NAVANEM
Preview / optionalOS build 28000.2179

KB5089570 (OS Build 28000.2179) Preview - Windows 11 Version 26H1, May 26 2026

Optional preview cumulative update for Windows 11 version 26H1, releasing OS build 28000.2179 on May 26, 2026, with AI features, security changes, and reliability fixes.

KB5089570: KB5089570 (OS Build 28000.2179) Preview - Windows 11 Version 26H1, May 26 2026 — navanem Microsoft KB cover
KB5089570 · Windows 11 · Preview Update

Summary

This is an optional, non-security preview cumulative update for Windows 11, version 26H1, released May 26, 2026, producing OS build 28000.2179. It delivers production-quality improvements across AI-powered PC experiences, security, storage, input, and general reliability. A bundled servicing stack update (KB5095676, build 28000.2172) is also included. Source: Microsoft Support.

Highlights

  • Shared Audio - Two people can now listen to the same audio from a single Windows 11 PC simultaneously, using Bluetooth LE Audio broadcast technology. The feature is accessible from Quick Settings on the taskbar.
  • Xbox mode - A full-screen, controller-friendly game interface, inspired by the Xbox console experience, is now available on Windows 11 PCs including laptops, desktops, and tablets. It is accessible from the Xbox app, Game Bar settings, or by pressing Windows logo key + F11.
  • Haptic feedback on compatible input devices - Users can now feel haptic signals when aligning objects in PowerPoint or snapping and resizing windows. Supported devices include Surface Slim Pen 2, ASUS Pen 3.0, MSI Pen 2, and select mice such as the Logitech MX Master 4 (subject to hardware partner updates).
  • Windows Driver Policy update - Default trust for cross-signed drivers is removed. Drivers from the Windows Hardware Compatibility Program and an allow list of trusted legacy drivers remain permitted. Windows audits driver compatibility for at least 100 hours and three reboots before enforcement.
  • Enhanced batch file security - Administrators can enable a registry-controlled mode that prevents batch files from being modified during execution, giving Application Control for Business policy authors additional control.
  • Policy-Based Removal of Preinstalled Microsoft Apps - Administrators can now remove additional MSIX/APPX-packaged apps by specifying package family names via Group Policy under the "Remove Default Microsoft Store packages" policy for Windows Enterprise and Education editions.

Improvements and fixes

  • File Explorer - The list of supported archive formats now includes uu, cpio, xar, and NuGet packages (.nupkg). View and Sort preferences are now retained in folders such as Downloads and Documents when apps launch File Explorer directly to those locations. A white flash that could appear when opening This PC or resizing the Details pane in dark mode has been removed. Reliability of relevant explorer.exe processes is improved so they stop after File Explorer windows are closed.
  • Input - Voice typing on the touch keyboard now shows animations directly on the dictation key instead of displaying a full-screen overlay. The Arabic 101 Legacy keyboard layout is now available under Time and Language settings. Reliability of setting custom tools for wheel devices is improved. Persistence of the Fluid Dictation setting is improved. Reliability of keyboard navigation for the emoji panel (Windows logo key + Period) is improved. Typing reliability when using the ADLaM keyboard is improved.
  • Sharing - Drag Tray is renamed Drop Tray, its settings have moved to Settings > System > Multitasking, and it now uses a smaller peek view to reduce accidental openings.
  • Taskbar agent monitoring - A new taskbar experience lets users monitor long-running agents from first- and third-party apps. The Microsoft 365 Copilot app's Researcher feature is the first adopter, showing real-time progress and a completion notification on the taskbar.
  • Enterprise State Roaming (ESR) - ESR can now be managed through Windows Backup for Organizations policies, simplifying configuration for IT administrators.
  • Printing - A new icon in print settings indicates whether a printer supports Windows Protected Print Mode.
  • Microsoft Store - Unexpected errors during app downloads and installations, including errors 0x80070057, 0x80240008, and 0x80073d28, are reduced.
  • Fonts - Leelawadee UI font family improvements cover Thai, Lao, Khmer, and Lontara scripts, enhancing glyph sequencing, positioning, and rendering.
  • Audio - Third-party driver compatibility with midisrv.exe is improved. Shared Audio feature added (see Highlights).
  • Taskbar - Reliability of loading the system tray area is improved.
  • Windows Hello - Reliability of Windows Hello Face recognition is improved. Persistence of Windows Hello Fingerprint settings across upgrades is improved.
  • Storage - Performance when viewing storage information for large volumes in Settings > System > Storage > Advanced Storage Settings > Disks and Volumes is improved. The FAT32 volume formatting size limit from the command line increases from 32 GB to 2 TB.
  • Delivery Optimization - Memory usage is reduced, lowering the likelihood of unexpectedly high memory consumption.
  • Display and graphics - Persistence and availability of color profile options for supported monitors is improved.
  • Kiosk mode - Configuration for allowed packaged apps in kiosks is simplified when Microsoft Edge is among the allowed apps.
  • General Performance - Startup app launch performance after device startup is improved (apps listed under Settings > Apps > Startup).
  • General Reliability - Underlying changes improve explorer.exe reliability at sign-in, when interacting with taskbar menus and Task View, when unpinning items from File Explorer's Quick Access, and in other scenarios.
  • Secure Boot - Windows quality updates now include additional high-confidence device targeting data to expand coverage of devices eligible to automatically receive new Secure Boot certificates, using a controlled and phased rollout. A new Group Policy and MDM setting, LimitSecureBootRequiredServiceData, is added under Computer Configuration > Administrative Templates > Windows Components > Secure Boot. When enabled, Windows suppresses the Secure Boot service data event normally sent to Microsoft.
  • AI components updated - Image Search, Content Extraction, Semantic Analysis, and Settings Model components are all updated to version 1.2604.515.0.

Known issues

Microsoft lists no known issues for this update at the time of writing.

How to get this update

Microsoft combines the latest servicing stack update for the operating system with the latest cumulative update in this package. Devices that have installed earlier updates will download and install only the new content in this package.

Windows Update - Open Start > Settings > Update and Security > Windows Update. The update appears in the Optional updates available area. Select the link to download and install it.

Windows Update for Business - These changes will appear in the next security update to Windows Update for Business.

Microsoft Update Catalog / WSUS - Download the standalone package for KB5089570 from the Microsoft Update Catalog. The package contains one or more MSU files that must be installed in a specific order. Two installation methods are supported:

  • Method 1 - Download all MSU files and place them in the same folder. Use DISM.exe with the /Add-Package /PackagePath switch pointing to that folder. DISM discovers and installs prerequisite MSU files automatically. The same result can be achieved with the Add-WindowsPackage PowerShell cmdlet or Windows Update Standalone Installer.
  • Method 2 - Download and install each MSU file individually using DISM or Windows Update Standalone Installer in the documented order. The primary file is windows11.0-kb5089570-arm64_f5ceb5d832355adf56ca80ec52f19a6be6e73af5.msu.

To apply this update to Windows installation media rather than a running system, follow the Update Windows installation media with Dynamic Update guidance. Ensure any additional Dynamic Update packages match the same release month as this KB.

Frequently asked questions

Is this update mandatory, and will it install automatically?

KB5089570 is an optional, non-security preview update. It will not install automatically on most configurations. Devices running Windows Update will see it listed under Optional updates available. It is not pushed as a required update, so administrators must opt in or schedule deployment manually before its contents are rolled into a future mandatory release.

What prerequisite must be in place before installing this update?

Microsoft bundles the latest servicing stack update (SSU KB5095676, build 28000.2172) together with this cumulative update, so no separate SSU installation step is required before applying KB5089570. Devices that already have earlier cumulative updates installed will download only the new delta content.

How does the new Windows Driver Policy change affect existing third-party drivers?

The update removes default trust for cross-signed drivers that are not part of the Windows Hardware Compatibility Program or an approved legacy allow list. Windows audits driver compatibility for at least 100 hours and three reboots before enforcement begins. After enforcement, a small number of cross-signed drivers may be blocked. Administrators should review the Windows driver policy documentation and the Advancing Windows driver security blog before deploying broadly.

How can administrators enable the new secure batch file processing mode?

Administrators can enable the mode by adding a DWORD registry value named LockBatchFilesWhenInUse under HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, set to 1 to enable or 0 to disable. Application Control for Business policy authors can alternatively enable it through the LockBatchFilesWhenInUse application manifest control, as documented in the Application Control for Business manifest schema.

#windows-11#cumulative-update#preview#26h1#ai-features#secure-boot#driver-policy

Related topics