet their needs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;To learn more:&lt;/SPAN&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/AVDHybridDocs" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Azure Virtual Desktop Hybrid public preview&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/windows-365/business/compare-plans-pricing" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows 365 Business pricing and plans&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;Continue the conversation. Find best practices. Bookmark the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Tech Community&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;, then follow us on&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/company/windows-it-pro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;or&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://twitter.com/mswindowsitpro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSWindowsITPro&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;for updates. Looking for support? Visit&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows on Microsoft Q&amp;amp;A&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:257}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;FOOTER style="font-size: 12px; color: #666; margin-top: 40px;"&gt;
&lt;P&gt;&lt;SUP&gt;1&lt;/SUP&gt;Microsoft reserves the right to discontinue this promotion, and to modify these policies and the promotion’s terms and conditions at any time.&lt;/P&gt;
&lt;P&gt;This offer includes licenses for Windows 365 Enterprise, Business, Frontline, and Government (available in the United States only). &lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;To &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;purchase&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt; Windows 365 Frontline, please &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/windows-365/contact-sales" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;contact our Sales team&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;For Windows 365 Government licenses, visit &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;our&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2328611" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Government page&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;This offer runs from May 1, &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;2025&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt; to June 30,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;2026&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;&amp;nbsp;and is for customers not currently subscribed to Windows 365. Transactions must be processed through Microsoft’s operations center before 11:00 PM Pacific Time on June 30, 2026. This offer is non-transferable and cannot be combined with any other offer or discount on Windows 365. This offer is available only once per customer. The discount price will be in effect for the duration of the purchase commitment. Purchases made prior to the effective date of the offer are not eligible. Taxes, if any, are the sole responsibility of the recipient.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335557856&amp;quot;:16250871,&amp;quot;335559685&amp;quot;:360,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/FOOTER&gt;</description>
      <pubDate>Mon, 04 May 2026 16:59:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-365-and-azure-virtual-desktop-expanding-access/ba-p/4515931</guid>
      <dc:creator>Tristan Scott</dc:creator>
      <dc:date>2026-05-04T16:59:00Z</dc:date>
    </item>
    <item>
      <title>Windows 365 for Agents now in public preview: Run AI agents securely, at scale</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-365-for-agents-now-in-public-preview-run-ai-agents/ba-p/4513479</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="none"&gt;AI agents are rapidly evolving from tools that answer questions to performing human-level work inside an enterprise ecosystem, powering essential business workflows that have traditionally been completed manually. But while governance and policy models are emerging, one critical question remains unresolved for IT: where should agents actually&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;run&lt;/SPAN&gt;&lt;/EM&gt;&lt;SPAN data-contrast="none"&gt;?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Many applications that enterprises rely on, from legacy line-of-business systems to complex multistep workflows, were not built with APIs. As a result, critical work still happens through user interfaces, where context, data, and intent are conveyed visually. To unlock their full potential, AI agents need to interact with applications the same way people do, using a computer to interact directly through clicks, typing, and navigation. Today, many agents execute on ad&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;hoc infrastructure—local machines, shared virtual machines, or unmanaged cloud environment—creating gaps in identity, policy enforcement, auditability, and control. That makes it difficult for IT teams to confidently scale agentic workloads beyond API- or MCP-based pilots.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Today, we’re bringing&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Windows 365 for Agents&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt; to public preview (US only), providing a secured, purpose-built, IT-managed Cloud PC environment designed specifically for running AI agents at enterprise scale. Windows 365 for Agents provides agents with a dedicated, Microsoft Intune-managed Cloud PC—bringing the same identity, security, and compliance model IT already uses for employees to agent execution.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Windows 365 for Agents works alongside &lt;/SPAN&gt;&lt;A href="https://aka.ms/A365GAblog" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft A&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;gent 365&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;(now generally available&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;), which serves as the control plane for AI agents. It's where organizations define agent behavior, set up organizational policies, manage permissions, and maintain visibility into what agents are doing across the enterprise, whether those agents are built by Microsoft or third-party agent makers.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Together, these two offerings give IT teams a clear model for governing what agents can do and securely managing where that work runs, enabling organizations to move from early agent experiments to IT-managed, production-ready deployments.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Think of it this way: every employee in an organization has an identity and works on a managed device, such as a Windows 365 Enterprise Cloud PC. Now, each AI agent also has its own identity, governed through Agent 365 and running on a managed Cloud PC provided by Windows 365 for Agents. It’s the same trust model and same IT controls—now extended to AI. By extending this proven model to agent workloads, organizations gain:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Enterprise-grade identity and access controls for ever&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;y&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt; agent&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Unified device and policy management through the tools IT already use&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Global scalability and &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;geo-level&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;&amp;nbsp;data residency options&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt; to meet compliance requirements&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;How Windows 365 for Agents fits into the Microsoft AI ecosystem&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Microsoft 365 Copilot brings AI into the flow of work inside the apps employees already use. Behind it is &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Microsoft IQ&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt;, the intelligence layer that provides shared context across people, work, and the business—helping AI understand what matters in the moment and make informed decisions.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;That intelligence enables agents to reason, but completing real work—especially for AI agents that interact with UI-based or legacy applications and browsers through computer-use workflows—requires a secured place to execute. &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;STRONG&gt;Windows 365 for Agents&lt;/STRONG&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;provides that execution layer, delivering a fully managed Windows environment purpose-built for agentic workloads. Unlike ad-hoc infrastructure, Windows 365 for Agents is a complete, IT-managed Cloud PC service, with identity, security, policy, and lifecycle management handled for you.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Microsoft IQ gives agents the smarts; Windows 365 for Agents gives them the trusted runtime to get work done. All of this runs on &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Microsoft Azure&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt;, the global cloud foundation for secure, scalable AI.&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Agent 365&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;complements this model by providing the control plane to govern agent&amp;nbsp;behavior&amp;nbsp;end to end. These capabilities&amp;nbsp;combine to&amp;nbsp;form a single platform that lets organizations scale AI with confidence—without compromising trust.&lt;/SPAN&gt;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Windows 365for Agents is the foundational layer for running agents securely across first-party and third-party agent makers.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/img&gt;
&lt;H4 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;E&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;valuating Windows 365 for Agents&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Windows 365 for Agents is built for enterprise IT teams and the organizations they support, specifically those that:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Rely on applications that require UI interaction&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;STRONG&gt;, &lt;/STRONG&gt;including legacy tools, browser-based workflows, and systems where APIs alone aren't enough&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Need enterprise-grade security and compliance for AI agents&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;STRONG&gt;, &lt;/STRONG&gt;with identity governance, policy controls, and audit trails&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Want IT-managed environments for agent workloads&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;without building and&amp;nbsp;maintaining&amp;nbsp;custom infrastructure&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Are exploring human-in-the-loop models&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;where agents work alongside people, requesting approval for sensitive actions&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;This includes IT administrators, security teams, digital workplace leaders, and platform teams responsible for enabling AI safely across the organization.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;To bring this to life, &lt;/SPAN&gt;&lt;A href="http://aka.ms/W365AAdminDemo" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;this&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows 365 for Agents&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;demo&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; shows how agents move from setup to execution in a secured, managed environment.&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="lia-embeded-content" contenteditable="false"&gt;&lt;IFRAME src="https://www.youtube.com/embed/SPT32EbckVg?si=mtFlhW7YCErQz9g7" width="560" height="315" title="YouTube video player" allowfullscreen="allowfullscreen" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" frameborder="0" sandbox="allow-scripts allow-same-origin allow-forms"&gt;&lt;/IFRAME&gt;&lt;/DIV&gt;
