Hi all, Last Wednesday Microsoft released the last insider flight of the year, Windows 11 Insider Preview Build 26120.2705 (KB5050636) to the Dev Channel.
This Build adds real-time translation in live captions for AMD and Intel®-powered Copilot+ PCs and an improvement for real-time translation on Snapdragon-powered Copilot+ PCs. Beyond these two changes, this update is the same as the update released to the Dev Channel last week.
Smooth flighting on all my Dev Channel devices, Happy Flighting!
New experiences for AMD and Intel®-powered Copilot+ PCs
Please install all the latest driver updates available from Windows Update to ensure the following experience work correctly on your AMD or Intel®-powered Copilot+ PC. To ensure you have the latest drivers for your Copilot+ PC, make sure the “Get the latest updates as soon as they’re available” toggle is on under Settings > Windows Update. Just click the “Check for updates” button and install any new drivers that Windows Update delivers to you.
If you’d like to test the latest driver versions available directly from our partners before they get to Windows Update, you can download them directly here:
We are enhancing communication on AMD and Intel®-powered Copilot+ PCs with live captions and real-time translation. We’re beginning to roll out the ability in live captions to translate more than 44 languages into English, including speakers in real-time video calls, recordings and streamed content. Real-time translation is rolling out AMD and Intel®-powered Copilot+ PCs with English as the primary language in use. Be sure to check the known issues for real-time translation in live captions documented below in this blog post.
FEEDBACK: Please file feedback in Feedback Hub (WIN + F) under Accessibility > Live captions.
Changes and Improvements gradually being rolled out to the Dev Channel with toggle on*
[Live captions]
On Snapdragon-powered Copilot+ PCs, we’re beginning to roll out the ability to do real-time translation to Chinese (Simplified). Supported languages include Arabic, Bulgarian, Czech Danish, German, Greek English Spanish, English, Estonian, Finnish, France, Hindi, Hungarian, Italian, Japanese, Korean, Lithuanian, Norwegian, Dutch, Polish, Portuguese, Romanian, Russian, Slovak, Slovene, and Swedish.
Known issues
[General]
After you do a PC reset under Settings > System > Recovery, your build version may incorrectly show as Build 26100 instead of Build 26120. This will not prevent you from getting future Dev Channel updates which will resolve this issue.
[Recall]
The following known issues will be fixed in future updates to Windows Insiders:
Recall can be enabled or disabled from “Turn Windows features on or off”. We are caching the Recall binaries on disk while we test add/remove. In a future update we will completely remove the binaries.
Some users may see a message to “Make sure Recall is saving snapshots”, while the Settings page for Recall shows saving snapshots is enabled. Reboot your device to resolve this issue.
Make sure you update Microsoft 365 apps to the latest version so you can jump back into specific documents.
[Click to Do]
The following known issues will be fixed in future updates to Windows Insiders:
Sometimes additional context is given when using more intelligent text actions powered by Phi Silica.
The intelligent text actions leverage the power of Microsoft’s secure cloud to improve your text results by ensuring prompts and responses are safe and appropriate. This data is automatically deleted. Local moderation to ensure the safety of prompts and responses will be added in the future, replacing this cloud endpoint.
Sometimes Click to Do doesn’t highlight any info on screen if there is no content on a connected external monitor in extended mode.
[Live captions & real-time translation]
The following known issues will be fixed in future updates to Windows Insiders:
Some Insiders may see a crash on first launch of live captions. Restart live captions if you encounter this issue and you will not see it again.
If audio is playing or the microphone is enabled, switching languages will crash live captions. Stop audio when changing languages to resume captions or translations.
Hello Windows Insiders, today we are releasing Windows 11 Insider Preview Build 26120.2702 (KB5048761) to the Dev Channel.
Changes in Dev Channel builds and updates are documented in two buckets: new features, improvements, and fixes that are being gradually rolled out for Insiders who have turned on the toggle to get the latest updates as they are available (via Settings > Windows Update*) and then new features, improvements, and fixes rolling out to everyone in the Dev Channel. For more information, see the Reminders section at the bottom of this blog post.
New features gradually being rolled out to the Dev Channel with toggle on*
Windows Camera Advanced Configurations
We are beginning to roll out a new advanced camera options page. Just navigate to a camera under Settings > Bluetooth & devices > Cameras and click the edit button for advanced camera options.
This new advanced camera options page will provide you with the following two configurations for your camera:
Multi-app camera: Allows multiple applications to access the camera stream simultaneously, developed with the Hard-of-Hearing community to enable video streaming to both a sign language interpreter and the end audience at the same time.
Basic camera: Enables basic camera functionality for improved debugging, recommended as a last resort when your camera is not functioning correctly. This feature was developed in collaboration with Microsoft support agents.
Coming in a future build, we plan to introduce a third option here for selecting a media type. This feature will let you choose different media types like resolution and frame rate, with the default setting being “Let Windows Choose” for optimal experience.
FEEDBACK: Please file feedback in Feedback Hub (WIN + F) under Devices and Drivers > Device Camera or Webcams.
Passwordless Improvements
As part of Microsoft’s commitment to a passwordless future, on Windows, we are launching API support for third-party passkey providers. Microsoft has been engaging with passkey manager partners on developing this capability. We are committed to bringing a passwordless future to all customers – together with third-party credential providers, we will raise the bar on login security with passkeys for all users on Windows.
WebAuthn Plugin Authenticator APIs
We are releasing updates to WebAuthn APIs to support a plugin authentication model for passkeys. In the coming months, Windows customers will be able to choose a third-party provider as an additional choice alongside the native Windows passkey provider while maintaining the Windows Hello user experience. Messages in WebAuthn flows will be forwarded to the plugin and responses are returned to the WebAuthn client applications. This enables plugins to create and authenticate with passkeys when requested by the customer. This model allows plugins to use Windows Hello as a user verification mechanism to enable a seamless passkey experience. You will notice additional user experience updates to the passkey flows and Settings alongside the new capabilities.
