NAVANEM
Out-of-bandOS build 20348.4776

KB5082314 (OS Build 20348.4776) Out-of-Band Update for Windows Server 2022

Out-of-band cumulative update for Windows Server 2022, released March 2, 2026, fixing a Windows Hello for Business certificate renewal issue in ADFS deployments.

KB5082314: KB5082314 (OS Build 20348.4776) Out-of-Band Update for Windows Server 2022 — navanem Microsoft KB cover
KB5082314 · Windows Server · Out-of-Band Update

Summary

This is a cumulative out-of-band (OOB) update for Windows Server 2022, released March 2, 2026, producing OS Build 20348.4776. It includes all fixes from the February 10, 2026 security update (KB5075906) plus an additional targeted fix for a Windows Hello for Business certificate renewal failure in specific Active Directory Federation Services (ADFS) deployments. See Microsoft Support for the official page.

Improvements and fixes

  • This update carries all quality and security improvements from the February 10, 2026 security update (KB5075906) as a baseline, so no previously delivered fixes are lost.
  • The primary new fix targets a certificate renewal failure for Windows Hello for Business in certain on-premises ADFS-based deployments running on Windows Server 2022. ADFS in these environments is responsible for validating and renewing user authentication certificates, and a specific configuration caused that renewal process to fail.
  • Microsoft notes this issue affects only a small number of organizations using this exact deployment model; it does not affect individual PCs or consumer devices.
  • The fix is protected by Known Issue Rollback (KIR) and is disabled by default. Installing this update alone does not activate the fix. The required KIR enablement Group Policy is provided only by Microsoft Support and is intended for confirmed affected customers. Admins should apply this update only to ADFS servers that combine ADFS with Windows Hello for Business.
  • The update bundles the latest servicing stack update (SSU) for Windows Server 2022 - KB5075905, version 20348.4763 - alongside the cumulative update package.

Known issues

WSUS does not display synchronization error details

Symptom: After installing KB5070884 or any later update, Windows Server Update Services (WSUS) does not display synchronization error details within its error reporting interface.

Workaround: Microsoft states this functionality was temporarily removed to address the Remote Code Execution vulnerability CVE-2025-59287. No additional workaround is documented on this page beyond contacting Microsoft Support if the ADFS certificate renewal issue is observed.

How to get this update

KB5082314 is available exclusively through the Microsoft Update Catalog; it does not distribute through Windows Update automatic channels. Windows Update for Business, WSUS, and standard Windows Update channels all point administrators to the Catalog as the only retrieval path. To download the standalone package, visit the Microsoft Update Catalog and search for KB5082314.

If you need to remove the cumulative update after installation, use the DISM /online /remove-package command with the LCU package name as the argument. You can identify the package name by running DISM /online /get-packages. Running wusa.exe with the /uninstall switch against the combined package will not work because the package contains the SSU, and the SSU cannot be removed from the system once installed.

Prerequisite note: The servicing stack update (KB5075905, version 20348.4763) is included in this combined package, so no separate SSU installation step is required before applying KB5082314.

Frequently asked questions

Does this update install automatically on all Windows Server 2022 systems?

No. Microsoft specifies that KB5082314 is available only from the Microsoft Update Catalog and is not pushed through standard automatic update channels. Admins must download and deploy it manually, and Microsoft recommends applying it only to ADFS servers confirmed to be affected by the Windows Hello for Business certificate renewal issue.

What is Known Issue Rollback and why does it matter here?

Known Issue Rollback (KIR) is a Microsoft mechanism that lets a specific fix ship in a disabled state so that only confirmed affected customers can enable it via Group Policy. For this update, installing KB5082314 does not automatically activate the ADFS certificate renewal fix. Admins must obtain the KIR enablement Group Policy from Microsoft Support and apply it to targeted servers.

How should admins handle the Secure Boot certificate expiration announcement?

Microsoft notes that Secure Boot certificates on many Windows devices are set to expire starting in June 2026. Devices that have not yet received newer certificates will continue to start and operate normally, and standard Windows updates will keep installing. IT administrators should review the Secure Boot Playbook for Windows clients and Windows Server for guidance on managed environments.

How can affected organizations get help enabling the fix?

Organizations that observe the Windows Hello for Business certificate renewal failure on Windows Server 2022 ADFS servers should contact Microsoft Support for Business. Microsoft Support will provide the KIR enablement Group Policy needed to activate the fix included in this update.

#windows-server-2022#out-of-band#adfs#windows-hello-for-business#certificate-renewal#known-issue-rollback#cumulative-update

Related topics