&lt;H4 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Join the Windows 365 for Agents public preview (US only) &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:200}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Ready to try Windows 365 for Agents?&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;You will need:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Agent 365 license&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Intune license&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;An active Azure subscription to support Window 365 for Agents billing&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Setup and onboarding&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Explore Agent 365&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;to understand how agents are defined, governed, and managed&amp;nbsp;[&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/microsoft-agent-365/overview" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Agent 365 overview | Microsoft Learn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;]&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Create an agent blueprint&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;for scenarios that require Windows 365 for Agents&amp;nbsp;[&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/microsoft-agent-365/onboard" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Discover, create, and onboard an agent&amp;nbsp; | Microsoft Learn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;]&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Set up billing for Windows 365 for Agents&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;using your existing Azure subscription&amp;nbsp;[&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/windows-365/agents/billing-w365a?branch=pr-en-us-1359" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows 365 for Agents Billing | Microsoft Learn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;]&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Create a Cloud PC pool&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;for agent workloads&amp;nbsp;[&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/windows-365/agents/cloud-pc-agent-pools?branch=pr-en-us-1359" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Cloud PC Agent Pools | Microsoft Learn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;]&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Explore and validate scenarios&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;by running agents&amp;nbsp;in a secure environment&amp;nbsp;[&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/microsoft-agent-365/use" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Use and collaborate with agents in Agent 365 | Microsoft Learn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;]&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:200}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:200}"&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;Continue the conversation. Find best practices. Bookmark the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Tech Community&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;, then follow us on&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/company/windows-it-pro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;or&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://twitter.com/mswindowsitpro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSWindowsITPro&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;for updates. Looking for support? Visit&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows on Microsoft Q&amp;amp;A&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2026 15:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-365-for-agents-now-in-public-preview-run-ai-agents/ba-p/4513479</guid>
      <dc:creator>SwarnimSrivastava</dc:creator>
      <dc:date>2026-05-01T15:00:00Z</dc:date>
    </item>
    <item>
      <title>Dynamically remove apps from managed Windows 11 devices</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/dynamically-remove-apps-from-managed-windows-11-devices/ba-p/4516291</link>
      <description>&lt;P&gt;You can now use policy to remove select pre-installed Microsoft Store apps on devices running Windows 11, version 25H2 or version 24H2. We've also made a significant update to this policy: a dynamic app removal list. This feature lets you remove &lt;EM&gt;any&lt;/EM&gt; preinstalled MSIX/APPX app by referencing its Package Family Name (PFN).&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;What's the benefit? Fewer unwanted apps, simpler provisioning, and a more tailored desktop for your users. Just use a standard, policy-based approach that integrates with Microsoft Intune and Group Policy. This policy, called "Remove default Microsoft Store packages from the system," is available only on Enterprise and Education devices. The improvements are available starting with the April 2026 Windows non-security update. Additional Intune capabilities are coming.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Dynamic app removal list&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Microsoft offers a set of robust policy controls to help you customize app availability for your users. With the latest updates to the &lt;A href="https://learn.microsoft.com/windows/configuration/policy-based-inbox-app-removal/policy-based-inbox-app-removal?tabs=intune" target="_blank"&gt;RemoveDefaultMicrosoftStorePackages&lt;/A&gt; policy, you can now remove any MSIX/APPX packaged app. Just add its Package Family Name (PFN)&lt;STRONG&gt; &lt;/STRONG&gt;to the new dynamic app removal list. Today, you can use Group Policy Object (GPO) or custom OMA-URI for mobile device management (MDM).&lt;/P&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;Group Policy&lt;/H3&gt;
&lt;P style="margin-top: 16px;"&gt;Here's how you can make it work using Group Policy:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Find the app's PFN using PowerShell. Use the following example, replacing "Notepad" with your desired app:
&lt;PRE&gt;Get-AppxPackage *Notepad* | Select-Object PackageFamilyName&lt;/PRE&gt;
&lt;/LI&gt;
&lt;LI&gt;Open Group Policy Editor (gpedit.msc). Navigate to &lt;STRONG&gt;Computer Configuration&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Administrative Templates&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Windows Components&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;App Package Deployment&lt;/STRONG&gt; and select&amp;nbsp;&lt;STRONG&gt;Remove default Microsoft Store packages from the system&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Add the PFN to the multi-text list under &lt;STRONG&gt;Specify additional package family names to remove&lt;/STRONG&gt;. Enter one package family name per line.&lt;/LI&gt;
&lt;/OL&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;Custom OMA-URI&lt;/H3&gt;
&lt;P style="margin-top: 16px;"&gt;Alternatively, you can configure devices with the &lt;A href="https://learn.microsoft.com/windows/client-management/mdm/policy-csp-applicationmanagement" target="_blank"&gt;RemoveDefaultMicrosoftStorePackages Policy CSP&lt;/A&gt;. This ADMX-backed policy uses an XML payload to specify which apps to remove. For example, to remove Bing News and the Windows Alarms apps, see the last entry.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;OMA-URI: ./Device/Vendor/MSFT/Policy/Config/ApplicationManagement/RemoveDefaultMicrosoftStorePackages&lt;/LI&gt;
&lt;LI&gt;Data type: string&lt;/LI&gt;
&lt;LI&gt;Value:
&lt;PRE&gt;&amp;lt;enabled/&amp;gt;&lt;BR /&gt;&amp;lt;data id="WindowsFeedbackHub" value="false"/&amp;gt;&lt;BR /&gt;&amp;lt;data id="MicrosoftOfficeHub" value="false"/&amp;gt;&lt;BR /&gt;&amp;lt;data id="Clipchamp" value="false"/&amp;gt;&lt;BR /&gt;&amp;lt;data id="Copilot" value="false"/&amp;gt;&lt;BR /&gt;&amp;lt;data id="BingNews" value="true"/&amp;gt;&lt;BR /&gt;&amp;lt;data id="Photos" value="false"/&amp;gt;&lt;BR /&gt;&amp;lt;data id="MicrosoftSolitaireCollection" value="true"/&amp;gt;&lt;BR /&gt;&amp;lt;data id="MicrosoftStickyNotes" value="true"/&amp;gt;&lt;BR /&gt;&amp;lt;data id="MSTeams" value="false"/&amp;gt;&lt;BR /&gt;&amp;lt;data id="Todo" value="false"/&amp;gt;&lt;BR /&gt;&amp;lt;data id="BingWeather" value="true"/&amp;gt;&lt;BR /&gt;&amp;lt;data id="OutlookForWindows" value="false"/&amp;gt;&lt;BR /&gt;&amp;lt;data id="Paint" value="false"/&amp;gt;&lt;BR /&gt;&amp;lt;data id="QuickAssist" value="false"/&amp;gt;&lt;BR /&gt;&amp;lt;data id="ScreenSketch" value="false"/&amp;gt;&lt;BR /&gt;&amp;lt;data id="WindowsCalculator" value="false"/&amp;gt;&lt;BR /&gt;&amp;lt;data id="WindowsCamera" value="false"/&amp;gt;&lt;BR /&gt;&amp;lt;data id="MediaPlayer" value="false"/&amp;gt;&lt;BR /&gt;&amp;lt;data id="WindowsNotepad" value="false"/&amp;gt;&lt;BR /&gt;&amp;lt;data id="WindowsSoundRecorder" value="false"/&amp;gt;&lt;BR /&gt;&amp;lt;data id="WindowsTerminal" value="false"/&amp;gt;&lt;BR /&gt;&amp;lt;data id="GamingApp" value="true"/&amp;gt;&lt;BR /&gt;&amp;lt;data id="XboxGamingOverlay" value="true"/&amp;gt;&lt;BR /&gt;&amp;lt;data id="XboxIdentityProvider" value="true"/&amp;gt;&lt;BR /&gt;&amp;lt;data id="XboxSpeechToTextOverlay" value="true"/&amp;gt;&lt;BR /&gt;&amp;lt;data id="XboxTCUI" value="true"/&amp;gt;&lt;BR /&gt;&amp;lt;data id="DynamicRemovalList" value="Microsoft.BingNews_8wekyb3d8bbwe&amp;amp;#x0D;&amp;amp;#x0A;Microsoft.WindowsAlarms_8wekyb3d8bbwe"/&amp;gt;&lt;/PRE&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;The XML payload includes a static list of app names (preceded by "data id") and corresponding values. Apps with the value of "true" will be removed. Apps with the value of "false" won't be removed.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;You can remove additional apps by adding them to the value field of the "DynamicRemoval List" at the end of the payload. Separate multiple apps by the HTML-encoded carriage return + line feed characters ( &amp;amp;#x0D;&amp;amp;#x0A;), indicating a new line between each app name.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;IMPORTANT: &lt;/STRONG&gt;If you create a custom OMA-URI, you must open the dynamic list entry in the registry once on each device to which the policy is targeted. This helps ensure the correct format for the items in the dynamic list. Here is the entry: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Appx\RemoveDefaultMicrosoftStorePackages&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P style="margin-top: 16px;"&gt;Once configured, change happens at provisioning or on next user sign-in. The device uninstalls the apps you specify in the following two areas:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The default checkbox selections&lt;/LI&gt;
&lt;LI&gt;The dynamic PFN list&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;Removed apps remain blocked from reinstallation while the policy is active.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;IMPORTANT:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Removing an app also removes any associated on-disk app data. Therefore, notify users in advance if they need to save local data.&lt;/LI&gt;
&lt;LI&gt;You can't use the dynamic list to remove system components. These components aren't supposed to be removed.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;Prepare for Microsoft Intune capabilities&lt;/H3&gt;
&lt;P style="margin-top: 16px;"&gt;The Intune settings catalog entry for this policy doesn't yet contain the dynamic list option. It will be available in the following months.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;When this feature becomes generally available in Intune, search for &lt;STRONG&gt;"Remove Default Microsoft Store packages"&lt;/STRONG&gt; in the settings picker to locate it.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;During rollout of the updated RemoveDefaultMicrosoftStorePackages policy, devices in your environment might support different CSP versions. If a device receives a policy that doesn't match its supported schema, the policy might fail to parse and won't be applied.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;To prevent this, maintain your existing policy for older devices. Create a separate policy that includes the new dynamic app removal list for newer devices. Use Intune assignment filters or targeting rules (such as OS version or update rings) to help ensure that each device receives a compatible policy.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Once all devices are updated, and Intune fully supports the new CSP, you can safely consolidate policies.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Extended support: Windows 11, version 24H2 and later&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;The updated app removal policy is now extended to Windows 11, version 24H2 Enterprise and Education editions. Originally, you could only use this feature on devices running Windows 11, version 25H2 or newer. If your organization has standardized on the 2024 release, you can benefit from policy-driven app management without a full OS version upgrade. The same Group Policy path and enforcement behavior apply to all supported versions.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Supported Windows versions: Windows 11, version 24H2 and later&lt;/LI&gt;
&lt;LI&gt;Supported Windows editions: Enterprise and Education (Home and Pro remain unsupported)&lt;/LI&gt;
&lt;/UL&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;IMPORTANT:&lt;/STRONG&gt; Ensure that your devices have the latest cumulative updates installed to receive these improvements. You need at least the April 2026 Windows non-security update. If you're a Windows Insider, you'd have this feature with the March 13, 2026 builds in the &lt;A href="https://blogs.windows.com/windows-insider/2026/03/13/announcing-windows-11-insider-preview-build-26300-8068-dev-channel/" target="_blank"&gt;Dev&lt;/A&gt; and &lt;A href="https://blogs.windows.com/windows-insider/2026/03/13/announcing-windows-11-insider-preview-build-26220-8062-beta-channel/" target="_blank"&gt;Beta&lt;/A&gt; channels.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Control your preinstalled apps like a pro&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;With dynamic app removal, you can remove any preinstalled app with a simple policy change. Benefit from a cleaner, more controlled Windows experience across your organization, now on even more devices. Start planning this policy rollout across your enterprise today.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Have feedback? Share your thoughts in the Feedback Hub (accessible using the shortcut WIN + F) under &lt;STRONG&gt;Developer Platform&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;App Deployment&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Learn more with additional resources:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/policy-based-removal-of-pre-installed-microsoft-store-apps/4463835" target="_blank"&gt;Policy-based removal of pre-installed Microsoft Store apps&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/windows/configuration/policy-based-inbox-app-removal/policy-based-inbox-app-removal?tabs=intune" target="_blank"&gt;Policy-based in-box app removal&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/windows/client-management/mdm/policy-csp-applicationmanagement#removedefaultmicrosoftstorepackages" target="_blank"&gt;ApplicationManagement Policy CSP&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 30 Apr 2026 18:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/dynamically-remove-apps-from-managed-windows-11-devices/ba-p/4516291</guid>