If you are a developer for third-party passkeys, we invite you to integrate with Windows 11 to support customers in their passkey journey. To find out more about implementation detail, go to https://aka.ms/3P-Plugin-API.
FEEDBACK: Please file feedback in Feedback Hub (WIN + F) under Security and Privacy > Passkey.
Changes and Improvements gradually being rolled out to the Dev Channel with toggle on*
[Start menu]
We are improving the filtering for recommended websites on the Start menu based on feedback from Windows Insiders so that we show the highest quality sites based on your own browsing history. Please continue to give us feedback if you see a website recommended you feel shouldn’t be.
[Settings]
The ability to change time zones is available again under Settings > Time & Language > Date & Time for standard (non-admin) users.
Fixes gradually being rolled out to the Dev Channel with toggle on*
[Input]
Fixed an issue where if pointer trails were enabled, the mouse cursor may become invisible with a black box behind it.
Mitigated an issue where the ALT or Shift key on the keyboard may get stuck down in the latest flights after the Windows Hello prompt appeared for some Insiders.
Fixed an issue which could lead to the mouse cursor unexpectedly stuttering when you moved it around sometimes.
[Graphics]
Fixed an underlying issue which could result in some games appearing oversaturated when using Auto HDR.
Fixes for everyone in the Dev Channel
[Rollback]
We fixed the issue where if you roll back from Build 26120.2510 to an earlier build, you would see an “Your organization used App Control for Business to block this app” dialog when attempting to use or install certain third-party apps on your PC due to an incorrect policy being enforced.
Known issues
[General]
[NEW] After you do a PC reset under Settings > System > Recovery, your build version may incorrectly show as Build 26100 instead of Build 26120. This will not impact you from getting future Dev Channel updates which will resolve this issue.
[Recall]
The following known issues will be fixed in future updates to Windows Insiders:
Recall can be enabled or disabled from “Turn Windows features on or off”. We are caching the Recall binaries on disk while we test add/remove. In a future update we will completely remove the binaries.
Some users may see a message to “Make sure Recall is saving snapshots”, while the Settings page for Recall shows saving snapshots is enabled. Reboot your device to resolve this issue.
Make sure you update Microsoft 365 apps to the latest version so you can jump back into specific documents.
[Click to Do]
The following known issues will be fixed in future updates to Windows Insiders:
Sometimes additional context is given when using more intelligent text actions powered by Phi Silica.
The intelligent text actions leverage the power of Microsoft’s secure cloud to improve your text results by ensuring prompts and responses are safe and appropriate. This data is automatically deleted. Local moderation to ensure the safety of prompts and responses will be added in the future, replacing this cloud endpoint.
Sometimes Click to Do doesn’t highlight any info on screen if there is no content on a connected external monitor in extended mode.
Microsoft Edge Game Assist (Preview)
We invite Windows Insiders to try out Microsoft Edge Game Assist (Preview)!
Game Assist is the first in-game browser that delivers a rich gaming-centric browsing experience—including access to your browser data from your PC and mobile devices. Game Assist is a special version of Microsoft Edge that’s optimized for PC gaming and can appear on top of your game in Game Bar. It’s game-aware and will suggest tips and guides for what you’re playing. It also shares the same browser data with Edge on your PC so the information you care about is always accessible while you play, including your favorites, history, cookies, form fills, and more. Check out this blog post for more details and how to get started using Game Assist!
Hi all, last Wednesday Microsoft released Windows 11 Insider Preview Build 27764 to the Canary Channel.
A few small tweaks and fixes in this one,
All my Canary devices upgraded smoothly to this build, Happy Upgrading!
Changes and Improvements
[Start menu]
When right-clicking on apps pinned to the Start menu, jump lists will be shown for apps that have them such as PowerPoint, Word and more.
[Dynamic Lighting]
When no compatible devices are attached, the Dynamic Lighting settings page will now show a placeholder message and Brightness and Effects controls are disabled.
On the Dynamic Lighting settings page, we have added Forward, Backward, Outward and Inward direction options to the Wave effect, and added the Forward direction option to the Gradient effect.
[Input]
We are beginning to roll out a change where we now hide the IME toolbar when apps are in full screen mode for those who have the IME toolbar enabled and type in Chinese or Japanese.
[Narrator]
We have added new functionalities to Narrator scan mode. Skip past links (N’) allows you to navigate to the text after a link. This is most helpful when navigating through long emails, news articles, and wiki pages. Jump to lists (L’) allows you to quickly access a list on a web page or a document. To try these new features, you need to turn on Narrator first (Win key + Ctrl + Enter), then turn scan mode ON by pressing Caps Lock + Spacebar and finally use the new shortcuts – ‘N’ and ‘L’. Please note that scan mode is ‘ON’ by default on most web pages (like news articles, wiki page, etc.).
[Speech in Windows]
We have improved our speech-to-text and text-to-speech experience on Windows. Users of Narrator, voice access, live captions, live translations, and voice typing might see a message asking them to update their language files manually. The language files will be released separately through Microsoft Store.
Fixes
[General]
Fixed an issue causing some Insiders to see a bugcheck with error PAGE_FAULT_IN_NONPAGED_AREA while using their PC starting with Build 27754.
[File Explorer]
We did some work to help address an issue where File Explorer might hang when browsing a folder with lots of media in it.
[Taskbar & System Tray]
Fixed an issue on secondary monitors for left aligned taskbar users, where the widgets text in the taskbar might overlap the date and time.
[Input]
Fixed an issue where if pointer trails were enabled, the mouse cursor may become invisible with a black box behind it.
[Task Manager]
Fixed an issue where some HDDs were being incorrectly listed as SSD on the Performance page.
[Display]
Fixed an issue which could result in lag and screen tearing on secondary monitors with full screen windows.
[Other]
Fixed an underlying issue which could lead to Excel sometimes hanging on launch when opening certain files.
Known issues
[General]
[IMPORTANT NOTE FOR COPILOT+ PCs] If you are joining the Canary Channel on a new Copilot+ PC from the Dev Channel, Release Preview Channel or retail, you will lose Windows Hello pin and biometrics to sign into your PC with error 0xd0000225 and error message “Something went wrong, and your PIN isn’t available”. You should be able to re-create your PIN by clicking “Set up my PIN”.
