KB5064489 (OS Build 26100.4656) Out-of-Band Update for Windows 11 24H2 - July 13, 2025
Out-of-band cumulative update for Windows 11 24H2, build 26100.4656, released July 13, 2025. Fixes Azure VM startup failures when VBS is enabled on non-Trusted Launch GE VMs.

Summary
This is an out-of-band (OOB) cumulative update for Windows 11, version 24H2, bringing the OS to build 26100.4656. Released on July 13, 2025, it includes all security fixes from the July 8, 2025 security update (KB5062553) and adds a targeted fix for Azure virtual machines that failed to start with Virtualization-Based Security enabled. Source: Microsoft Support
Improvements and fixes
- Fixes an issue that prevented certain Azure virtual machines from starting when Virtualization-Based Security (VBS) was enabled. The problem affected VMs running version 8.0 (a non-default version) where VBS was offered by the host. In Azure, this specifically impacts standard (non-Trusted Launch) General Enterprise (GE) VMs on older VM SKUs. The root cause was identified as a secure kernel initialization issue.
Known issues
Microsoft lists no known issues for this update at the time of writing.
How to get this update
This update is delivered as a combined package that includes both the latest servicing stack update (SSU) and the latest cumulative update (LCU). The bundled servicing stack update is KB5063666, version 26100.4651. Deployment channels and prerequisites are as follows.
Windows Update / Windows Update for Business The update is available automatically. No additional steps are required for devices configured to receive updates through these channels.
Microsoft Update Catalog Download the standalone package directly from the Microsoft Update Catalog. This KB contains multiple MSU files that must be installed in a specific order.
- Method 1 - Install all MSU files together: Download all MSU files for KB5064489 and place them in a single folder (for example,
C:\Packages). Use DISM with the/PackagePathswitch pointing to that folder; DISM will discover and install prerequisite MSU files automatically. DISM and PowerShell (Add-WindowsPackage) commands are provided for both running Windows PCs and offline installation media. - Method 2 - Install each MSU file individually in the following order: first
windows11.0-kb5043080-x64.msu, thenwindows11.0-kb5064489-x64.msu.
WSUS (Server Update Services) The update is available through WSUS.
Removal note: To remove only the LCU after installing the combined SSU+LCU package, use DISM /online /Remove-Package with the LCU package name as the argument. Running wusa.exe /uninstall against the combined package will not work because the SSU is included and cannot be removed after installation.
AI component note: This cumulative update includes updates for AI components, but those components will only install on Windows Copilot+ PCs. They will not install on standard Windows PCs or Windows Server.
Secure Boot certificate notice: Secure Boot certificates used by most Windows devices are set to expire starting in June 2026. Microsoft has been pushing updated certificates to consumer and non-managed business devices. Devices that have not yet received the newer certificates will continue to start and operate normally, and standard Windows updates will continue to install. IT administrators should consult the Secure Boot Playbook for Windows clients and Windows Server for guidance.
Frequently asked questions
Which devices does this update target?
This update applies to Windows 11, version 24H2, all editions, resulting in OS build 26100.4656. The fix it carries is specifically relevant to Azure environments running standard (non-Trusted Launch) General Enterprise VMs on older VM SKUs where Virtualization-Based Security was enabled and VMs could not start.
Does this update replace the July 8, 2025 security update?
Yes, this OOB update is cumulative and includes all security fixes and improvements from the July 8, 2025 security update (KB5062553), plus the additional VM startup fix. Devices that already have KB5062553 installed still need this update to receive the VBS-related fix.
Is a servicing stack update required before installing this update?
No separate SSU installation is required. Microsoft has combined the latest SSU (KB5063666, version 26100.4651) with this cumulative update into a single package. DISM handles prerequisite installation automatically when all MSU files are placed in the same folder.
Can this update be uninstalled if it causes problems?
The LCU portion can be removed using DISM /online /Remove-Package with the appropriate package name, which you can identify by running DISM /online /get-packages. Using wusa.exe /uninstall on the combined package will not work. The SSU portion cannot be removed from the system after installation.









