KB5077744: Windows 11 Out-of-Band Update (OS Builds 26200.7627 and 26100.7627) - January 17, 2026
Out-of-band cumulative update for Windows 11 versions 25H2 and 24H2, released January 17, 2026, fixing Remote Desktop sign-in failures introduced by the January 2026 security update.

Summary
This is a cumulative out-of-band (OOB) update for Windows 11 versions 25H2 and 24H2, released January 17, 2026, targeting OS builds 26200.7627 and 26100.7627. It includes all fixes from the January 13, 2026 security update (KB5074109) plus an additional fix for Remote Desktop sign-in failures. See the Microsoft Support page for full details.
Highlights
- Fixes Remote Desktop sign-in failures introduced by the January 2026 Windows security update (KB5074109), which affected authentication for Remote Desktop applications including Windows App.
Improvements and fixes
- Remote Desktop fix: After installing the January 2026 security update (KB5074109), some users experienced sign-in failures when connecting via Remote Desktop. This affected authentication for various Remote Desktop applications on Windows, including the Windows App. This OOB update resolves that failure.
- Cumulative content: The update includes all security fixes and quality improvements from the January 13, 2026 security update (KB5074109), so devices that missed that update will receive those fixes as well.
- AI component updates: The following AI components are updated to version 1.2511.1224.0 - Image Search, Content Extraction, Semantic Analysis, and Settings Model. These components apply only to Windows Copilot+ PCs and will not install on standard Windows PCs or Windows Server.
- Servicing stack update included: Windows 11 servicing stack update KB5071142 (version 26100.7295) is bundled with this release, improving the reliability of the component responsible for installing Windows updates.
Known issues
Password icon missing on lock screen
Symptom: After installing the August 2025 non-security preview update (KB5064081) or later updates, the password icon may not be visible in the sign-in options on the lock screen. Hovering over the blank space where the icon should appear confirms the button is still present and functional. Selecting the invisible placeholder opens the password text box for normal sign-in. This issue primarily affects enterprise or managed IT environments; users on Windows Home or Pro editions on personal devices are very unlikely to encounter it.
Workaround: This issue is addressed in KB5074105.
Apps might become unresponsive when saving files to cloud-based storage
Symptom: After installing this update, some applications may become unresponsive or encounter unexpected errors when opening or saving files to cloud-based storage such as OneDrive or Dropbox. In certain Outlook configurations where PST files are stored on OneDrive, Outlook may hang and fail to reopen unless the process is terminated or the system is restarted. Users may also see missing sent items or previously downloaded emails being re-downloaded.
Workaround: This issue is addressed in KB5078127.
How to get this update
This update is not delivered through Windows Update or Windows Update for Business automatically - it is available via the Microsoft Update Catalog only. Microsoft now combines the latest servicing stack update (SSU) with the latest cumulative update (LCU) in a single package, so no separate SSU installation is required beforehand.
To install from the Catalog, download all MSU files for KB5077744 and use one of two methods:
- Method 1 - Install all MSU files together: Place all downloaded MSU files in a single folder and run DISM with the
/Add-Packageswitch pointing to the target.msufile. DISM will automatically discover and install any prerequisite packages from the same folder. The equivalent PowerShell cmdletAdd-WindowsPackagecan be used as an alternative. Windows Update Standalone Installer is also supported. - Method 2 - Install MSU files individually, in order: Install
windows11.0-kb5043080-x64_(...).msufirst, followed bywindows11.0-kb5077744-x64_(...).msu.
To apply the update to Windows installation media rather than a running system, use the DISM /Image:mountdir parameter or the Add-WindowsPackage cmdlet with -PreventPending. When downloading Dynamic Update packages, ensure they match the same month as this KB; if SafeOS or Setup Dynamic Update packages for this month are unavailable, use the most recently published versions.
To remove the LCU after installation, use DISM /online /remove-package with the LCU package name obtained from DISM /online /get-packages. Running wusa.exe /uninstall against the combined package will not work because the SSU cannot be removed after installation.
Frequently asked questions
Why was this update released out-of-band rather than on Patch Tuesday?
Microsoft issues out-of-band updates when a fix is urgent enough to ship outside the regular monthly schedule. In this case, the January 13, 2026 security update (KB5074109) introduced Remote Desktop sign-in failures affecting multiple applications. Rather than wait until the next Patch Tuesday, Microsoft released KB5077744 on January 17, 2026 to address the issue promptly.
Does this update replace the January 2026 security update, or do both need to be installed?
KB5077744 is cumulative and includes all fixes from the January 13, 2026 security update (KB5074109). Devices that already installed KB5074109 will download only the new content, while devices that did not will receive the full cumulative payload. Administrators do not need to install KB5074109 separately before applying this OOB update.
Will the AI component updates in this package install on all devices?
No. Although the AI component updates (Image Search, Content Extraction, Semantic Analysis, and Settings Model, all at version 1.2511.1224.0) are bundled in the package, they will only install on Windows Copilot+ PCs. Standard Windows PCs and Windows Server machines will not receive those components even if the update is applied successfully.
How should enterprise admins deploy this update if Windows Update for Business is their standard channel?
KB5077744 is not available through Windows Update or Windows Update for Business - deployment must go through the Microsoft Update Catalog. Admins should download the MSU files, then deploy via DISM, PowerShell, or a software distribution tool that supports standalone packages. Follow Method 1 or Method 2 as described in the installation instructions, ensuring MSU files are installed in the correct order if using Method 2.