      <dc:creator>Ingrid_Allen</dc:creator>
      <dc:date>2026-04-30T18:00:00Z</dc:date>
    </item>
    <item>
      <title>Public Preview: User-initiated provisioning for Windows 365 Reserve</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/public-preview-user-initiated-provisioning-for-windows-365/ba-p/4512474</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="none"&gt;When an employee loses access to their primary work device, every minute offline can impact productivity, slow progress on work, and add strain for IT teams.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Launched in December 2025, &lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/windows-365/reserve?msockid=0021ad7896ec68c6314fba79975669af" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows 365 Reserve&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;is a business continuity solution&amp;nbsp;that helps&amp;nbsp;restore employee&amp;nbsp;access&amp;nbsp;when&amp;nbsp;their primary device becomes unavailable by&amp;nbsp;providing a&amp;nbsp;Cloud PC when&amp;nbsp;it’s&amp;nbsp;needed most.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Today, we’re announcing the public preview of user‑initiated provisioning for Windows 365 Reserve. This new, IT enabled setting allows eligible users to initiate provisioning themselves within existing policy and security controls from Windows App, helping reduce the need for manual IT provisioning.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Enabling this setting helps provide eligible users with more direct access to Reserve Cloud PCs when their primary devices are unavailable&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;,&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;especially&amp;nbsp;during large-scale device disruptions, for time-critical roles, or when support teams are already under load.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;This capability was teased at Microsoft Ignite and is now available in public preview!&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Heading 2 Char"&gt;U&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 2 Char"&gt;ser-initiated provisioning&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 2 Char"&gt;&amp;nbsp;for Windows 365 Reserve&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 2 Char"&gt; is disabled by default&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;User-initiated provisioning is a new Windows App setting IT can apply to user groups in Intune.&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="none"&gt;By default, with user-initiated provisioning disabled, Windows 365 Reserve relies on IT to provision Cloud PCs on demand from Intune.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="none"&gt;With user-initiated provisioning enabled, specific user groups can also initiate provisioning themselves &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;directly from the Windows App.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;This setting is off by default, fully governed by IT, and scoped to specific Microsoft Entra ID user groups.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;What's new&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;With the setting enabled, eligible users can:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="none"&gt;Sign in to the Windows App from any device&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="none"&gt;Provision their own Windows 365 Reserve Cloud PC&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Get back to work without waiting for manual IT provisioning&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;What does&amp;nbsp;&lt;/SPAN&gt;&lt;U&gt;&lt;SPAN data-contrast="none"&gt;not&lt;/SPAN&gt;&lt;/U&gt;&lt;SPAN data-contrast="none"&gt; change&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="none"&gt;Licensing requirements remain the same&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="none"&gt;Reserve provisioning policies still govern the Cloud PC configuration&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="none"&gt;IT retains ownership of Cloud PC lifecycle and management&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="none"&gt;IT can still provision Cloud PCs from Intune as before&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="none"&gt;This does &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;not&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt; automatically provision Cloud PCs for all users&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Heading 3 Char"&gt;IT admin &lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 3 Char"&gt;configuration&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 3 Char"&gt;&amp;nbsp;for&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 3 Char"&gt;user-initiated provisioning&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;User-initiated provisioning is configured through &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Windows App settings for Windows 365 in Microsoft Intune&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Admin setup&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="5" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;In Intune, go to&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Devices &amp;gt; Windows 365 &amp;gt; Settings&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="5" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;Select &lt;STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="none"&gt;Create &amp;gt; Windows App settings (Preview)&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;img /&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="5" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;Under &lt;STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="none"&gt;Configuration settings&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="none"&gt;, enable:&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="none"&gt;Enable users to provision new Cloud PC instances&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;img /&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="5" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;Assign the policy to &lt;STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="none"&gt;Microsoft Entra ID user groups&lt;/SPAN&gt;&lt;/STRONG&gt;
&lt;OL&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="5" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;Note: Users must be licensed for Windows 365 Reserve and assigned to Reserve provisioning policies&amp;nbsp;&lt;img /&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="5" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;Review and create the policy&lt;/LI&gt;
&lt;/OL&gt;
&lt;H4&gt;&lt;SPAN data-ccp-charstyle="Heading 3 Char"&gt;End user experience&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;User steps&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="none"&gt;Sign in to the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Windows App (or web)&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;from any device&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="none"&gt;Locate the Reserve Cloud PC card&amp;nbsp;&lt;/SPAN&gt;&lt;img /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="none"&gt;Click anywhere on the card&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="none"&gt;Review and confirm to proceed with provisioning&amp;nbsp;&lt;/SPAN&gt;&lt;img /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&lt;SPAN data-contrast="none"&gt;When provisioning completes, click to connect to the Reserve Cloud PC&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;H4&gt;&lt;SPAN data-ccp-charstyle="Heading 3 Char"&gt;Try &lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 3 Char"&gt;public&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 3 Char"&gt;preview&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 3 Char"&gt;&amp;nbsp;and share feedback&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 3 Char"&gt;!&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;We’re looking forward to hearing your feedback as you test&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;&lt;STRONG&gt;public preview of&amp;nbsp;user-initiated provisioning for Windows 365 Reserve&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;!&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="none"&gt;What scenarios does this unlock for your organization?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="none"&gt;Which user groups benefit most?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="none"&gt;What additional controls or signals would you want to see?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Let us know in the comments below.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;To learn more about user-initiated provisioning for Windows 365 Reserve, see &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/windows-365/enterprise/windows-365-reserve-manage" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Manage Windows 365 Reserve&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Preview note&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;This capability is currently in public preview and may change before general availability. See preview limitations in documentation:&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/windows-365/public-preview" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows 365 public preview overview&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;Continue the conversation. Find best practices. Bookmark the &lt;/SPAN&gt;&lt;A href="https://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Tech Community&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;, then follow us on &lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/company/windows-it-pro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;or&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://twitter.com/mswindowsitpro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSWindowsITPro&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;for updates. Looking for support? Visit&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows on Microsoft Q&amp;amp;A&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:257}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/public-preview-user-initiated-provisioning-for-windows-365/ba-p/4512474</guid>
      <dc:creator>Logan_Silliman</dc:creator>
      <dc:date>2026-04-28T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Protect your estate: Reassess your Windows update policies</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/protect-your-estate-reassess-your-windows-update-policies/ba-p/4515228</link>
      <description>&lt;P&gt;&lt;EM&gt;Editor's note 4.30.2026:&amp;nbsp; The new Windows Autopatch overview report is now available for all tenants.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;A new Windows Autopatch report reflects updated recommendations on patch compliance and highlights risk exposure based on patch status and configured policies.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Keeping devices up to date has never been more critical for security. As noted in a recent post &lt;A href="https://www.microsoft.com/en-us/security/blog/2026/04/22/ai-powered-defense-for-an-ai-accelerated-threat-landscape/?msockid=033570d464eb6a880f18668e65036bd8" target="_blank"&gt;AI-powered defense for an AI-accelerated threat landscape&lt;/A&gt;, by Ales Holecek, Chief Architect and Corporate Vice President of Microsoft Security, organizations need to rethink exposure, response, and risk. This is especially true when it comes to keeping Windows devices patched with the latest security updates.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;On April 22, 2026, Microsoft Intune released a new &lt;A href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/as-vulnerability-discovery-moves-at-ai-speed-keeping-current-is-foundational-to-/4513766" target="_blank"&gt;security update status dashboard&lt;/A&gt; offering centralized visibility into update compliance across Windows client, Windows Server, and Microsoft 365 apps. The dashboard provides a clear, current view for IT and security teams, backed by current data, and without the need to switch between multiple reports or tools.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Today, we're announcing that Windows Autopatch offers an extension to that dashboard offering more detailed information on client patching status and policy risk exposure. This new Windows Autopatch report:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Breaks down specific patch versions within your estate.&lt;/LI&gt;