We’re investigating reports that some Insiders are still experiencing rollbacks (with error code 0xc190010) when attempting to install the latest Canary builds.
We’re working on the fix for an underlying issue causing accent colored window borders to not be not displayed when enabled, shadows around windows not displaying when enabled, and window launching (and other) animations to show even though the setting to show animations is turned off.
Hi all, last Friday Microsoft released Windows 11 Insider Preview Build 26120.2510 (KB5048780) to the Dev Channel. With this update, we are previewing new experiences for AMD and Intel®-powered Copilot+ PCs including Recall and more and expanding Click to Do (Preview) beyond Recall in Windows.
Exciting times Copilot+ experiences are amazing, I had a problem with recall not showing recorded items, this update fixed that nicely.
Happy Upgrades
Join the Dev Channel on your Copilot+ PC
Here is how you can join the Dev Channel on your Copilot+ PC today (we have a video too!):
Register for the Windows Insider Program here via our website with your Microsoft account or Microsoft Entra ID. This should be the same account you use to sign into your Copilot+ PC with.
After you have registered, go to Settings > Windows Update > Windows Insider Program on your PC and select the Get Started button.
When asked to link an account, choose the account you’re signed into Windows with and be sure that it is the same account you registered for the program with.
Choose the Dev Channel and reboot.
After rebooting and signing into your Copilot+ PC, go to Settings > Windows Update and check for updates and Build 26120.2510 should be offered.
Your PC will download the update and reboot to finish the update process.
New experiences for AMD and Intel®-powered Copilot+ PCs
The following experiences are rolling out to Windows Insiders in the Dev Channel on AMD and Intel®-powered Copilot+ PCs. Please install all the latest driver updates available from Windows Update to ensure the following experiences, like Recall, work correctly on your PC. To ensure you have the latest drivers for your Copilot+ PC, make sure the “Get the latest updates as soon as they’re available” toggle is on under Settings > Windows Update. Just click the “Check for updates” button and install any new drivers that Windows Update delivers to you.
If you’d like to test the latest driver versions available directly from our partners before they get to Windows Update, you can download them directly here:
After previewing Recall with our Windows Insider community on Snapdragon-powered Copilot+ PCs, we are expanding the preview of Recall to Windows Insiders on AMD and Intel®-powered Copilot+ PCs. This includes Click to Do in Recall as well. With the AI capabilities of Copilot+ PCs, it’s now possible to quickly find and get back to apps, website, image, or document just by describing its content.
We continue to invite you to try out Recall and share feedback, issues, or suggestions for improvement through in-experience links or the Feedback Hub. We also want to recognize the contributions of researchers and the security community in shaping Recall. If you’re an Insider also in this group, we additionally invite feedback on Recall’s updated security and privacy architecture through participation in our Windows Insider Preview Bug Bounty Program.
To get started, check out this blog post which highlights all the steps required to opt-in to using Recall and saving snapshots on your Copilot+ PC.
As we gradually roll out Recall in preview, Recall is supported on select languages including Chinese (simplified), English, French, German, Japanese, and Spanish. Content-based and storage limitations apply. See here for more details. Recall is not yet available in all regions, with expanded availability coming over time. As part of today’s update, we’re expanding the roll out of Recall (Preview) through the Windows Insider Program to the European Economic Area (EEA).
As a reminder for when we first preview new features with Windows Insiders, you may encounter some known issues listed at the bottom of this blog post we highly recommend you read.
FEEDBACK: Please file feedback in Feedback Hub (WIN + F) under Desktop Environment > Recall or through in-experience links.
Cocreator in Paint
Microsoft Paint is your creative companion, making it effortless to bring your visions to life. The latest update to the Paint app (version 11.2410.1002.0 and higher) brings Cocreator to AMD and Intel®-powered Copilot+ PCs. Paint Cocreator allows you to create amazing artwork with the help of AI. You can enter a text prompt and start drawing on the Paint canvas, and Cocreator will generate beautiful artwork based on your input, all for free and without the need for a subscription.
We are beginning to roll out Cocreator to AMD and Intel®-powered Copilot+ PCs, so it may not be available on your PC just yet.
FEEDBACK: Please file feedback in Feedback Hub (WIN + F) under Apps > Paint.
Restyle Image and Image Creator in the Photos app
In the latest update to the Microsoft Photos app, we are introducing Image Creator and Restyle Image to AMD and Intel® Copilot+ PCs. These advanced AI-powered features are designed to unlock new creative possibilities—all powered locally on your device for fast and seamless performance.
Image Creator lets you generate brand-new images from simple text prompts. For example, you can type “a serene lake at sunset” or “a vibrant city skyline at night,” and the AI will transform your idea into a feed of images. Whether you’re seeking inspiration or crafting the perfect visual, Image Creator delivers endless possibilities for creativity.
Restyle Image allows you to take an existing photo and apply a variety of artistic styles. Whether you want to give your vacation photos a vintage aesthetic or turn a casual snapshot into a bold modern artwork, Restyle Image makes it effortless.
To get these new features, update your Photos app to version 2024.11120.1001.0 or higher via the Microsoft Store. This update is currently rolling out, so it may not be available right away. Don’t forget to share your creations with us!
FEEDBACK: Please file feedback in Feedback Hub (Win + F) under Apps > Photos.
New ways to engage with Click to Do (Preview)
In addition to expanding support for Click to Do with Recall to AMD and Intel®-powered Copilot+ PCs, today’s update also introduces new ways for you to effortlessly engage with Click to Do outside of Recall on Copilot+ PCs. You can now engage with Click to Do by simply pressing WIN key + mouse-click, WIN + Q, through the Snipping Tool menu and print screen, or searching “Click to Do” through the search box on the Windows taskbar. These methods will make it easier than ever to take immediate action on whatever catches your eye on-screen.
