March 10, 2026 Hotpatch KB5079420 (OS Builds 26200.7979 and 26100.7979)
Hotpatch KB5079420 delivers miscellaneous security improvements to Windows 11 Enterprise LTSC 2024 (builds 26200.7979 and 26100.7979), released March 10, 2026.

Summary
This is a Hotpatch security update for Windows 11, version 25H2 and 24H2, applying to OS Builds 26200.7979 and 26100.7979. Released on March 10, 2026, it targets Windows 11 Enterprise LTSC 2024 and delivers miscellaneous security improvements to internal OS functionality without requiring a device restart. See the Microsoft Support page for full details.
Improvements and fixes
- This update applies miscellaneous security improvements to internal OS functionality for both x64 and Arm64 devices.
- Note: Secure Boot certificate updates are not included in this Hotpatch; they will be delivered with the next baseline Windows update in April 2026.
Known issues
Signing in with a Microsoft account might fail for Microsoft Teams Free and other apps
Symptom: After installing this update, sign-in to apps using a Microsoft account may fail. Even when a working internet connection is present, an error may appear during sign-in indicating no internet connection, blocking access to services such as Microsoft Teams Free and OneDrive. Other affected applications include, but are not limited to, Microsoft Edge, Excel, Word, and Microsoft 365 Copilot. This issue only affects Microsoft account sign-ins; businesses using Microsoft Entra ID for app authentication are not affected.
Workaround: This issue is addressed in KB5085518.
Reset this PC might fail with the March 2026 Hotpatch security update or later
Symptom: Devices that have installed KB5079420 or later may experience failures when performing a Push Button Reset (Reset this PC) using either the "Keep my files" or "Remove everything" options. After the first phase of the offline reset, a black boot screen appears, the reset does not complete, and the device restarts to the desktop with the error: "There was a problem resetting your PC. No changes were made." This issue is limited to Windows Autopatch-managed commercial devices where Hotpatch is enabled to apply security updates and monthly security updates are installed without restarting. It does not affect retail consumer devices, devices not using Hotpatch, or devices not managed with Windows Autopatch.
Workaround: This issue is addressed in KB5083769.
How to get this update
Microsoft bundles the latest servicing stack update (SSU) for the operating system together with this Hotpatch update. If you are using Windows Update, the latest SSU installs automatically alongside this update. The associated SSU is KB5083532, version 26100.8035.
This update is available through the following channels:
- Windows Update / Microsoft Update - downloads and installs automatically.
- Microsoft Update Catalog - available for manual download.
- Windows Server Update Services (WSUS) - available via WSUS for managed environments.
For Arm64 devices, Hotpatch is now generally available for Windows 11, version 25H2 and 24H2. Prerequisites include Windows 11 Enterprise version 25H2 or 24H2 (Build 26100.4929 or later) with the current baseline update installed, Microsoft Intune with a Hotpatch-enabled quality update policy, an eligible license (Windows 11 Enterprise E3/E5, Microsoft 365 F3, Windows 11 Education A3/A5, Microsoft 365 Business Premium, or Windows 365 Enterprise), Virtualization-based Security (VBS) enabled, and Compiled Hybrid PE (CHPE) disabled.
Frequently asked questions
Does this update require a device restart?
No. As a Hotpatch update, KB5079420 is designed to apply security improvements to a live running OS without requiring a restart. This is the core benefit of the Hotpatch servicing model for eligible Windows Autopatch-managed devices running Windows 11 Enterprise LTSC 2024.
Are Arm64 devices supported by this Hotpatch update?
Yes. Hotpatch is now generally available for Windows 11, version 25H2 and 24H2 on Arm64 devices. To qualify, admins must disable Compiled Hybrid PE (CHPE), enroll devices in a Hotpatch-enabled quality update policy via Microsoft Intune, and ensure all listed license and VBS prerequisites are met.
What should admins know about the Secure Boot certificate expiration?
Secure Boot certificates used by most Windows devices are set to expire starting June 2026. Microsoft has been deploying updated certificates to consumer and non-managed business devices. Devices that have not yet received updated certificates will continue to start and operate normally. Admins should consult the Secure Boot Playbook for Windows clients and Windows Server for managed environment guidance.
Which known issues should admins prioritize before deploying this update?
Two issues warrant attention. Microsoft account sign-in failures can affect apps including Teams Free, OneDrive, Edge, Excel, Word, and Microsoft 365 Copilot - addressed by KB5085518. Additionally, Windows Autopatch-managed devices with Hotpatch enabled may fail the "Reset this PC" operation - addressed by KB5083769. Admins should evaluate deploying those fixes alongside or after KB5079420.









