enrollment

Winsage
August 13, 2026
A recent update has been released, addressing security vulnerabilities and improving system functionality. Key improvements include a fix for the Backup feature, resolving an "invalid credentials" error that caused automatic backups to fail when using Server Message Block (SMB). The update also enhances the Secure Boot feature by introducing high-confidence device targeting data, allowing more devices to receive new Secure Boot certificates. This update addresses outdated Secure Boot certificates for Windows 11 and Windows 10 users. The update, identified as KB5120249, is under 1 GB and is available only to PCs enrolled in the Extended Security Updates (ESU) program, which ensures Windows 10 PCs receive security updates until at least October 2027. Non-enrolled PCs lost security update support in October 2025.
Winsage
August 12, 2026
Microsoft's August Patch Tuesday update addressed 421 vulnerabilities across various products, including multiple versions of Windows (11 25H2/24H2, 11 23H2, and 10). A critical zero-day flaw, the "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability," allows attackers with lower-level access to gain system privileges without user interaction. Additionally, the update addresses two other zero-day flaws, including the "Windows User Profile Service Elevation of Privilege Vulnerability," which has not yet been exploited but was publicly disclosed. The update is mandatory and should automatically install on supported PCs, with users encouraged to verify its application. The update also includes minor improvements to Windows features, such as enhancements to File Explorer, Windows Hello, Voice Access, and touchpad controls.
Winsage
August 10, 2026
Microsoft is offering Extended Security Updates (ESUs) for Windows Server 2016, which will provide critical security patches until January 2030, after the end of extended support on January 12, 2027. Organizations can enroll their Windows Server 2016 instances via Azure Arc to receive these updates without migrating to Azure. The ESUs are available through a pay-as-you-go pricing model, allowing flexibility for on-premises servers and other cloud platforms. By using Azure Arc, organizations gain access to Azure management tools for improved visibility and compliance. IT administrators should connect eligible systems to Azure Arc to manage ESU enrollment and compliance effectively. ESUs are intended as a temporary solution while businesses modernize applications and plan migrations to supported platforms.
Winsage
July 29, 2026
Microsoft reassured Windows 11 and Windows 10 users that their PCs will continue to boot normally and receive updates even if they have not yet received the new Secure Boot 2023 certificates. The rollout of these certificates is expected to continue over the upcoming months. The initial Secure Boot certificate expired on June 24, 2026, and Microsoft has been replacing older 2011 certificates since 2024. The latest update, KB5101650, transitioned Windows 11 to OS builds 26200.8875 and 26100.8875 for versions 25H2 and 24H2, respectively. The 2023 certificates replace older certificates with modern cryptographic standards, allowing Microsoft to deliver DBX revocation updates without interruption. Devices using the 2011 KEK can only receive DBX updates signed with that key, which is no longer valid after June 24. Microsoft has been rolling out the 2023 certificates for the past two years, and many devices remained in a yellow or red status by the June deadline. To check Secure Boot status, users can navigate to Windows Security > Device Security. A green checkmark indicates successful application of the certificates, while yellow and red alerts indicate compatibility issues or firmware incompatibility. PCs that are older or operating in Legacy BIOS mode will not receive the updates. Windows 10 also receives Secure Boot updates, but enrollment in Extended Security Updates (ESU) is required.
Winsage
July 20, 2026
Users may experience double reboots when installing substantial Windows updates, such as the April and July 2026 Updates, due to factors like Secure Boot and .NET Framework updates. The July 2026 .NET Framework update specifically requires a separate reboot. Microsoft is still rolling out the Secure Boot 2023 certificate update, which may also lead to multiple reboots. Users are advised not to panic during these reboots and to allow the system time to complete the installation process. Additionally, Microsoft has warned against delaying updates for more than three days due to increasing update sizes related to security vulnerabilities. Some users may encounter SCEP certificate errors in the Event Viewer after the July 2026 Update, but these errors do not indicate a failure of the update process.
Search