What’s new for IT pros in Windows 10, version 1909
Published Nov 12 2019 10:00 AM 309K Views
Microsoft

Windows 10, version 1909 is now available through Windows Server Update Services (WSUS) and Windows Update for Business, and can be downloaded from Visual Studio Subscriptions, the Software Download Center (via the Media Creation Tool[1]), and the Volume Licensing Service Center (VLSC)[2].

We recommend IT administrators begin targeted deployments of Windows 10, version 1909 to validate that the apps, devices, and infrastructure used by their organizations work as expected with the new features. As recently announced in blogs by John Cable and John Wilcox, Windows 10, version 1909 can be delivered in a new, streamlined fashion to devices currently running Windows 10, version 1903. For details on this new delivery approach, read John Wilcox’s blog post on Windows 10, version 1909 delivery options. The update process will be the same as previous feature updates for devices running Windows 10, version 1809 and older—or if you choose to deploy Windows 10, version 1909 from media.

Today marks the start of the servicing timeline for this Semi-Annual Channel release. By updating to Windows 10, version 1909, devices running the Enterprise and EDU editions will receive 30 months of support. (Devices running the Home, Pro, Pro for Workstations, Pro Education, and IoT Core will receive the standard 18 months of support.) For more details, see the Windows lifecycle fact sheet.

New features in Windows 10, version 1909

As you begin to roll out this new update to your organization, here are some of the new, key features and enhancements that will allow you to benefit from intelligent security, simplified updates, flexible management, and enhanced productivity.

  • Calendar – You can now create new events in your Calendar app by clicking the date and time on the Taskbar.
  • Cloud Clipboard[3] – Let’s face it, you work on multiple devices. With this feature enabled, you can copy text, links, graphics – just about anything! – from one device and paste it onto another. Or you can go back and view the history of what’s recently been copied. You can use Cloud Clipboard with either an Azure Active Directory (Azure AD) account or Microsoft Account (MSA).
  • CPU rotation – A CPU may have multiple “favored” cores. To provide better performance and reliability, we’ve implemented a rotation policy that distributes the work more fairly among the favored cores.
  • Digital assistants – Third-party digital assistants can activate above the Lock screen using your voice commands.
  • Reduced inking latency – We’ve reduced inking latency by basing latency on the hardware capabilities of the devices rather than the latency selected on typical hardware configuration by the OS.
  • Intel processor debugging – We’ve added additional debugging capabilities for newer Intel processors, for our OEM partners and hardware manufacturers.
  • Kiosk mode – Users can customize their experience in Kiosk mode, while keeping their devices locked down. For example, you can allow a user to switch to a different language while blocking access to network settings.
  • Microsoft BitLocker key rolling – BitLocker and Mobile Device Management (MDM) with Azure AD[4] work together to protect your devices from accidental password disclosure. Now, a new key-rolling feature securely rotates recovery passwords on MDM-managed devices. The feature is activated whenever a BitLocker-protected drive is unlocked using Microsoft Intune/MDM tools or a recovery password. As a result, the recovery password will be better protected when users manually unlock a BitLocker drive.
  • Narrator – Narrator and other assistive technologies can now detect the location of the dedicated FN key, and determine if it is locked or unlocked.
  • Notifications – We’ve made several improvements to manage and configure notifications:
    • There is now a “Manage Notifications” button at the top of Action Center.
    • You can configure and turn off notifications directly from the notification, both from the banner and from Action Center.
    • The default sorting for notification senders will be by most recently shown notification, rather than sender name.
  • Windows 10 Pro and Enterprise in S mode – You can deploy and run traditional Win32 (desktop) apps without leaving the security of S mode by configuring the Windows 10 in S mode policy to support Win32 apps, then deploy them with Mobile Device Management (MDM) software such as Microsoft Intune[5].
  • Windows Defender Credential Guard – Windows Defender Credential Guard is now available for ARM64 devices, for additional protection against credential theft for enterprises deploying ARM64 devices in their organizations, such as Surface Pro X.
  • Windows Sandbox – Windows Sandbox is an isolated desktop environment where you can install software without the fear of lasting impact to your device. This feature is available in Windows 10, version 1903. In Windows 10, version 1909 you have even more control over the level of isolation.
  • Windows Search – The Search box in Explorer is now powered by Windows Search, allowing results to include online OneDrive content. Additionally, the results appear instantly as you type.

11.21.2019 Editor's note: We have updated this section to remove an error. Windows Sandbox does not support mixed-container scenarios at this time.