&lt;LI&gt;Informs you of policies putting your estate at risk.&lt;/LI&gt;
&lt;LI&gt;Provides actionable workflows to help reduce exposure.&lt;/LI&gt;
&lt;/UL&gt;
&lt;img /&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Updated recommendations for servicing Windows&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Strategies for reducing risk and staying current are changing. Across the industry, organizations often had a 14- or 28-day SLA to patch devices across their estate. In today's threat landscape, this can leave users in an exposed or critical vulnerability state.&lt;/P&gt;
&lt;img /&gt;
&lt;P style="margin-top: 16px;"&gt;Aligned with the recommendations provided in the &lt;A href="https://www.microsoft.com/en-us/security/blog/2026/04/22/ai-powered-defense-for-an-ai-accelerated-threat-landscape/?msockid=033570d464eb6a880f18668e65036bd8" target="_blank"&gt;recent post from Microsoft Security&lt;/A&gt; we are adjusting our recommendations and encourage organizations to install the latest security updates:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Within 3 days to be considered current (and reported as current)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Within 7 days to help ensure devices aren’t subject to vulnerabilities (and reported as critical)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Between 3 and 7 days, devices are considered exposed (and reported as exposed)&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;To view which policies in your tenant are not configured per recommendations, navigate to the Windows Autopatch overview pane and select &lt;STRONG&gt;View policies leading to increased risk exposure, a poor experience&lt;/STRONG&gt;. From here, you can see which policies are configured in a way that falls short of these recommendations.&lt;/P&gt;
&lt;img /&gt;
&lt;P style="margin-top: 16px;"&gt;We recognize that more aggressive timelines can introduce disruption. However, given the pace of today's threat landscape, these updated recommendations are intended to balance stronger security while maintaining user productivity and stability.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;To help ensure devices stay secure, while having an optimal experience, we recommend using Windows Autopatch and configuring the following policies:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/windows/client-management/mdm/policy-csp-update#deferqualityupdatesperiodindays" target="_blank"&gt;Quality update deferral&lt;/A&gt; of &amp;lt; 3 days&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/windows/client-management/mdm/policy-csp-update#configuredeadlineforqualityupdates" target="_blank"&gt;Quality update deadline&lt;/A&gt; of 0 or 1 day&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/windows/client-management/mdm/policy-csp-update#configuredeadlinegraceperiod" target="_blank"&gt;Grace period&lt;/A&gt; of 1 or 2 days&lt;/LI&gt;
&lt;LI&gt;Enable &lt;A href="https://learn.microsoft.com/windows/deployment/windows-autopatch/manage/windows-autopatch-hotpatch-updates" target="_blank"&gt;hotpatch updates&lt;/A&gt; (Note: Hotpatch updates will be &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/securing-devices-faster-with-hotpatch-updates-on-by-default/4500066" target="_blank"&gt;enabled by default&lt;/A&gt; for all eligible devices that haven't been opted out starting in May 2026.)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;We also recommend using &lt;A href="https://learn.microsoft.com/windows/whats-new/extended-security-updates" target="_blank"&gt;Extended Security Updates (ESU)&lt;/A&gt; for &lt;STRONG&gt;all&lt;/STRONG&gt; eligible devices still running Windows 10 so those devices continue to receive critical security updates.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Reassess and stay protected&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Now is the time to reassess your risk profile and patching deployments. We continue to improve Windows Autopatch reports to give you the information you need to help reduce threats to your estate. By using the new report, you can identify where to take action to stay even more protected in this ever-evolving threat landscape.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Additional resources:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/as-vulnerability-discovery-moves-at-ai-speed-keeping-current-is-foundational-to-/4513766" target="_blank"&gt;As vulnerability discovery moves at AI speed, keeping current is foundational to reduce exposure&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/msrc/blog/2026/04/strengthening-secure-software-global-scale-how-msrc-is-evolving-with-ai" target="_blank"&gt;Strengthening secure software at global scale: How MSRC is evolving with AI&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 30 Apr 2026 22:46:23 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/protect-your-estate-reassess-your-windows-update-policies/ba-p/4515228</guid>
      <dc:creator>AriaUpdated</dc:creator>
      <dc:date>2026-04-30T22:46:23Z</dc:date>
    </item>
    <item>
      <title>Hardening administrative actions: What IT pros need to know</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/hardening-administrative-actions-what-it-pros-need-to-know/ba-p/4503956</link>
      <description>&lt;P&gt;Administrative actions are undergoing hardening changes that reduce the risk of privilege escalation and unauthorized access on Windows devices. These changes strengthen the trust boundary between identity, authentication, and User Account Control (UAC) enforcement. It’s now much harder for an attacker (or a misconfigured cloned device) to reuse or manipulate authentication artifacts after an OS restart to silently gain elevated privileges.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;With these hardening changes, Windows now detects and blocks authentication attempts between machines that share duplicate SIDs.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;This is by design and should be seen as a security signal, not a code defect.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Some environments deploy Windows devices using automation or virtual machine templates. Some of these methods rely on previously accepted authentication behavior between cloned systems. If you created these deployments without running Sysprep, that’s your case. Recent authentication hardening updates might now require you to rebuild affected devices using supported imaging methods.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;A temporary workaround (detailed below) is available to provide time for remediation. However, it reduces the security protections introduced by the latest updates and cannot be used as a permanent solution due to its lifecycle end date.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Running Sysprep prepares a Windows image for deployment. Sysprep removes device-specific identity and security information, allowing each deployed machine to generate a unique system identity and authentication context when it starts.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Let’s take a closer look at why these hardening changes are important to the overall security of your environment and how you can update your cloning, imaging, and authentication practices.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Why administrative action hardening is necessary for security&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;The current administrative action hardening phase began with the &lt;A href="https://support.microsoft.com/topic/august-29-2025-kb5064081-os-build-26100-5074-preview-3f9eb9e1-72ca-4b42-af97-39aace788d93" target="_blank" rel="noopener"&gt;August 2025 non-security update (KB5064081)&lt;/A&gt; and the &lt;A href="https://support.microsoft.com/en-us/topic/september-9-2025-kb5065426-os-build-26100-6584-6a59dc6a-1ff2-48f4-b375-81e93deee5dd" target="_blank" rel="noopener"&gt;September 2025 security update (KB5065426)&lt;/A&gt;. These updates strengthen loopback authentication protections. They help ensure that Kerberos authentication is more tightly bound to the current machine state across OS restarts.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Previously, authentication artifacts could persist across restarts in ways that allowed elevated operations to proceed without explicit user approval. Current hardening helps reduce this risk. It improves how machine identity is validated during authentication.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;While these changes improve security posture, they might require adjustments to how you deploy and manage devices in some environments.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Symptoms of administrative action hardening&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;With the installation of Windows updates released on or after August and September 2025, your devices were hardened against unauthorized attempts to bypass loopback detection. This applies to devices running Windows 11, version 24H2 and later as well as Windows Server 2025.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;You might have observed authentication failures between machines when accessing SMB shares or connecting via Remote Desktop. Similar failures might also occur with authentication using New Technology LAN Manager (NTLM) or between machines that aren’t joined to a domain.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;The target machine shows the following LsaSrv Event ID 6167 in the System event log:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-22 lia-border-style-dotted" border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-style-dotted"&gt;
&lt;P style="margin: 10px; line-height: 140%; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 400; font-size: 16px;"&gt;There is a partial mismatch in the machine ID. This indicates that the ticket has either been manipulated or it belongs to a different boot session. Failing authentication.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 100.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P style="margin-top: 16px;"&gt;This is an inconvenient but necessary symptom of administrative action hardening that might require operational change to support your organization’s security posture. Here’s why.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;What changed internally&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;User Account Control (UAC) in Windows primarily acts as a privilege mediation mechanism. It helps ensure that administrative rights are exercised only with explicit user approval. While users may hold administrative credentials, applications they launch initially run with standard user privileges. Privileges must be explicitly elevated through a UAC consent prompt to perform administrative actions.&lt;/P&gt;
&lt;img /&gt;
&lt;P style="margin-top: 16px;"&gt;&lt;BR /&gt;Recent security investments in Windows have tightened how you approve and enforce administrative actions. These UAC hardening changes reduce the risk of elevation without explicit user consent. Hardening happens through Windows updates and applies regardless of whether Administrator protection is enabled. Administrator protection (available in preview) also benefits from these changes. It helps reduce automatic elevation paths and reinforces explicit, user-approved elevation for administrative operations. The result is a stronger trust boundary between identity, authentication, and UAC enforcement.&amp;nbsp;&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Loopback detection and token filtering scenarios are also part of this effort. A machine ID is used to check if a machine is performing loopback authentication, i.e., authenticating to itself. Before the August 2025 non-security update, each boot randomly generated the machine ID. However, authentication artifacts could still persist across a restart in ways that allowed threat actors to bypass token filtering.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Windows updates released on and after August 2025 detect and block such behavior. Windows now persists part of the machine ID across boots.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Before, authentication handshakes between Windows hosts that were cloned from each other succeeded because only per-boot components were checked. Now, authentication handshakes are detected and blocked because the cross-boot component of the machine ID is the same between the two hosts, while the per-boot component is not, resulting in a partial mismatch of machine IDs.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Specifically, if you've cloned machines without running &lt;A href="https://learn.microsoft.com/en-us/windows-hardware/manufacture/desktop/sysprep--generalize--a-windows-installation?view=windows-11" target="_blank" rel="noopener"&gt;Sysprep&lt;/A&gt;, you might see Kerberos and NTLM authentication failures. You can identify them by the LsaSrv event 6167 log in the auth target machine, for both NTLM and Kerberos protocols.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;&lt;STRONG&gt;This behavior is not a regression. It’s a direct and intentional consequence of binding loopback authentication more tightly to machine identity across OS boots.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;In summary, prior to installing Windows Updates released on or after August 2025:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Machine ID regenerated on every boot.&lt;/LI&gt;