We’re also working on introducing more intelligent text actions to enhance your Click to Do experience even further. Use WIN key + mouse-click or WIN + Q to select a text block and then drag to select the text that you want. You’ll see options to Summarize or to help you Rewrite your text, so it sounds more causal or more formal.
Click to Do is the first experience to leverage the capabilities of Phi Silica, the on-device Small Language Model (SLM) that is built right into Windows. Results from our local model will show directly inline and if you’re happy with the rewrites you can copy them directly to your clipboard for use anywhere. These more intelligent text actions are available on Snapdragon-powered Copilot+ PCs today when your language is set to English with support for AMD and Intel®-powered Copilot+ PCs coming soon.
The intelligent text actions leverage the power of Microsoft’s secure cloud to improve your text results by ensuring prompts and responses are safe and appropriate. This data is automatically deleted. The analysis of your screen is always performed locally on your device. Content is only shared out of Click to Do if you choose to complete an action, like copying text to your clipboard, for use in another app, or sharing an image with Bing for a visual search.
You can continue to use the same image and text actions you saw for the Click to Do in the Recall experience we released two weeks ago as well including on AMD or Intel®-powered Copilot+ PCs too. Click to Do in Recall will recognize text and images in snapshots and offers AI powered actions you can take on these. Just press the Windows logo key and left mouse-click on any image in a snapshot in Recall to get options like Copy, Save, Share, Visual Search with Bing, Blur background with Photos, or Remove background with Paint. And by pressing the WIN key and left mouse-click on any text in a snapshot will give you options to Copy, Search the web, or send email or open a website if an email or URL is recognized.
To use Click to Do, you will need to have Recall enabled on your Copilot+ PC but do not have to opt in to having snapshots saved.
FEEDBACK: Please file feedback in Feedback Hub (WIN + F) under Desktop Environment > Click to Do.
Other changes included in this Dev Channel update
This update (Build 26120.2510) includes other changes and improvements available to Windows Insiders across all Windows 11 PCs in addition to the features noted above that are exclusive to Copilot+ PCs. These changes are documented below in two buckets:
New features, improvements, and fixes that are being gradually rolled out for Insiders who have turned on the toggle to get the latest updates as they are available (via Settings > Windows Update*).
New features, improvements, and fixes rolling out to everyone in the Dev Channel.
For more information, see the Reminders section at the bottom of this blog post.
New features gradually being rolled out to the Dev Channel with toggle on*
Modernized Windows Hello
At Microsoft, we are committed to security and enhancing user experiences. As part of this commitment, we launched enhanced passkey features in September 2023 and are now revamping the Windows Hello user experience. This represents a significant update to Windows Hello, aligning it with contemporary Windows visual design standards. The primary focus is on making authentication intuitive and seamless.
Modernized Windows Hello Visual Communication: The updated Windows Hello visuals are designed to facilitate fast and clear communication and appear on the Windows Sign-in screen as well as other authentication flows such as passkey, Recall, Microsoft Store and many more.
Revamped Windows Hello credential user experience for passkeys and the new administrator protection experience: We redesigned Windows security credential user experience for passkey by creating a cleaner experience that supports secured and quick authentication. Users will now be able to switch between authentication options and select passkey/devices more intuitively.
This experience will also apply for the new administrator protection feature coming to Windows 11, version 24H2 and higher and currently in preview with Windows Insiders in the most recent Canary Channel builds. For more information on administrator protection – you can check out this blog post that highlights our investments in adminless experiences in Windows from Microsoft Ignite.
FEEDBACK: Please file feedback in Feedback Hub (WIN + F) under Security and Privacy > Passwordless experience.
Changes and Improvements gradually being rolled out to the Dev Channel with toggle on*
[Taskbar & System Tray]
The more simplified system tray with shortened form date/time we began rolling out with Build 26120.1843 is being temporarily disabled to address a few issues. Thanks to all the Insiders who gave us feedback on this experience.
Fixes gradually being rolled out to the Dev Channel with toggle on*
[Taskbar & System Tray]
Fixed a few issues impacting taskbar and explorer.exe reliability.
[Audio]
Fixed an underlying issue which could lead to USB audio devices going to sleep after 1 minute of idle time, and not waking up until the PC was rebooted.
Fixed an underlying issue which could lead you to unexpectedly hear a mute or unmute noise in certain headsets.
Fixed an underlying issue that could lead to the audio on certain audio devices unexpectedly going to 100% on boot or after sleep.
[Other]
Fixed an underlying issue which could lead to Excel sometimes hanging on launch when opening certain files.
Fixes for everyone in the Dev Channel
[Recall]
Fixed an issue where Recall didn’t warn that you must have Secure Boot enabled for Recall to save snapshots.
Improved the experience for submitting feedback for Recall by adding a loading dialog.
Fixed an issue where some users experience a delay before snapshots first appear in the timeline while using their device.
Fixed an issue where Recall won’t save any snapshots if you join the Dev Channel and install Build 26120.2415 after installing KB5046740.
[Other]
[Exporting chart objects] Fixed: An app stops responding when it exports chart objects in PDF and XLSX formats.
[Internet connection] Fixed: A small number of devices cannot connect to the internet. This occurs when a DHCP server response has duplicate DHCP options. This stops IPv4 connections on certain networks.
[Display] Fixed: Some secondary displays might experience lag and screen tearing when a window is in full screen.
[HTML Applications (HTA)] Fixed: HTA optional components (OC) are now in ARM64 Windows PE.
Known issues
[Rollback]
There is an issue where if you roll back from Build 26120.2510 to Build 26120.2415, you will see an “Your organization used App Control for Business to block this app” dialog when attempting to use or install certain third-party apps on your PC due to an incorrect policy being enforced. To avoid this, please take the following steps FIRST before rolling back:
Open Command Prompt with administrator privileges.
Type and hit enter: mountvol s: /s
Type and hit enter: del S:\EFI\Microsoft\Boot\cipolicies\active\{8E8A94F0-6EB9-42C7-A189-E018C8CF3D10}.cip
Type and hit enter: del S:\EFI\Microsoft\Boot\cipolicies\active\{36D62F7C-AB85-4F61-8724-744294F24023}.cip
Type and hit enter: del S:\EFI\Microsoft\Boot\cipolicies\active\{66D7D265-7EDD-47DD-86E4-F7C42CD55A8F}.cip
Then proceed with rolling back.