What else have we been up to?

To complement your Windows 10, version 1909 experience, we’ve been busy with other new, exciting products and features that you may have heard about!

  • Windows Virtual Desktop[6] – Windows Virtual Desktop is now generally available. Windows Virtual Desktop is a comprehensive desktop and app virtualization service running in the cloud. It’s the only virtual desktop infrastructure (VDI) that delivers simplified management, multi-session Windows 10, optimizations for Office 365 ProPlus, and support for Remote Desktop Services (RDS) environments. Deploy and scale your Windows desktops and apps on Azure in minutes and get built-in security and compliance features.
  • Desktop Analytics[7] – Desktop Analytics is now generally available. Desktop Analytics is a cloud-connected service, integrated with Configuration Manager, that gives you data-driven insights to the management of your Windows endpoints. It provides insight and intelligence that you can use to make more informed decisions about the update readiness of your Windows endpoints.
  • Microsoft Connected Cache – Together with Delivery Optimization, Microsoft Connected Cache installed on your Configuration Manager distribution point, Windows Server, or Linux Server can seamlessly offload your traffic to local sources, caching content efficiently at the byte range level. Connected Cache is a “configure once and forget it” solution that transparently caches content that your devices on your network need.
  • Microsoft Endpoint Manager – As announced at Microsoft Ignite, Microsoft Endpoint Manager is a single, integrated endpoint management platform for managing all of your endpoints. We’re bringing Configuration Manager and Microsoft Intune together and removing the migration barriers to allow you to leverage your existing Configuration Manager investments, while taking advantage of the power of the Microsoft cloud.

Frequently asked questions

On Tuesday, November 19, 2019 from 9:00-10:00 AM Pacific Time, we will be hosting a live Windows 10 Ask Microsoft Anything (AMA) event on the Tech Community. This event is your opportunity to talk to the engineers and product managers—and ask them any questions you may have about update management, deployment, device management, identity management, policy settings, you name it.

To participate, visit https://aka.ms/ama/w10v1909 at 9:00 AM on November 19th, sign in to Tech Community, and post your questions! We’ll have members of the Windows Autopilot, Microsoft Endpoint Manager, Microsoft Defender ATP, Microsoft Edge, Windows Servicing & Delivery, and other teams standing by to provide answers.

w10v1909-AMA.png

In the meantime, here are some answers to frequently asked questions that come up when we release a Windows 10 feature update.

Is there also a Windows Server release with this release?

Yes. The next Windows Server semi-annual channel (SAC) release is also available today. The Windows Server semi-annual channel is designed for customers who wish to take advantage of new operating system capabilities at a faster pace. Windows Server, version 1909 is focused on reliability, performance and other general improvements. It will be available from Azure Marketplace or the VLSC.

Will there be a new Long-Term Servicing Channel (LTSC) release?
No. Windows 10 Enterprise LTSC 2019 is the current LTSC option, and was released with Windows 10, version 1809 in November of 2018. The next LTSC release can be expected toward the end of 2021. Customers currently using the LTSC for special-purpose devices should start working to upgrade those devices to Windows 10 Enterprise LTSC 2019 as mainstream support for that release will continue until January 9, 2024.

Can I upgrade our devices from Windows 7 directly to Windows 10, version 1909?

Yes. You can directly upgrade from Windows 7 to Windows 10, version 1909. We strongly encourage you to begin your upgrade process immediately to avoid missing the January 14, 2020 end-of-support date for Windows 7.

How can I preview versions of Windows 10 before they become available? I want to start testing these new features early so I can deploy them when they are released!

The Windows Insider Program for Business team enables IT administrators to view and provide feedback on upcoming security, management, and productivity features ahead of release. Plus you can manage the installation of Windows 10 Insider Preview Builds across multiple devices in your organization using WSUS and Configuration Manager. For more information, see Publishing pre-release Windows 10 feature updates to WSUS.

Kits, tools, and resources

Windows 10, versions 1903 and 1909 share a common core operating system with an identical set of system files (again, see Windows 10, version 1909 delivery options for details), you can continue to use the Windows Assessment and Deployment Kit (Windows ADK) for Windows 10 that was released with Windows 10, version 1903 for Windows 10, version 1909. This applies to developer kits, like the Windows HLK, HCK, and WinDbg.