&lt;LI&gt;Loopback detection relied entirely on per-boot state.&lt;/LI&gt;
&lt;LI&gt;Persisted authentication artifacts could bypass token filtering.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;After August 2025:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Machine ID combines per-boot and cross-boot components.&lt;/LI&gt;
&lt;LI&gt;Loopback detection survives restarts.&lt;/LI&gt;
&lt;LI&gt;Persisted authentication artifacts are reliably rejected.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Management recommendations for administrative action hardening symptoms&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;While administrative action hardening improves security, it requires an adjustment in your strategy to clone Windows images. As you embrace administrative action hardening for its security benefit, you should take the following actions:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Stop any automation that clones devices without Sysprep. If not addressed, devices end up with duplicate security IDs (SIDs).&lt;/LI&gt;
&lt;LI&gt;Rebuild all devices with duplicate SIDs from scratch, then run Sysprep. It's not sufficient to unjoin devices and run Sysprep. If needed for transition only: temporarily roll back the hardening change.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;Recommended solution&lt;/H3&gt;
&lt;P style="margin-top: 16px;"&gt;When cloning a Windows image, you should always use Sysprep. You can read more about this recommendation in our official documentation in &lt;A href="https://www.betaarchive.com/wiki/index.php/Microsoft_KB_Archive/314828" target="_blank" rel="noopener"&gt;KB314828&lt;/A&gt; and &lt;A href="https://learn.microsoft.com/troubleshoot/windows-server/setup-upgrade-and-drivers/windows-installations-disk-duplication" target="_blank" rel="noopener"&gt;The Microsoft policy for disk duplication of Windows installations&lt;/A&gt;.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;If your scenario falls outside of this recommendation, the only supported and durable resolution is to rebuild affected systems using supported deployment and imaging methods. Once done, you should remove existing clones.&lt;/P&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;Temporary workaround (not recommended)&lt;/H3&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-custom-ddf3ff" border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P style="margin: 10px;"&gt;&lt;STRONG&gt;Important! &lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin: 10px;"&gt;Microsoft&amp;nbsp;&lt;STRONG&gt;does not&lt;/STRONG&gt; recommend using this temporary registry-based compatibility option. It reduces the security protections introduced by recent updates. If your organization uses enhanced administrator security configurations (including Administrator protection, where applicable), avoid relying on this setting except as a short-term bridge while remediation is underway. Environments that remain in this configuration might be exposed to elevated risk until remediation is complete. Please plan and execute migration to supported deployment practices as soon as possible. See&amp;nbsp;&lt;A href="https://support.microsoft.com/topic/strengthening-administrator-protection-and-kerberos-authentication-f67abf78-41c5-4a89-a2da-a7b2fe280270" target="_blank" rel="noopener"&gt;KB5068222: Strengthening administrator protection and Kerberos authentication&lt;/A&gt;&lt;/P&gt;
&lt;A href="https://support.microsoft.com/topic/strengthening-administrator-protection-and-kerberos-authentication-f67abf78-41c5-4a89-a2da-a7b2fe280270" target="_blank" rel="noopener"&gt; &lt;/A&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 100.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P style="margin-top: 16px;"&gt;&lt;BR /&gt;We understand that while cloning without Sysprep may have been unsupported, you still may have taken a dependency on it. To help ease the transition to a supported configuration, a temporary compatibility option is now available. This option relaxes the updated authentication behavior to allow continued operation in affected environments. It’s provided solely to facilitate remediation and should not be considered a long-term configuration.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Please contact &lt;A href="https://support.serviceshub.microsoft.com/supportforbusiness/manage" target="_blank" rel="noopener"&gt;Microsoft Commercial Customer Service and Support (CSS)&lt;/A&gt; to get information about this registry value. Complete the intake form as follows:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 63.0556%; height: 352px; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr style="height: 44.6667px;"&gt;&lt;td style="height: 44.6667px; padding: 0px;"&gt;
&lt;P style="margin-top: 16px;"&gt;&lt;STRONG&gt;Form field&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 44.6667px; padding: 0px;"&gt;
&lt;P style="margin-top: 16px;"&gt;&lt;STRONG&gt;Recommended option&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 44.6667px;"&gt;&lt;td style="height: 44.6667px; padding: 0px;"&gt;
&lt;P style="margin-top: 16px;"&gt;Select the Product family&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 44.6667px; padding: 0px;"&gt;
&lt;P style="margin-top: 16px;"&gt;Windows Servers&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 72.6667px;"&gt;&lt;td style="height: 72.6667px; padding: 0px;"&gt;
&lt;P style="margin-top: 16px;"&gt;What product or service do you need help with?&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 72.6667px; padding: 0px;"&gt;
&lt;P style="margin-top: 16px;"&gt;Windows Server 2025&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 44.6667px;"&gt;&lt;td style="height: 44.6667px; padding: 0px;"&gt;
&lt;P style="margin-top: 16px;"&gt;Select the product version&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 44.6667px; padding: 0px;"&gt;
&lt;P style="margin-top: 16px;"&gt;Windows Server 2025&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 44.6667px;"&gt;&lt;td style="height: 44.6667px; padding: 0px;"&gt;
&lt;P style="margin-top: 16px;"&gt;Which category best describes the issue?&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 44.6667px; padding: 0px;"&gt;
&lt;P style="margin-top: 16px;"&gt;Windows Security Technologies&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 100.667px;"&gt;&lt;td style="height: 100.667px; padding: 0px;"&gt;
&lt;P style="margin-top: 16px;"&gt;Which problem best describes the issue&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 100.667px; padding: 0px;"&gt;
&lt;P style="margin-top: 16px;"&gt;Kerberos authentication&lt;BR /&gt;OR&lt;BR /&gt;Legacy authentication (NTLM)&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P style="margin-top: 16px;"&gt;&lt;BR /&gt;You must have an understanding of the risk of disabling administrative action hardening. You’ll also need to provide:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Reasoning for requiring this temporary workaround&lt;/LI&gt;
&lt;LI&gt;A clear plan for the long-term resolution of reimaging cloned machines in your environment&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-custom-ddf3ff" border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P style="margin: 10px;"&gt;&lt;STRONG&gt;Important! &lt;/STRONG&gt;This workaround is the replacement for the known issue rollback (KIR)-based group policy setting. These settings were released by Windows Updates between August 2025 and March 2026 to disable loopback protections. Your organization can only obtain the new registry key by opening an assisted support case and certifying that you can rebuild cloned devices prior to the end of 2027.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 100.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P style="margin-top: 16px;"&gt;&lt;BR /&gt;This registry key will act as temporary rollback until it expires and allow authentication that would otherwise by blocked by loopback identity protections. Event Viewer helps you monitor this temporary workaround. If you set this temporary registry value and restart the system, the next authentication attempt will be allowed. An LsaSrv warning event 6168 will be logged in the target machine in the System event log:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-22 lia-border-style-dotted" border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-style-dotted"&gt;
&lt;P style="margin: 10px; line-height: 140%; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 400; font-size: 16px;"&gt;UAC bypass via Kerberos vulnerability is explicitly allowed. A Kerberos loopback ticket can be manipulated to gain admin privileges. This is a security risk.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 100.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P style="margin-top: 16px;"&gt;The only way to stop seeing this event is to migrate your environment to a supported state. Once done, please delete the registry key or set it to&amp;nbsp;&lt;STRONG&gt;0&lt;/STRONG&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Timeline to remove the clones in your environment&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;The rollback is temporary and will remain available until the end of 2027. We hope this timeframe provides your organization with sufficient opportunity to migrate your environment to a supported state by following established deployment methods for cloning.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;For additional information, check out the following resources:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://support.microsoft.com/en-us/topic/kerberos-and-ntlm-authentication-failures-due-to-duplicate-sids-76f7394d-c460-4882-9ed1-d27e0960f949" target="_blank" rel="noopener"&gt;KB5070568&lt;/A&gt;: &lt;A href="https://support.microsoft.com/topic/kerberos-and-ntlm-authentication-failures-due-to-duplicate-sids-76f7394d-c460-4882-9ed1-d27e0960f949" target="_blank" rel="noopener"&gt;Kerberos and NTLM authentication failures due to duplicate SIDs&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://support.microsoft.com/en-us/topic/strengthening-administrator-protection-and-kerberos-authentication-f67abf78-41c5-4a89-a2da-a7b2fe280270" target="_blank" rel="noopener"&gt;KB5068222: Strengthening administrator protection and Kerberos authentication&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/troubleshoot/windows-server/setup-upgrade-and-drivers/windows-installations-disk-duplication" target="_blank" rel="noopener"&gt;The Microsoft policy for disk duplication of Windows installations&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/windows-hardware/manufacture/desktop/sysprep--generalize--a-windows-installation?view=windows-11" target="_blank" rel="noopener"&gt;Sysprep&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/windows/security/application-security/application-control/administrator-protection/?tabs=intune" target="_blank" rel="noopener"&gt;Administrator Protection&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Windows 11:&amp;nbsp;&lt;A href="https://support.microsoft.com/en-us/topic/august-29-2025-kb5064081-os-build-26100-5074-preview-3f9eb9e1-72ca-4b42-af97-39aace788d93" target="_blank" rel="noopener"&gt;August 29, 2025—KB5064081 (OS Build 26100.5074) Preview&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Windows Server 2025:&amp;nbsp;&lt;A href="https://support.microsoft.com/topic/september-9-2025-kb5065426-os-build-26100-6584-6a59dc6a-1ff2-48f4-b375-81e93deee5dd" target="_blank" rel="noopener"&gt;September 9, 2025—KB5065426 (OS Build 26100.6584)&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;P style="font-size: 14px;"&gt;&lt;EM&gt;&lt;STRONG&gt;Securing the present, innovating for the future &lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin-top: 16px; font-size: 14px;"&gt;Security is a shared responsibility. Through collaboration across hardware and software ecosystems, we can build more resilient systems secure by design, by default and during runtime, from Windows to the cloud, enabling trust at every layer of the digital experience.&lt;/P&gt;
&lt;P style="margin-top: 16px; font-size: 14px;"&gt;The updated &lt;A href="https://learn.microsoft.com/windows/security/book/" target="_blank" rel="noopener"&gt;Windows 11 Security Book&lt;/A&gt; and &lt;A href="https://techcommunity.microsoft.com/blog/microsoft-security-blog/windows-server-2025-security-book/4283981" target="_blank" rel="noopener"&gt;Windows Server Security Book&lt;/A&gt; are available to help you understand how to stay secure with Windows. Learn more about &lt;A href="https://www.microsoft.com/windows/business" target="_blank" rel="noopener"&gt;Windows 11&lt;/A&gt;, &lt;A href="https://learn.microsoft.com/windows-server/" target="_blank" rel="noopener"&gt;Windows Server&lt;/A&gt;, and&amp;nbsp;&lt;A href="https://www.microsoft.com/en-us/windows/business/devices/copilot-plus-pcs" target="_blank" rel="noopener"&gt;Copilot+ PCs&lt;/A&gt;. To learn more about Microsoft security solutions, visit our &lt;A href="https://www.microsoft.com/security" target="_blank" rel="noopener"&gt;website&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P style="margin-top: 16px; font-size: 14px;"&gt;Bookmark the&amp;nbsp;&lt;A href="https://www.microsoft.com/security/blog/" target="_blank" rel="noopener"&gt;Security Blog &lt;/A&gt;to keep up with our expert coverage on security matters.&lt;/P&gt;
&lt;P style="margin-top: 16px; font-size: 14px;"&gt;Also, follow us on LinkedIn (&lt;A href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;Microsoft Security&lt;/A&gt;) and X (&lt;A href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;@MSFTSecurity&lt;/A&gt;) for the latest news and updates on cybersecurity.&lt;/P&gt;
&lt;HR /&gt;
&lt;P style="font-size: 14px;"&gt;Continue the conversation. Find best practices. Bookmark the &lt;A href="http://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;Windows Tech Community&lt;/A&gt;, then follow us &lt;A href="https://x.com/mswindowsitpro" target="_self"&gt;@MSWindowsITPro&lt;/A&gt; on X and on &lt;A href="https://www.linkedin.com/company/windows-it-pro" target="_blank" rel="noopener"&gt;LinkedIn&lt;/A&gt;. Looking for support? Visit &lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;Windows on Microsoft Q&amp;amp;A&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2026 16:24:23 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/hardening-administrative-actions-what-it-pros-need-to-know/ba-p/4503956</guid>
      <dc:creator>DashmeetAjmani</dc:creator>
      <dc:date>2026-04-09T16:24:23Z</dc:date>
    </item>
    <item>
      <title>Introducing the new Windows 365 monitoring and reporting platform — now in Public Preview</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/introducing-the-new-windows-365-monitoring-and-reporting/ba-p/4505355</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We are excited to announce the new Windows 365 monitoring and reporting platform is now available in Public Preview!&lt;/SPAN&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The new Windows 365 monitoring and reporting platform is a unified reporting experience built into the Microsoft Intune admin center, now available in public preview. It consolidates Cloud PC health, performance, and configuration data into integrated dashboards, consolidating information from many locations in Intune, to a central location to monitor end-to-end configuration, detect problem, and troubleshoot.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Additionally, monitoring and reporting is designed to improve discoverability and usability, making the experience more intuitive, comprehensive, and flexible. The platform provides native, user-friendly reports that simplify how administrators access, understand, and act on monitoring data.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;By consolidating analytics into a unified experience that highlights potential outliers, the platform can help streamline troubleshooting workflows. In some customer environments, this may contribute to faster issue resolution and reduced reliance on specialized expertise or Microsoft support. The extent to which organizations realize operational efficiency improvements, cost benefits, or uptime gains will depend on individual deployment and usage.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;What’s&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;included in the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;new&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;m&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;onitoring and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;r&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;eporting platform&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Tenant-level Connection Health dashboards&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; provide comprehensive reliability and experience&amp;nbsp;data&amp;nbsp;with&amp;nbsp;trending&amp;nbsp;and aggregate views covering connection performance, errors, and device health.&amp;nbsp;Operations teams gain at-a-glance visibility into system-wide patterns,&amp;nbsp;helping&amp;nbsp;administrators&amp;nbsp;see issues earlier&amp;nbsp;and&amp;nbsp;investigating&amp;nbsp;sometimes before&amp;nbsp;receiving&amp;nbsp;helpdesk calls.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;User and Device insights&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;display connection performance, error trends, connection history, and duration of use for helpdesk troubleshooting. With all relevant data in one place, &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;frontline support staff&amp;nbsp;can more easily&amp;nbsp;diagnose and resolve issues, reducing escalations&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Configuration visuals and trends&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;offer prebuilt, end-to-end visuals that encompass the full environment from user endpoint through service configuration to the Cloud PC configuration. Configuration changes constantly, and understanding historical configuration in the context of any specific connection is critical, especially when Windows 365 is implemented with unmanaged components, such as BYOD user endpoints. This function facilitates correlating configuration changes with outcomes.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Outlier detection&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;surfaces system-identified anomalous metrics to assist administrators in identifying potential emerging issues. Depending on how customers use these insights, some organizations may experience earlier issue identification and reduced escalation, though results will vary.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Actionable charts and data tables&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;let administrators analyze trends and drill into root causes without manual data exports&amp;nbsp;and&amp;nbsp;additional&amp;nbsp;tooling. The intuitive design&amp;nbsp;helps&amp;nbsp;lower the barrier to entry, supporting the confidence of&amp;nbsp;administrators with varied skill levels&amp;nbsp;in&amp;nbsp;issue&amp;nbsp;investigation&amp;nbsp;and&amp;nbsp;resolution.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;The bottom line:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;Today, many organizations resort to exporting, processing and analyzing Cloud PC data, which can increase the complexity and total cost of ownership of Windows 365. The new platform helps reduce reliance on data exports and external tooling.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Try the &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;new monitoring and reporting&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;today&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Windows 365 Enterprise customers can access the new dashboards now in the Microsoft Intune admin center. Navigate to Reporting in Intune, then select monitoring and explore the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Connection Health&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;User &amp;amp; Devices&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, and&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Configuration&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; pages. Learn more at https://aka.ms/Windows365Monitoring&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-contrast="none"&gt;Continue the conversation. Find best practices. Bookmark the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Tech Community&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;, then follow us on&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/company/windows-it-pro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;or&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://twitter.com/mswindowsitpro" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSWindowsITPro&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;for updates. Looking for support? Visit&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows on Microsoft Q&amp;amp;A&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2026 16:36:10 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/introducing-the-new-windows-365-monitoring-and-reporting/ba-p/4505355</guid>
      <dc:creator>Doug_Coombs</dc:creator>
      <dc:date>2026-04-08T16:36:10Z</dc:date>
    </item>
    <item>
      <title>How hotpatch updates help keep Windows secure by design</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/how-hotpatch-updates-help-keep-windows-secure-by-design/ba-p/4508188</link>
      <description>&lt;P&gt;Windows hotpatch updates allow you to adopt a secure-by-design and secure-by-default approach to keeping Windows 11 protected and productive. The security architecture advantage behind hotpatch updates helps you support continuous protection, accelerate patch compliance, and reduce operational disruption. And since hotpatch updates will be enabled by default across Windows Autopatch for eligible devices in May 2026, you might wonder how this makes your environment even more secure by default.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;How hotpatch updates reflect Windows security by design&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;In &lt;A href="https://www.microsoft.com/trust-center/security/secure-future-initiative" target="_blank" rel="noopener"&gt;Microsoft overarching security-by-design philosophy,&lt;/A&gt; security comes first when designing any product or service. Embodying this philosophy are &lt;A href="https://learn.microsoft.com/windows/deployment/windows-autopatch/manage/windows-autopatch-hotpatch-updates" target="_blank" rel="noopener"&gt;hotpatch updates.&lt;/A&gt;&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;These are the same security fixes that are part of monthly security updates (also known as “B” releases). The distinction is that they get installed without requiring a restart. Hotpatch updates help you:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Reduce downtime for frontline devices, VDI sessions, IT-managed shared PCs, and high uptime systems.&lt;/LI&gt;
&lt;LI&gt;Shrink your vulnerability window (i.e., the time between patch availability and full deployment).&lt;/LI&gt;
&lt;LI&gt;Improve update compliance rates automatically.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;: Hotpatch updates only apply to devices that meet the &lt;A href="https://learn.microsoft.com/windows/deployment/windows-autopatch/manage/windows-autopatch-hotpatch-updates#prerequisites" target="_blank" rel="noopener"&gt;prerequisites&lt;/A&gt; and receive updates managed by Windows Autopatch. Otherwise, no action is needed. Ineligible devices continue to patch the same way they do today.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;How hotpatch update prerequisites strengthen your security baseline&lt;/H3&gt;
&lt;P style="margin-top: 16px;"&gt;Hotpatch update readiness is built on Windows security capabilities that help ensure that devices are in a trusted state before updates are applied.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;The key prerequisite is &lt;A href="https://learn.microsoft.com/en-us/windows-hardware/design/device-experiences/oem-vbs" target="_blank" rel="noopener"&gt;virtualization-based security (VBS)&lt;/A&gt; - a foundational Windows 11 security feature and the core requirement for hotpatch updates at scale. VBS (also known as core isolation) uses hardware virtualization to run a secure kernel alongside the OS in a hypervisor-isolated environment. This separation means that, even if the main OS is compromised, the secure kernel remains protected. For hotpatch updates, VBS provides the trusted environment needed to safely update running kernel code.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Hotpatch updates also require modern Windows 11 hardware that supports VBS. Protections like silicon-rooted security and firmware integrity further strengthen the trusted foundation, in which VBS operates. This way, hotpatch updates apply to devices with an already robust security baseline. In other words, devices that receive hotpatch updates are already trusted and well-protected - reducing risk and strengthening your security posture.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;&lt;STRONG&gt;Operational governance through existing update frameworks.&lt;/STRONG&gt; Hotpatch updates are delivered using the same Windows Update and Windows Autopatch mechanisms you already manage today. Clean integration of hotpatch updates into existing update rings and policies helps ensure consistent rollout, predictable compliance, and centralized, cloud‑managed enforcement - without introducing a new update model to govern. This means you get the benefits of hotpatch updates with no disruption to your current update processes or compliance reporting.&lt;/P&gt;
&lt;H3 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;How hotpatch updates fit into Windows chip-to-cloud security model&lt;/H3&gt;
&lt;P style="margin-top: 16px;"&gt;Security by design spans from chip to cloud. Hotpatch technology reflects this broader architectural framework in its prerequisites and functionality, designed to keep devices secure end-to-end. Let's take a look at the hardware (chip) layer, the operating system (OS) layer, and the cloud and identity layer of the same &lt;A href="https://learn.microsoft.com/windows/security/book/#chip-to-cloud-security" target="_blank" rel="noopener"&gt;chip-to-cloud trust chain&lt;/A&gt; you already manage.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;&lt;STRONG&gt;Hardware/chip layer.&lt;/STRONG&gt; Hotpatch updates are supported only on modern, secure silicon configurations (including Arm64), helping ensure that updates apply on hardware with:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;TPM 2.0&lt;/LI&gt;
&lt;LI&gt;UEFI Secure Boot&lt;/LI&gt;
&lt;LI&gt;Measured and trusted boot pathways&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;This way, the OS environment being patched is already hardware-rooted and trusted.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;&lt;STRONG&gt;OS layer.&lt;/STRONG&gt; Hotpatch update readiness guidance links directly to VBS, which is core to Windows 11 OS-level protections. These OS-level safeguards help you:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Protect sensitive processes from tampering.&lt;/LI&gt;
&lt;LI&gt;Enforce strong code integrity.&lt;/LI&gt;
&lt;LI&gt;Create a trusted foundation for in-memory patching.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;Hotpatch updates use this secure architecture, updating protected code paths while keeping the OS running.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;&lt;STRONG&gt;Cloud/identity layer.&lt;/STRONG&gt; Hotpatch updates use the same trusted channels as Windows Update. They're managed through:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/windows/deployment/update/waas-manage-updates-wufb" target="_blank" rel="noopener"&gt;Windows Update client policies&lt;/A&gt; (formerly Windows Update for Business)&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/windows/deployment/windows-autopatch/manage/windows-autopatch-windows-update-policies" target="_blank" rel="noopener"&gt;Windows Autopatch quality update rings&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/entra/identity/devices/overview" target="_blank" rel="noopener"&gt;Microsoft Entra ID (formerly Azure AD)-based device identity&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;This helps ensure that your patches come from a secure, authenticated cloud source and adhere to your compliance and deployment policies.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Hotpatch updates use the full chip-to-cloud trust chain, so every update is delivered and applied with end-to-end security.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;How hotpatch updates reflect Windows security by default&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;&lt;A href="https://www.microsoft.com/trust-center/security/secure-future-initiative" target="_blank" rel="noopener"&gt;Microsoft Secure Future Initiative&lt;/A&gt; defines security as protections that are enforced by default and require no extra effort. Windows 11 security posture, rooted in stronger defaults and continuous innovation, reinforces the security-by-design principles.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Hotpatch updates have always been designed with security at the core, and until now have been an opt-in feature. With the May 2026 security update, Windows Autopatch will enable hotpatch updates by default at the tenant level to help organizations get secure quicker. This change in default behavior is designed to reduce patch friction while keeping your existing update governance intact. Importantly, it doesn't override the controls you already use and comes with new controls to opt out until you're ready.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The default tenant setting is only applied to devices that aren't members of a quality update policy.&lt;/LI&gt;
&lt;LI&gt;Windows Autopatch continues to respect the preferences you've set for deferrals and update ring settings.&lt;/LI&gt;
&lt;LI&gt;Starting April 1, 2026, you can also opt out of this new default behavior at the tenant or device group level. Learn more at &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/securing-devices-faster-with-hotpatch-updates-on-by-default/4500066" target="_blank" rel="noopener"&gt;Securing devices faster with hotpatch updates on by default&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;With hotpatch updates enabled by default, you're secured with Windows security updates during each &lt;A href="https://learn.microsoft.com/en-us/windows/deployment/windows-autopatch/manage/windows-autopatch-hotpatch-updates#release-cycles" target="_blank" rel="noopener"&gt;hotpatch release month&lt;/A&gt;, with no additional steps. In addition, critical security out-of-band (OOB) updates can also be delivered as hotpatch updates. This automatically secures you against the threats addressed by the OOB update, and your organization is protected faster, with less effort and fewer manual steps.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Alignment with security best practices&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Enrolling in hotpatch updates automatically aligns your devices with Microsoft security best practices. &lt;A href="https://learn.microsoft.com/windows/deployment/windows-autopatch/prepare/windows-autopatch-start-using-autopatch" target="_blank" rel="noopener"&gt;Enroll devices in Windows Autopatch&lt;/A&gt; before May, if you haven't yet, and you'll start getting these updates enabled by default! These latest innovations in monthly servicing help keep your environment on a higher-trust, chip-to-cloud–aligned security baseline.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Embrace security by default with hotpatch updates that reduce user downtime and restart-driven tickets, improve update compliance, and shorten vulnerability exposure.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/event/windowsevents/the-latest-in-windows-11-security/4490530" target="_blank" rel="noopener"&gt;The latest in Windows 11 security &lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/hotpatch-for-client-frequently-asked-questions/4413582" target="_blank" rel="noopener"&gt;Hotpatch for client: Frequently asked questions&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/hotpatch-readiness-enable-vbs-at-scale/4441652" target="_blank" rel="noopener"&gt;Hotpatch readiness: Enable VBS at scale&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/hotpatch-efficiency-unlocked-smaller-update-size/4460681" target="_blank" rel="noopener"&gt;Hotpatch efficiency unlocked: Smaller update size&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/best-practices-for-securing-microsoft-intune/4502117" target="_blank" rel="noopener"&gt;Best practices for securing Microsoft Intune &lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/windows/security/book/" target="_blank" rel="noopener"&gt;Windows 11 security book&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;P style="font-size: 14px;"&gt;&lt;EM&gt;&lt;STRONG&gt;Securing the present, innovating for the future &lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin-top: 16px; font-size: 14px;"&gt;Security is a shared responsibility. Through collaboration across hardware and software ecosystems, we can build more resilient systems secure by design, by default and during runtime, from Windows to the cloud, enabling trust at every layer of the digital experience.&lt;/P&gt;
&lt;P style="margin-top: 16px; font-size: 14px;"&gt;Learn how to stay secure with Windows. Check out the updated &lt;A href="https://learn.microsoft.com/windows/security/book/" target="_blank" rel="noopener"&gt;Windows 11 Security Book&lt;/A&gt; and &lt;A href="https://techcommunity.microsoft.com/blog/microsoft-security-blog/windows-server-2025-security-book/4283981" target="_blank" rel="noopener"&gt;Windows Server Security Book&lt;/A&gt;, more about &lt;A href="https://www.microsoft.com/windows/business" target="_blank" rel="noopener"&gt;Windows 11&lt;/A&gt;, &lt;A href="https://learn.microsoft.com/windows-server/" target="_blank" rel="noopener"&gt;Windows Server&lt;/A&gt;, &lt;A href="https://learn.microsoft.com/windows/deployment/windows-autopatch/manage/windows-autopatch-hotpatch-updates" target="_blank" rel="noopener"&gt;Windows hotpatch updates&lt;/A&gt; and &lt;A href="https://www.microsoft.com/en-us/windows/business/devices/copilot-plus-pcs" target="_blank" rel="noopener"&gt;Copilot+ PCs&lt;/A&gt;. To learn more about Microsoft Security Solutions, visit our &lt;A href="https://www.microsoft.com/security" target="_blank" rel="noopener"&gt;website&lt;/A&gt;.&lt;/P&gt;
&lt;P style="margin-top: 16px; font-size: 14px;"&gt;Bookmark the &lt;A href="https://www.microsoft.com/security/blog/" target="_blank" rel="noopener"&gt;Microsoft Security Blog &lt;/A&gt;to keep up with our expert coverage on security matters. You can also follow &lt;A href="https://www.linkedin.com/showcase/microsoft-security/" target="_blank" rel="noopener"&gt;Microsoft Security on LinkedIn&lt;/A&gt; and &lt;A href="https://twitter.com/@MSFTSecurity" target="_blank" rel="noopener"&gt;@MSFTSecurity &lt;/A&gt;on X for the latest news and updates on cybersecurity.&lt;/P&gt;
&lt;HR /&gt;
&lt;P style="font-size: 14px;"&gt;Continue the conversation. Find best practices. Bookmark the &lt;A href="http://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;Windows Tech Community&lt;/A&gt;, then follow us &lt;A href="https://x.com/mswindowsitpro" target="_self"&gt;@MSWindowsITPro&lt;/A&gt; on X and on &lt;A href="https://www.linkedin.com/company/windows-it-pro" target="_blank" rel="noopener"&gt;LinkedIn&lt;/A&gt;. Looking for support? Visit &lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;Windows on Microsoft Q&amp;amp;A&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Apr 2026 20:53:13 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/how-hotpatch-updates-help-keep-windows-secure-by-design/ba-p/4508188</guid>
      <dc:creator>Katharine_Holdsworth</dc:creator>
      <dc:date>2026-04-06T20:53:13Z</dc:date>
    </item>
    <item>
      <title>Windows news you can use: March 2026</title>
      <link>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-news-you-can-use-march-2026/ba-p/4495553</link>
      <description>&lt;P&gt;This month, our Windows team shared a candid update on how we're thinking about Windows quality, what's changing behind the scenes, and how your real-world feedback is shaping the platform. It's all in a post entitled&lt;A href="https://blogs.windows.com/windows-insider/2026/03/20/our-commitment-to-windows-quality/" target="_blank"&gt; Our commitment to Windows quality&lt;/A&gt;. Windows + Devices EVP Pavan Davuluri walks through how we identify issues, prioritize fixes, and how the Windows Insider community helps make Windows more reliable before updates reach production environments. It's a helpful read if you're interested in learning more about how we build, measure, and strengthen Windows quality.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Now on to more highlights from March in this month's edition of Windows news you can use.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;New in Windows update and device management&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;[AUTOPATCH] – &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/windows-autopatch-update-readiness-brings-insights-to-it/4497611" target="_blank"&gt;Windows Autopatch update readiness is now generally available&lt;/A&gt;. It includes new capabilities to help you proactively detect and remediate device update issues. Reduce downtime, improve update success, and lower the security risk that comes from devices that aren't up to date.&lt;/LI&gt;
&lt;LI&gt;[HOTPATCH] – Windows Autopatch is enabling &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/securing-devices-faster-with-hotpatch-updates-on-by-default/4500066" target="_blank"&gt;hotpatch updates by default&lt;/A&gt; starting with the May 2026 security update. This change in default behavior will come to all eligible devices in Microsoft Intune and those accessing the service via Microsoft Graph API. New controls are available for those organizations that aren't ready to have hotpatch updates enabled by default.&lt;/LI&gt;
&lt;LI&gt;[RSAT] – Remote Server Administration Tools (RSAT) are now officially &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/rsat-capabilities-arrive-on-arm-based-windows-11-pcs/4500663" target="_blank"&gt;supported on Arm-based Windows 11 PCs&lt;/A&gt;. You can now remotely manage Windows server roles and features using Windows devices built on Arm processors, just as you would with traditional x64-based PCs.&lt;/LI&gt;
&lt;LI&gt;[SECURE BOOT] – The March 2026 security update introduces two new PowerShell features to help you manage the ongoing Secure Boot certificate rollout. The Get-SecureBootUEFI cmdlet now supports the -Decoded option, which displays Secure Boot certificates in a readable format. The Get-SecureBootSVN cmdlet lets you check the Secure Boot Security Version Number (SVN) of your device's UEFI firmware and bootloader. Use it to report whether the device follows the latest Secure Boot policy.&lt;/LI&gt;
&lt;LI&gt;[PRINT] – Instead of requiring device-specific drivers, Windows is now released with &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/building-a-modern-secure-and-seamless-print-experience-for-windows/4499051" target="_blank"&gt;a single, universal, inbox-class driver&lt;/A&gt; based on the industry standard IPP protocol and Mopria certification. If you're using a traditional x64 PC, including the latest Copilot+ PC running on Arm-based silicon, the print experience is the same: plug in (or connect over the network) and print.&lt;/LI&gt;
&lt;LI&gt;[W365] – &lt;A href="https://learn.microsoft.com/windows-365/enterprise/introduction-windows-365-frontline#windows-365-frontline-in-shared-mode" target="_blank"&gt;Windows 365 Frontline in shared mode&lt;/A&gt; is now available in Brazil South, Italy North, West Europe, New Zealand North, Mexico Central, Europe, Norway East, France Central, Spain Central, Germany West Central, and Switzerland North. Windows 365 is now available for Government Community Cloud (GCC &amp;amp; GCC-High) organizations in the &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/windows-365-available-in-us-gov-texas-for-government-community-cloud-customers/4500042" target="_blank"&gt;US Gov Texas region&lt;/A&gt;. In addition, &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/announcing-multi%E2%80%91region-selection-for-windows-365-in-government-community-cloud/4500043" target="_blank"&gt;multi-region selection&lt;/A&gt; is now available for Windows 365 GCC &amp;amp; GCC-High.&lt;/LI&gt;