Note if you update back to Build 26120.2510 after rolling back, you will still need to do this workaround.
If you do not do these steps FIRST before rolling back, your PC could get into a bad state. If you run into issues with Build 26120.2510, we recommend trying the option “Fix problems using Windows Update” via Settings > Recovery which delivers an in-place upgrade (IPU) of Build 26120.2510 instead of rolling back. We expect to have this issue fixed with the next Dev Channel flight.
[Recall]
The following known issues will be fixed in future updates to Windows Insiders:
Recall can be enabled or disabled from “Turn Windows features on or off”. We are caching the Recall binaries on disk while we test add/remove. In a future update we will completely remove the binaries.
Some users may see a message to “Make sure Recall is saving snapshots”, while the Settings page for Recall shows saving snapshots is enabled. Reboot your device to resolve this issue.
Make sure you update Microsoft 365 apps to the latest version so you can jump back into specific documents.
[Click to Do]
The following known issues will be fixed in future updates to Windows Insiders:
Sometimes additional context is given when using more intelligent text actions powered by Phi Silica.
The intelligent text actions leverage the power of Microsoft’s secure cloud to improve your text results by ensuring prompts and responses are safe and appropriate. This data is automatically deleted. Local moderation to ensure the safety of prompts and responses will be added in the future, replacing this cloud endpoint.
Sometimes Click to Do doesn’t highlight any info on screen if there is no content on a connected external monitor in extended mode.
Microsoft Store Update
For Win32 apps that are “provided and updated” by their publishers, the Microsoft Store will now support updating directly in the Store. Previously, these apps could only be updated outside of the Microsoft Store. Insiders can head to the Downloads page and click Get Updates. If any installed apps of this type have updates, it’ll be displayed on the pending list. You can perform the update by clicking the update button; it won’t start automatically.
You can also head to the product page and see an update button.
Windows Insiders across all channels running Microsoft Store version 22411.1401.x.x and higher will see this improvement.
Hi all, Last Wednesday Microsoft released Windows 11 Insider Preview Build 27758 to the Canary Channel.
This Build brings some nice stuff, shared camera usage, this enables Windows Hello to use the camera for elevation even during a video call nice!
Win32 app updates via the store make keeping apps up2date way easier
Happy Upgrades!!
What’s new in Build 27758
Windows Camera Advanced Configurations
We have introduced a new advanced camera options page in this build. Just navigate to a camera under Settings > Bluetooth & devices > Cameras and click the edit button for advanced camera options.
This new advanced camera options page will provide you with the following two configurations for your camera:
Multi-app camera: Allows multiple applications to access the camera stream simultaneously, developed with the Hard-of-Hearing community to enable video streaming to both a sign language interpreter and the end audience at the same time.
Basic camera: Enables basic camera functionality for improved debugging, recommended as a last resort when your camera is not functioning correctly. This feature was developed in collaboration with Microsoft support agents.
Coming in a future build, we plan to introduce a third option here for selecting a media type. This feature will let you choose different media types like resolution and frame rate, with the default setting being “Let Windows Choose” for optimal experience.
FEEDBACK: Please file feedback in Feedback Hub (WIN + F) under Devices and Drivers > Device Camera or Webcams.
Fixes
[File Explorer]
Did some work so the search box in File Explorer shouldn’t draw off the end of the window anymore.
[Taskbar]
Fixed an issue where right clicking on app icons in the taskbar might crash explorer.exe in the previous flight.
[Input]
Fixed an issue for some people where the mouse cursor would become invisible when hovering over text fields in certain apps.
[Desktop]
Fixed an issue where your desktop background might not show correctly sometimes with multiple monitors (showing big black areas).
[Task Manager]
We are beginning to roll out a fix for the issue where if you resized Task Manager to be larger while settings was open, the Mica background wouldn’t align with the new window size.
[Narrator]
Fixed an issue in the previous flight which caused Narrator to crash on launch if you used one of the natural voices (like Jenny).
[Audio]
Fixed an underlying issue which could lead to USB audio devices going to sleep after 1 minute of idle time, and not waking up until the PC was rebooted.
Fixed an underlying issue which could lead you to unexpectedly hear a mute or unmute noise in certain headsets.
[Settings]
Fixed an issue which could cause Settings to crash when selecting your default audio device.
[Other]
Fixed an issue which could cause an unexpected black line along the top border of a window.
Known issues
[General]
[IMPORTANT NOTE FOR COPILOT+ PCs] If you are joining the Canary Channel on a new Copilot+ PC from the Dev Channel, Release Preview Channel or retail, you will lose Windows Hello pin and biometrics to sign into your PC with error 0xd0000225 and error message “Something went wrong, and your PIN isn’t available”. You should be able to re-create your PIN by clicking “Set up my PIN”.
We’re investigating reports that some Insiders are still experiencing rollbacks (with error code 0xc190010) when attempting to install the latest Canary builds.
We’re working on the fix for an underlying issue causing accent colored window borders to not be not displayed when enabled, shadows around windows not displaying when enabled, and window launching (and other) animations to show even though the setting to show animations is turned off.
[NEW] We’re working on the fix for an issue causing some Insiders to see a bugcheck with error PAGE_FAULT_IN_NONPAGED_AREA starting with the previous flight.
Microsoft Store Update
For Win32 apps that are “provided and updated” by their publishers, the Microsoft Store will now support updating directly in the Store. Previously, these apps could only be updated outside of the Microsoft Store. Insiders can head to the Downloads page and click Get Updates. If any installed apps of this type have updates, it’ll be displayed on the pending list. You can perform the update by clicking the update button; it won’t start automatically.
You can also head to the product page and see an update button.
Windows Insiders across all channels running Microsoft Store version 22411.1401.x.x and higher will see this improvement.
Hi all, last Friday Microsoft released Windows 11 Insider Preview Build 26120.2415 (KB5046723) to the Dev Channel. With this update, we welcome Windows Insiders with Snapdragon-powered Copilot+ PCs to join the Dev Channel to try out Recall (Preview) with Click to Do (Preview).
Company managed devices have the recall feature disbaled by default, so the options will not be available in settings untill you to use Intune or Group Policy to allow the feature.
You can find the setting here: ( more info @ Manage Recall )
Once enabled LLM downloads run in the background through Windows Update
Join the Dev Channel on your Copilot+ PC
Here is how you can join the Dev Channel on your Copilot+ PC today (we have a video too!):
Register for the Windows Insider Program here via our website with your Microsoft account or Microsoft Entra ID. This should be the same account you use to sign into your Copilot+ PC with.
After you have registered, go to Settings > Windows Update > Windows Insider Program on your PC and select the Get Started button.
When asked to link an account, choose the account you’re signed into Windows with and be sure that it is the same account you registered for the program with.
Choose the Dev Channel and reboot.
After rebooting and signing into your Copilot+ PC, go to Settings > Windows Update and check for updates and Build 26120.2415 should be offered.
Your PC will download the update and reboot to finish the update process.
New Copilot+ PC experiences
Retrace your steps with Recall (Preview)
We’re excited to release the first preview of Recall to our Windows Insider community. Recall is an entirely new way to search for things you’ve seen or done on your PC securely. With the AI capabilities of Copilot+ PCs, it’s now possible to quickly find and get back to any app, website, image, or document just by describing its content.
We invite you to try out Recall and share feedback, issues, or suggestions for improvement through in-experience links or the Feedback Hub. We also want to recognize the contributions of researchers and the security community in shaping Recall. If you’re an Insider also in this group, we additionally invite feedback on Recall’s updated security and privacy architecture through participation in our Windows Insider Preview Bug Bounty Program.
As is typical when first previewing new features with Windows Insiders, you may encounter some known issues listed at the bottom of this blog post we highly recommend you read.
Setup: After installing this build, the models for Recall and Click to Do will start to download in the background. You can check the download status via Settings > Windows Update. To open Recall you can find it in the Start menu under the All apps list.
When you open Recall, you can complete the first-run experience, which will ask you to opt-in to saving snapshots. It will also require you to enroll in Windows Hello to confirm your presence. This requires you to enable BitLocker and Secure Boot if you haven’t already. If you don’t enable saving snapshots, Recall will not save any snapshots of your activity.
Find It: Use your PC as you normally would. When you need to find or get back to something you’ve done previously, open Recall and authenticate with Windows Hello. As we use our PCs throughout the day working on documents or presentations, taking video calls, and context switching across activities, Recall helps you find things faster and easier and reduces the strain when you can’t remember something. Search using the clues you remember. You can not only search for the text you need to get back to, but now simply describe what you’re looking for (“pie chart”). You can also browse the timeline to see snapshots from a specific time you remember and get right back to that document or website quickly. Recall’s search results leverage AI to provide both text and visual matches for your query. AI can make mistakes, if the results aren’t accurate or don’t look right, please provide us with feedback using the feedback link. When you’ve found what you were looking for, you can get back to the application, website, or document, or use Click to Do to act on any image or text in the snapshot you found. You can learn more about using Recall here.
Control: With Recall, you’re in control of what snapshots are saved and when Recalls saves them. A new icon in the system tray displays status and provides quick access to Recall actions. When Recall is enabled, you’ll see the Recall icon visible. It provides visual cues to remind you when snapshots are being analyzed and saved. Click the icon and you will be able to pause saving snapshots or view more status information. When paused, you see a slash through the icon.
You can delete any snapshot in Recall that you don’t want and tell Recall to ignore that app or website in that snapshot going forward, either when viewing an individual snapshot or by searching for what you want deleted and removing those results.
Your data: Insiders and Recall users, we want you to know your snapshots are truly yours. We do not send your snapshots off your PC to Microsoft or third parties, and don’t use them for training purposes. Microsoft can’t access the keys to view your encrypted data, so we can’t restore your snapshots if you remove Windows Hello or restore your snapshots if you need to reset your PC or move to a new PC. We will in future updates provide ways for you to store a backup of your keys for these cases. For now, your Copilot + PC only releases the keys to use Recall if you show your face, fingerprint, or PIN. Please note that while in preview, we may make updates that require a reset of your saved snapshots and will let you know here. Technical Insiders can learn more about the security and privacy architecture of Recall here.
Privacy: We’ve updated Recall to detect sensitive information like credit card details, passwords, and personal identification numbers. When detected, Recall won’t save or store those snapshots. We’ll continue to improve this functionality, and if you find sensitive information that should be filtered out, for your context, language, or geography, please let us know through Feedback Hub. We’ve also provided an option in Settings that we encourage you to enable that will anonymously share the apps and sites you prefer to be excluded from Recall to help us improve the product. And you can also choose to exclude specific apps and websites through the Recall settings page which we talk about below.
Settings: Try out the additional settings available to configure Recall. Changing Recall settings requires you to authenticate with Windows Hello. You can disable saving snapshots, pause temporarily, filter applications and websites in supported browsers, control disk usage, and delete your snapshots at any time via Settings > Privacy and security > Recall and snapshots. Please provide us with feedback if additional settings would improve your experience. You can also remove Recall entirely by typing “Turn Windows features on or off” in the search box on your taskbar. Uncheck Recall from the dialog and restart your PC.
Enterprises: As announced at Ignite, for our enterprise customers, Recall is removed by default on PCs managed by an IT administrator for work or school, as well as Enterprise versions of Windows 11. IT administrators fully control the availability of Recall within their organization. Employees must choose to opt-in to saving snapshots and enroll their face or fingerprint with Windows Hello for snapshots to be saved. Only the signed-in user can access and decrypt Recall data, so although enterprises cannot access employee Recall data, they can prevent Recall from being used altogether and prevent any saving of specific apps or sites. IT administrators can click here to learn more about managing Recall on Copilot+ PCs in their organizations.