We will, however, be updating the following resources for this release:

  • Windows 10 Enterprise Evaluation (free 90-day evaluation) – available now
  • Security baseline for Windows 10, version 1909 and Windows Server, version 1909 – available in the coming week

The Windows release health dashboard has also been updated so that you can easily see and track any known issues for Windows 10, version 1909 until they are mitigated and resolved.

To see a summary of the latest documentation updates, see What’s new in Windows 10, version 1909 IT pro content on Docs.

 


[1] Update Assistant support for Windows 10, version 1909 will be available the week of November 18, 2019.

[2] It may take 24 hours for downloads to be fully available in the VLSC across all products, markets, and languages.

[3] Cloud Clipboard requires users to be signed into all devices using either MSA or AAD. Users must be signed into the same account across all devices.

[4] Sold separately

[5] Sold separately

[6] Windows Virtual Desktop requires a Microsoft E3 or E5 license, or a Microsoft 365 E3 or E5 license, as well as an Azure tenant. Each sold separately.

[7] Desktop Analytics requires a Windows E3 or E5 license, or a Microsoft 365 E3 or E5 license; sold separately.

35 Comments
Copper Contributor

Question: I keep seeing this in various MS documents about the 1909 update and WSUS...

 

"The Windows 10, version 1909 enablement package will be available on WSUS as KB4517245, which can be deployed on existing deployments of Windows 10, version 1903."

 

That's great, if you are on 1903. What about enterprises that are on 1709(enterprise)/1803/1809. They don't have to go to 1903 first do they? They we are talking 2 back to back updates which is a major pain to manage.

 

Please tell me there will be a 1909 released on WSUS that can be DIRECTLY applied to 1803/1809. Pretty please.

Microsoft

Don-

Please see John Wilcox's earlier post from July 1st. Yes of course you can upgrade to Windows 10, version 1909 from any version of Windows. Upgrading via enablement package requires starting from version 1903. If you are coming from any other version of Windows (including Windows 7/8/8.1/10) then the upgrade is done via normal upgrade channels.

reference: https://techcommunity.microsoft.com/t5/Windows-IT-Pro-Blog/Moving-to-the-next-Windows-10-feature-upd...

Copper Contributor

@Joe Lurie any updates to the security baselines for 1909

 

Edit: oops, it’s in the blog post, reading is hard, thanks!

Copper Contributor

@Steven Turner  It says in the post. Security baseline for Windows 10, version 1909 and Windows Server, version 1909 – available in the coming week" 

Copper Contributor
"CPU rotation – A CPU may have multiple “favored” cores. To provide better performance and reliability, we’ve implemented a rotation policy that distributes the work more fairly among the favored cores." Is this specific to the new 10th gen Intel processors or also applicable to the AMD Ryzen processors?
Iron Contributor

1909 also adds experimental support for TLS 1.3, although this is not mentioned here.

 

Is there something I need to do to enable this, besides adding the "DisabledByDefault" and "Enabled" keys to "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.3"

 

I now see the option in IE for "Use TLS 1.3 (experimental)", but this doesn't work.  Everything opens in TLS 1.2. If I disable 1.2, sites don't connect with 1.3.

 

Do I need to update "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Cryptography\Configuration\SSL\00010002" with new Functions?

Microsoft

@Tom_Fox Please join the AMA on Tuesday. We left TLS 1.3 out of the article because its still experimental (as you mention). So please join the AMA ror more information.

Iron Contributor

@Joe Lurie

 

I'm not able to join to due time zone differences.  Is it possible to post instructions to enable it?  I found a list of 5 1.3 ciphers and added these to my Functions list, but it still doesn't work.  I assume I'm missing something here. 

Microsoft

Sorry you won't be able to join the AMA. We can't publish steps for TLS 1.3 here, as we purposefully left this out of the blog. When TLS 1.3 is ready for public release - even in preview (now its experimental, not preview) the team responsible for TLS 1.3 will post a blog. Until then, I can't post those steps.

Iron Contributor

@Joe Lurie

 

Is there a release date for the 1909 ADMX file?  We are currently testing 1909 in our company, and need to control some of the new features.

Copper Contributor

Also, will there be new language packs, or are the LP's from 1903 working for 1909?

Silver Contributor

What about identification in WSUS? I have pushed Enablement Package to one 1903 and it still reports as 18362, not 18363 in WSUS.

Microsoft

@Tom_Fox here's the ADMX files, released on Friday (sorry I was working in a different timezone Friday and am just back to work now) https://www.microsoft.com/en-us/download/100591

Iron Contributor

@Joe Lurie

 

Thanks for the link, is there also a document/blog outlining the new policies?  Normally there is a "Group Policy Settings Reference Spreadsheet" but I can't find one for 1909.