&lt;LI&gt;[RDP] – Microsoft recently released a sample repository demonstrating &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/announcing-the-rdp-dynamic-virtual-channel-plugin-samples/4501337" target="_blank"&gt;how to build Remote Desktop Protocol (RDP) plugins&lt;/A&gt; using modern tools and development patterns.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;New in Windows security&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;[DRIVERS] – Starting with the April 2026 security update, Microsoft is removing trust for all kernel drivers signed by the deprecated cross-signed root program. This update will help ensure that by default, you can only load kernel drivers the Windows Hardware Compatibility Program (WHCP) passes and signs. This &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/advancing-windows-driver-security-removing-trust-for-the-cross-signed-driver-pro/4504818" target="_blank"&gt;new kernel trust policy&lt;/A&gt; applies to devices running Windows 11 and Windows Server 2025.&lt;/LI&gt;
&lt;LI&gt;[SECURE BOOT] – Catch up on the latest FAQs by watching the March edition of &lt;A href="https://techcommunity.microsoft.com/event/windowsevents/ask-microsoft-anything-secure-boot---april-2026/4501308" target="_blank"&gt;Secure Boot: Ask Microsoft Anything (AMA)&lt;/A&gt; on demand. The next AMA will be April 23, 2026. &lt;A href="https://techcommunity.microsoft.com/event/windowsevents/ask-microsoft-anything-secure-boot---april-2026/4501308" target="_blank"&gt;Save the date&lt;/A&gt; and post your questions in advance or during the live event. New guidance and resources are now available, including:
&lt;UL&gt;
&lt;LI&gt;Video deep dive: &lt;A href="https://techcommunity.microsoft.com/event/windowsevents/secure-boot-certificate-updates-explained/4490529" target="_blank"&gt;Secure Boot certificate updates explained&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Guide: &lt;A href="https://support.microsoft.com/topic/secure-boot-troubleshooting-guide-5d1bf6b4-7972-455a-a421-0184f1e1ed7d" target="_blank"&gt;Secure Boot troubleshooting&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Reference: &lt;A href="https://support.microsoft.com/topic/a-closer-look-at-the-high-confidence-database-32382469-4505-4ed4-915b-982eff09b5d2" target="_blank"&gt;A closer look at the high confidence database&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Documentation and sample PowerShell scripts: &lt;A href="https://support.microsoft.com/topic/sample-secure-boot-e2e-automation-guide-f850b329-9a6e-40d1-823a-0925c965b8a0" target="_blank"&gt;Sample Secure Boot E2E automation&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Guide: &lt;A href="https://support.microsoft.com/topic/it-admin-guide-secure-boot-certificate-update-status-in-the-windows-security-app-fb8e2121-4402-433b-af8b-623760951fdb" target="_blank"&gt;Secure Boot certificate update status in the Windows Security app&lt;/A&gt;[SYSMON] – System Monitor (Sysmon) functionality is now &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/native-sysmon-functionality-coming-to-windows/4468112" target="_blank"&gt;natively available in Windows&lt;/A&gt;. Capture system events for threat detection and use custom configuration files to filter the events you want to monitor. Windows writes captured events to Windows Event Log, which allows security tools and other applications to use them.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;[WDS] As announced in January 2026, the Unattend.xml file used in hands‑free deployment with Windows Deployment Services (WDS) poses a vulnerability when transmitted over an unauthenticated RPC channel. Beginning with the April 2026 security update, the second phase of hardening changes for &lt;A href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-0386" target="_blank"&gt;CVE-2026-0386&lt;/A&gt; begins. These changes will make hands‑free deployment disabled by default to enforce secure behavior. For detailed guidance, see &lt;A href="https://go.microsoft.com/fwlink/?linkid=2344403" target="_blank"&gt;Windows Deployment Services (WDS) Hands‑Free Deployment Hardening&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;New in AI&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;[W365] [AGENTS] – Curious about the difference between Windows 365 for Agents and Microsoft Agent 365? &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/unlocking-secure-agentic-productivity-with-windows-365-for-agents/4499149" target="_blank"&gt;Explore the distinct role of each product&lt;/A&gt; and learn how to use them together to run agentic workloads securely, at scale, and under enterprise governance.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;To learn about latest capabilities for Copilot+ PCs, visit the &lt;A href="https://www.microsoft.com/windows/business/roadmap" target="_blank"&gt;Windows Roadmap&lt;/A&gt; and filter Platform by "Copilot+ PC Exclusives."&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;New in Windows Server&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;For the latest features and improvements for Windows Server, see the &lt;A href="https://support.microsoft.com/topic/windows-server-2025-update-history-10f58da7-e57b-4a9d-9c16-9f1dcd72d7d7" target="_blank"&gt;Windows Server 2025 release notes&lt;/A&gt; and &lt;A href="https://support.microsoft.com/topic/windows-server-version-23h2-update-history-68c851ff-825a-4dbc-857b-51c5aa0ab248" target="_blank"&gt;Windows Server, version 23H2 release notes&lt;/A&gt;.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;[EVENT] – Save the date for the &lt;A href="https://techcommunity.microsoft.com/blog/windowsservernewsandbestpractices/save-the-date-windows-server-summit-%E2%80%93-may-11-13-2026/4501057" target="_blank"&gt;Windows Server Summit, May 11-13&lt;/A&gt;. RSVP for three days of practical, engineering-led guidance on real-world operations, security, and hybrid scenarios supported by live Q&amp;amp;A.&lt;/LI&gt;
&lt;LI&gt;[NVMe] – A &lt;A href="https://techcommunity.microsoft.com/blog/windowsservernewsandbestpractices/introducing-the-windows-nvme-of-initiator-preview-in-windows-server-insiders-bui/4501344" target="_blank"&gt;basic NVMe-over-Fabrics (NVMe-oF) initiator&lt;/A&gt; is available in the latest Windows Server Insiders build. This release introduces an in-box Windows initiator for NVMe/TCP and NVMe/RDMA, enabling early evaluation of networked NVMe storage using native Windows Server components.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;New in productivity and collaboration&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Install the March 2026 security update for &lt;A href="https://support.microsoft.com/topic/march-10-2026-kb5079473-os-builds-26200-8037-and-26100-8037-9c222a8e-cc02-40d4-a1f8-ad86be1bc8b6" target="_blank"&gt;Windows 11, versions 25H2 and 24H2&lt;/A&gt; to get these and other capabilities, which will be rolling out gradually:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;[RECOVERY] – &lt;A href="https://support.microsoft.com/windows/quick-machine-recovery-in-windows-aa2852f4-e04e-4af4-9508-0addda165304" target="_blank"&gt;Quick Machine Recovery&lt;/A&gt; now turns on automatically for Windows Professional devices that are not domain‑joined and not enrolled in enterprise endpoint management. These devices receive the same recovery features available to Windows Home users. For domain‑joined or enterprise managed devices, Quick Machine Recovery stays off unless you enable it for your organization.&lt;/LI&gt;
&lt;LI&gt;[NETWORK] – A built‑in network speed test is now available from the taskbar. The speed test opens in the default browser and measures Ethernet, Wi‑Fi, and cellular connections.&lt;/LI&gt;
&lt;LI&gt;[CAMERA] – Control pan and tilt for supported cameras in the Settings app.&lt;/LI&gt;
&lt;LI&gt;[SEARCH] – Using search on the taskbar? Preview search results by hovering and quickly seeing when more results are available with group headers.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;New features and improvements are coming in the April 2026 security update. You can preview them by installing the March 2026 optional non-security update for &lt;A href="https://support.microsoft.com/topic/march-26-2026-kb5079391-os-builds-26200-8116-and-26100-8116-preview-7c9e2275-b9ba-4068-aeb0-23da42b81d3b" target="_blank"&gt;Windows 11, versions 25H2 and 24H2&lt;/A&gt;. This update includes the gradual rollout of:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;[SECURITY] –You can turn Smart App Control on or off without needing a clean install.&lt;/LI&gt;
&lt;LI&gt;[SETTINGS] – The Settings &amp;gt; About page now provides a more structured and intuitive experience. Get clearer device specifications and easier navigation to related device components, including quick access to Storage settings.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Lifecycle reminders&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;Windows 10 Enterprise 2016 LTSB and Windows 10 IoT Enterprise 2016 LTSB will reach end of support on October 13, 2026. Windows Server 2016 will reach end of support on January 12, 2027. If your organization cannot migrate to newer, supported releases in time, &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/plan-for-windows-server-2016-and-windows-10-2016-ltsb-end-of-support/4496136" target="_blank"&gt;explore the options available&lt;/A&gt; to help you keep your devices protected with monthly security updates. Extended Security Updates (ESU) are now available for purchase for Windows 10 Enterprise 2016 LTSB.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;Check out our lifecycle documentation for the latest updates on &lt;A href="https://learn.microsoft.com/windows/whats-new/deprecated-features" target="_blank"&gt;Deprecated features in the Windows client&lt;/A&gt; and &lt;A href="https://learn.microsoft.com/windows-server/get-started/removed-deprecated-features-windows-server-2025" target="_blank"&gt;Features removed or no longer developed starting with Windows Server 2025&lt;/A&gt;.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Additional resources&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Looking for the latest news and previews for Windows, Copilot, Copilot+ PCs, the Windows and Windows Server Insider Programs, and more? Check out these resources:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/windows/business/roadmap" target="_blank"&gt;Windows Roadmap&lt;/A&gt; for new Copilot+ PCs and Windows features – filter by platform, version, status, and channel or search by feature name&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/copilot/microsoft-365/release-notes?tabs=all" target="_blank"&gt;Microsoft 365 Copilot release notes&lt;/A&gt; for latest features and improvements&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://blogs.windows.com/windows-insider/" target="_blank"&gt;Windows Insider Blog&lt;/A&gt; for what's available in the Canary, Dev, Beta, or Release Preview Channels&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/windows-server/discussions/windowsserverinsiders" target="_blank"&gt;Windows Server Insider&lt;/A&gt; for feature preview opportunities&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://support.microsoft.com/topic/understanding-update-history-for-windows-insider-preview-features-fixes-and-changes-bb9dd4b1-9d2b-4753-8b23-ce90e62f6845" target="_blank"&gt;Understanding update history for Windows Insider preview features, fixes, and changes&lt;/A&gt; to learn about the types of updates for Windows Insiders&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Join the conversation&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;If you're an IT admin with questions about managing and updating Windows, add our monthly &lt;A href="https://aka.ms/Windows/OfficeHours" target="_blank"&gt;Windows Office Hours&lt;/A&gt; to your calendar. We assemble a crew of Windows, Windows 365, security, and Intune experts to help answer your questions and provide tips on tools, best practices, and troubleshooting.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Finally, we're always looking to improve this monthly summary. Drop us a note in the Comments and let us know what we can do to make this more useful for you!&lt;/P&gt;
&lt;HR /&gt;
&lt;P style="font-size: 14px;"&gt;Continue the conversation. Find best practices. Bookmark the &lt;A href="http://aka.ms/community/Windows" target="_blank" rel="noopener"&gt;Windows Tech Community&lt;/A&gt;, then follow us &lt;A href="https://x.com/mswindowsitpro" target="_self"&gt;@MSWindowsITPro&lt;/A&gt; on X and on &lt;A href="https://www.linkedin.com/company/windows-it-pro" target="_blank" rel="noopener"&gt;LinkedIn&lt;/A&gt;. Looking for support? Visit &lt;A href="https://docs.microsoft.com/answers/products/windows#windows-client-for-it-pros" target="_blank" rel="noopener"&gt;Windows on Microsoft Q&amp;amp;A&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2026 21:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-news-you-can-use-march-2026/ba-p/4495553</guid>
      <dc:creator>Chris_Morrissey</dc:creator>
      <dc:date>2026-04-03T21:00:00Z</dc:date>
    </item>
  </channel>
</rss>