Recall (Preview) will begin to rollout on Snapdragon-powered Copilot+ PCs, with support for AMD and Intel-powered Copilot+ PCs coming soon. As we gradually roll out Recall in preview, Recall is supported on select languages including Chinese (simplified), English, French, German, Japanese, and Spanish. Content-based and storage limitations apply. See here for more details. Recall is not yet available in all regions, with expanded availability coming over time.
FEEDBACK: Please file feedback in Feedback Hub (WIN + F) under Desktop Environment > Recall or through in-experience links.
Click to Do (Preview) with Recall
With Click to Do in Recall, you can get more done with snapshots and improve your productivity and creativity. Click to Do recognizes text and images in snapshots and offers AI powered actions you can take on these, saving you time by helping complete tasks inline, and/or quickly getting you to the app that can best complete the job for you.
For text, Click to Do offers the following actions:
Copy: Easily copy text to your clipboard.
Open with: Open the selected text with your preferred application.
Search the web: Quickly search the web for the selected text.
Open website: Open any URL you recognize on screen in your preferred browser
Send email: Send email to the email address recognized on screen in your preferred email app
For image, Click to Do provides a variety of options:
Copy: Copy the image to your clipboard.
Save as: Save the image to your desired location.
Share: Share the image with others.
Open with: Open the image with your preferred application.
Visual search with Bing: Perform a visual search and surface relevant contents using Bing.
Blur background with Photos: Blur the background of the image using Photos app.
Erase objects with Photos: Erase unwanted objects from the image using Photos app.
Remove background with Paint: Remove the background of the image using Paint app.
In this update Click to Do only works within the Recall experience. In a future update, you’ll be able to effortlessly engage with Click to Do by simply pressing Windows logo key + mouse click, Windows logo key + Q, through the snipping tool menu and Print Screen, or searching “Click to Do” through Windows Search Box. These methods will make it easier than ever to take immediate action on whatever catches your eye on-screen. We’re also working on introducing more intelligent text actions to enhance your experience even further.
Just like with Recall noted above, Click to Do (Preview) is available only on Snapdragon-powered Copilot+ PCs. Support for Intel and AMD-powered Copilot+ PCs is coming soon.
FEEDBACK: Please file feedback in Feedback Hub (WIN + F) under Desktop Environment > Click to Do.
Other changes included in this Dev Channel update
This update (Build 26120.2415) includes additional changes and improvements available to Windows Insiders across every Windows 11 PCs. These changes include:
New features, improvements, and fixes that are being gradually rolled out for Insiders who have turned on the toggle to get the latest updates as they are available (via Settings > Windows Update*).
New features, improvements, and fixes rolling out to everyone in the Dev Channel.
For more information, see the Reminders section at the bottom of this blog post.
Changes and Improvements gradually being rolled out to the Dev Channel with toggle on*
[Windows Hello]
The revamped and modernized Windows Hello user experience that is rolling out to Windows Insiders in the Beta and Canary Channels will start rolling out to Insiders in the Dev Channel soon.
[Narrator]
We have added new functionalities to Narrator scan mode. Skip past links (N’) allows you to navigate to the text after a link. This is most helpful when navigating through long emails, news articles, and wiki pages. Jump to lists (L’) allows you to quickly access a list on a web page or a document. To try these new features, you need to turn on Narrator first (Win key + Ctrl + Enter), then turn scan mode ON by pressing Caps Lock + Spacebar and finally use the new shortcuts – ‘N’ and ‘L’. Please note that scan mode is ‘ON’ by default on most web pages (like news articles, wiki page, etc.).
[Speech in Windows]
We have improved our speech-to-text and text-to-speech experience on Windows. Users of Narrator, voice access, live captions, live translations, and voice typing might see a message asking them to update their language files manually. The language files will be released separately through Microsoft Store.
Fixes gradually being rolled out to the Dev Channel with toggle on*
[Taskbar & System Tray]
Fixed an issue causing explorer.exe to crash sometimes when interacting with app icons in the taskbar in the latest flights.
[Desktop]
Fixed the issue where your desktop background may not show correctly sometimes with multiple monitors (showing big black areas).
[File Explorer]
Did some work so the search box in File Explorer shouldn’t draw off the end of the window anymore.
[Input]
Fixed an underlying issue in the last few flights that could cause Windows wheel devices to not scroll.
[Narrator]
Fixed an issue in the previous flight which caused Narrator to crash on launch if you used one of the natural voices (like Jenny).
Known issues
[Recall with Click to Do]
The following known issues will be fixed in future updates to Windows Insiders:
You must have Secure Boot enabled for Recall to save snapshots. Ensure Secure Boot is enabled before trying out Recall. This support article will help you enable Secure Boot.
Clicking links within Recall to submit feedback may experience a delay in loading the Feedback Hub application. Be patient and it will display.
Recall can be enabled or disabled from “Turn Windows features on or off”. We are caching the Recall binaries on disk while we test add/remove. In a future update we will completely remove the binaries.
Some users experience a delay before snapshots first appear in the timeline while using their device. If snapshots do not appear after 5 minutes, reboot your device. If saving snapshots is enabled, but you see snapshots are no longer being saved, reboot your device.
Some users may see a message to “Make sure Recall is saving snapshots”, while the Settings page for Recall shows saving snapshots is enabled. Reboot your device to resolve this issue.
Websites added as filters may be saved if the content is in split screen or side bar pane in Edge. This will be addressed in an update.
Make sure you update Microsoft 365 apps to the latest version so you can jump back into specific documents.
Recall may not currently work with some accessibility applications.
Hi all, last Wednesday Microsoft released Windows 11 Insider Preview Build 27754 to the Canary Channel.
This Build resolved the issue I was still having with RDP connections, where the previous build fixed connecting without the message launing the app failed, this build fixed connections to a 2nd target to dicsonnec the 1st (Feedback Hub https://aka.ms/AAtji2m)
The redesigend Windows Hello graphics are great! nice animations too
What’s new with Build 27754
Modernized Windows Hello
At Microsoft, we are committed to security and enhancing user experiences. As part of this commitment, we launched enhanced passkey features in September 2023 and are now revamping the Windows Hello user experience. This represents a significant update to Windows Hello, aligning it with contemporary Windows visual design standards. The primary focus is on making authentication intuitive and seamless.