 

 

Copper Contributor
@Joe Lurie - joined the AMA promptly on time, asked the question about TLS 1.3 schannel support - not a single reply.
Copper Contributor

I have installed nov 2019 windows updates. now my windows search is not working.

 

OS- Win 10 pro

@Subraatp Hi,

try to change the settings in here see if they fix it

Annotation 2019-11-26 180746.png

 

Copper Contributor

@HotCakeX , ok will check.

Copper Contributor

@Tom_Foxyou can find the spreadsheet under within Windows 10 Version 1909 and Windows Server Version 1909 Security Baseline.zip on https://www.microsoft.com/en-us/download/details.aspx?id=55319

PB Salling

Copper Contributor

regarding Cloud Clipboard, what if users are copying passwords? are they strored then in history as well?

@bears10 only in the clipboard history

Copper Contributor

@HotCakeXyeah thats what i meant - moreove i presume stored in plaintext?! in my opinion this must not be possible.

@bears10 Yeah but it shouldn't be a problem because a) you can delete your password after copying it from the clipboard so there won't be any history of it and b) when you copy your password as a plaintext format instead of the masked starred format, you must be needing it that way so clipboard can't automatically mask it or detect it's a password .so either you should let browsers automatically enter your passwords into the websites which most browsers do these days, or you type in your password yourself manually.

 

gfdg.png

 there you can just click delete on the password entry.

the thing is, clipboard syncing is Not enabled by default in Windows 10, you need a Microsoft account and 2 factor authentication enabled for it to work.

also when you sign into your other devices, Windows 10 devices, they are secured by your password/PIN or other Windows Hello biometric authentications, no one can easily access your clipboard history :)

Copper Contributor

At the moment, quite disappointed to be honest.

 

Lost an hour and a half of my working day when pressed the upgrade button - this on an i7 with 8 logical processors and a SSD - so obviously a big upgrade. 

However; thus far the only change I have noticed is where I used to click Start and type one or two characters, to get my application shown on the short list to run; I now only see Microsoft applications, until I get to 5 or 6 characters, at which point I get to see the application I actually want to run. 

Sorry Microsoft, but as an Engineer, 90% of the application you supply Windows 10 with are of little or no use to me, I need to use third part applications to do my job. That is now that little bit less efficient with 1909.

@ColinBurnell 

 

"Lost an hour and a half of my working day when pressed the upgrade button "

 

what does this mean exactly? how one loses work by pressing upgrade button? you forgot to save your open programs?

Copper Contributor

No, it took an Hour and a half for the upgrade to install...

Copper Contributor

@Subraatp 

 

Hi, I also experienced Windows Search no longer working.  In the task bar, selecting the Search icon, opened the Search screen but this remained black for some seconds, after which it disappeared again.  No luck to enter anything.

 

I was able to fix it by using method 1 from following article (no reboot was needed):

 

https://valleychristian.zendesk.com/hc/en-us/articles/216440763-Can-t-type-in-Windows-10-Start-or-Se...

 

Silver Contributor

Have noticed odd behavior updating our base images used for VMware Horizon. Updating from 1809 to 1909 using Windows Update (no WSUS, directly to WU). It shows 1909 as available. I press Download and install. It shows that 1909 is being installed. But in the end it is 1903 after the update and i have to go through update again to actually update it to 1909. And even if it is 1903 it is not providing Enablement package update and installs full update instead. Not sure if this is because of something on our images or what.

Microsoft

@wroot Thanks for the message. I haven't noticed that. I'm adding my friend and colleague, the great @Aria Carley to see if she can answer.

Microsoft

@oleg Hey Oleg, submit a support case / file a bug on feedback hub. That shouldn't be happening. 

Silver Contributor

Ok.. The only way for me to submit via Feedback Hub is using my personal Insider machine. Feedback Hub is not present on these images.

Microsoft

@wroot what about contacting customer support or your account rep?

Silver Contributor

We have reps, although they usually consult about licenses :) But i am able to open cases. These two machines are already updated. I have a bunch waiting to be updated (all 1809). Do you think i should open a case before updating one? Probably not much to look at after the update. I'm not sure if this issue will happen again, but so far it is 2 for 2.

Version history
Last update:
‎Nov 21 2019 01:45 PM
Updated by: