NAVANEM
Security updateOS build 26200.8037 and 26100.8037

KB5079473: Windows 11 versions 25H2 and 24H2 Security Update (March 10, 2026)

March 2026 cumulative security update for Windows 11 versions 25H2 and 24H2, bringing OS builds to 26200.8037 and 26100.8037.

KB5079473: Windows 11 versions 25H2 and 24H2 Security Update (March 10, 2026) — navanem Microsoft KB cover
KB5079473 · Windows 11 · Security Update

Summary

KB5079473 is the March 2026 cumulative security update for Windows 11 versions 25H2 and 24H2, released on March 10, 2026. It brings OS builds to 26200.8037 and 26100.8037, bundles the latest security fixes, and incorporates non-security improvements carried over from February's optional preview release. Source: Microsoft Support.

Highlights

  • Secure Boot certificate coverage is expanded by including additional high-confidence device targeting data in Windows quality updates, rolling out new certificates in a controlled, phased manner.
  • File Explorer search reliability is improved when searching across multiple drives or "This PC".
  • Windows Defender Application Control (WDAC) COM object allowlisting behavior is corrected.
  • Windows System Image Manager gains a warning dialog to help confirm that selected catalog files come from a trusted source.

Improvements and fixes

  • [Secure Boot] This update packages additional high-confidence device targeting data into Windows quality updates. More devices become eligible to receive updated Secure Boot certificates automatically, but only after sufficient successful update signals are confirmed, keeping the rollout phased and controlled.
  • [File Explorer] Search reliability is improved when a user searches across multiple drives or uses the "This PC" scope, reducing cases where results were incomplete or unreliable.
  • [Windows Defender Application Control] A bug is fixed where COM objects were incorrectly blocked when the endpoint security policy was set at a higher level than the allowlisting policy. COM objects that should be permitted by an allowlisting policy are now allowed as expected.
  • [Windows System Image Manager] Reliability is improved when selecting trusted catalog files. A new warning dialog prompts administrators to confirm that the file being selected comes from a trusted source before proceeding.
  • AI components for Copilot+ PCs are updated to version 1.2602.1451.0 across Image Search, Content Extraction, Semantic Analysis, and Settings Model. These components install only on Copilot+ PCs and do not apply to standard Windows PCs or Windows Server.
  • All security fixes and quality improvements from KB5077181 (released February 10, 2026) are included in this package.

Known issues

Signing in with a Microsoft account might fail for Microsoft Teams Free and other apps

Symptom: After installing this update, sign-in attempts using a Microsoft account may fail even when the device has a working internet connection. An error message indicating no internet connection can appear, blocking access to services and apps including Microsoft Teams Free and OneDrive. Other affected applications include, but are not limited to, Microsoft Edge, Excel, Word, and Microsoft 365 Copilot - any feature within these apps that requires a Microsoft account sign-in can trigger a similar error. Only Microsoft account sign-ins are affected; organizations using Microsoft Entra ID for app authentication are not impacted.

Workaround: This issue is addressed in KB5085516.

How to get this update

Microsoft bundles the latest servicing stack update (SSU) for the operating system together with this cumulative update (LCU). The accompanying SSU is KB5083532 (version 26100.8035), which improves the reliability of the component responsible for installing Windows updates.

This update is available through the following channels:

  • Windows Update / Microsoft Update - Downloads and installs automatically.
  • Windows Update for Business - Deploys automatically in line with configured policies.
  • Microsoft Update Catalog - Download the arm64 or x64 MSU package manually. Packages can be installed together using DISM with a shared folder path, or individually in order (KB5043080 first, then KB5079473).
  • Windows Server Update Services (WSUS) - Syncs automatically when Product is set to Windows 11 and Classification is set to Security Updates.

To remove the LCU after installation, use DISM /online /get-packages to locate the package name and then DISM /Remove-Package. Running wusa.exe /uninstall on the combined SSU+LCU package will not work because the SSU cannot be removed after installation.

Frequently asked questions

Does this update apply to both Windows 11 24H2 and 25H2?

Yes. KB5079473 applies to Windows 11 version 24H2 (all editions) and Windows 11 version 25H2 (all editions). Both versions land on the same resulting build number - 26200.8037 for 25H2 and 26100.8037 for 24H2 - through a single cumulative update package.

Will Secure Boot certificates be updated automatically on managed devices?

The update includes additional high-confidence device targeting data to expand eligibility for automatic Secure Boot certificate renewal. Devices receive the new certificates only after sufficient successful update signals are confirmed. IT administrators should consult the Secure Boot Playbook for Windows clients and Windows Server for guidance. Devices that have not yet received newer certificates continue to start and operate normally.

Are the AI component updates in this package relevant to all Windows 11 devices?

No. The AI component updates bundled in KB5079473 - covering Image Search, Content Extraction, Semantic Analysis, and Settings Model - apply only to Windows Copilot+ PCs. They will not install on standard Windows PCs or Windows Server machines, even though the components are included in the package.

What should admins do about the Microsoft account sign-in failure?

Admins should be aware that this update introduces a known issue where Microsoft account sign-ins can fail in apps such as Microsoft Teams Free, OneDrive, Microsoft Edge, Excel, Word, and Microsoft 365 Copilot. Microsoft Entra ID-based authentication is not affected. The fix is available in KB5085516, and admins should plan to deploy that update promptly.

#windows-11#security-update#secure-boot#file-explorer#wdac#cumulative-update#march-2026

Related topics