Modernized Windows Hello Visual Communication: The updated Windows Hello visuals are designed to facilitate fast and clear communication and appear on the Windows Sign-in screen as well as other authentication flows such as passkey, Microsoft Store and many more.
Revamped Windows Hello credential user experience for passkeys and the new administrator protection experience: We redesigned Windows security credential user experiences for passkey creating a cleaner experience that supports secured and quick authentication. Users will now be able to switch between authentication options and select passkey/devices more intuitively.
This experience will also apply for the new administrator protection feature coming to Windows 11, version 24H2 and higher and currently in preview with Windows Insiders in the most recent Canary Channel builds. For more information on administrator protection – you can check out this blog post that highlights our investments in adminlesss experiences in Windows from Microsoft Ignite.
FEEDBACK: Please file feedback in Feedback Hub (WIN + F) under Security and Privacy > Passwordless experience.
Changes and Improvements
[General]
If you hold Shift and CTRL when clicking on a jump list item in Start menu or taskbar, this will now launch that item as admin, just like if you were to do Shift + CTRL and click the app icon itself. For example, if you right-click on Windows Terminal, and hold Shift and CTRL when you click PowerShell, it would open a PowerShell window as admin.
[Taskbar & System Tray]
We’ve updated the previews that show when you mouse-over/hover over apps on the taskbar. We have also improved the animations for when these previews show on the taskbar based on Insider feedback.
We are trying out a more simplified system tray to highlight the date/time in a shortened form and to show the notifications bell icon based on DND status. Without the notification bell icon, you can get to your notifications by clicking the date and time to Notification Center. You can revert to the long form of the date/time and bell icon visuals by toggling the values in the Settings via Settings > Date and Time under “Show time and day in the system tray” and Settings > System > Notifications under “Notifications”. These settings are also accessible through the context menu shown by right clicking the system tray clock/bell icon button.
Fixes
[General]
Fixed the issue with applying policy for the Digital Markets Act in EEA regions in Build 27749.
Fixed an issue where an update failing and rolling back could potentially result in a duplicate Windows entry in the boot menu.
[File Explorer]
Fixed an underlying issue which was causing RAW images taken in portrait mode to unexpectedly display in landscape mode thumbnails.
Did some work so the search box in File Explorer shouldn’t draw off the end of the window anymore.
[Taskbar & System Tray]
Fixed an issue on secondary monitors for left aligned taskbar users, where the widgets text in the taskbar might overlap the date and time.
[Input]
Fixed an underlying issue which could cause the mouse to unlock from a game window on a system with multiple monitors after opening and closing Game Bar, so you couldn’t use it within the game.
[Other]
Fixed an underlying issue causing some apps used for remoting into other PCs to crash in the latest Canary builds.
Fixed an issue causing some Insiders to see bugchecks with SYSTEM THREAD EXCEPTION NOT HANDLED in the latest Canary builds.
Fixed an issue where sfc /scannow was unexpectedly showing errors every time it was run. This issue is not fixed.
Fixed an underlying issue which could lead to Registry Editor going unresponsive if you pressed Alt after clicking on the license information in the About section.
Known issues
[General]
[IMPORTANT NOTE FOR COPILOT+ PCs] If you are joining the Canary Channel on a new Copilot+ PC from the Dev Channel, Release Preview Channel or retail, you will lose Windows Hello pin and biometrics to sign into your PC with error 0xd0000225 and error message “Something went wrong, and your PIN isn’t available”. You should be able to re-create your PIN by clicking “Set up my PIN”.
We’re investigating reports that some Insiders are still experiencing rollbacks (with error code 0xc190010) when attempting to install the latest Canary builds.
[NEW] We’re investigating reports that accent colored window borders are not displaying when enabled, and shadows aren’t displaying when enabled.
[NEW] We’re investigating reports that people are seeing window launching (and other) animations even though the setting to show animations is turned off.
[Desktop]
We’re working on the fix for an issue where your desktop background may not show correctly sometimes with multiple monitors (showing big black areas).
[Narrator]
[ADDED 11/22] Narrator is crashing on some builds with Natural voices like Jenny or Aria. We suggest you switch to a non-natural voice like David, Mark, etc. from Narrator settings page and restart your PC to continue using Narrator.
Hi all, last Wednesday Microsoft released Windows 11 Insider Preview Build 27749 to the Canary Channel.
There are also ISOs for this build – they can be > downloaded here <.
The issue where RDP connections to published apps are terminated on connection is fixed, however, connecting to a secondary target crashes mstsc.exe (Feedback Hub: https://aka.ms/AAthazt)
Changes and Improvements
[Narrator]
We have added a new shortcut “Narrator key + control + X” to copy what Narrator last spoke to clipboard. It follows the pattern of using “Narrator key + X” which repeats the last spoken phrase out loud and is a good way to memorize similar shortcuts. You can use these shortcuts to review and copy what Narrator spoke, useful in cases you want to quickly copy some content or descriptions or codes/numbers for use.
Narrator will now auto-read contents of a mail in the new Outlook app similar to behavior in Outlook classic.
Fixes
[File Explorer]
Fixed an issue which was causing the items in the navigation pane to become very spread out (with unexpected padding between each item) for some people.
Fixed an underlying issue which was causing RAW images taken in portrait mode to unexpectedly display in landscape mode thumbnails.
[Taskbar & System Tray]
Made a change so you will now see a search box if the taskbar auto-hides when the setting for search on the taskbar is set to “Search box” (rather than an icon).
[Input]
Updated the mouse option “Show location of pointer when I press the CTRL key”, so that the circles displayed are now DPI-aware, and aren’t really small on high DPI monitors.
[Narrator]
We have addressed a performance issue where Narrator would slow down after 15 minutes of continuous use with a single application. If you continue to experience any performance delays, do report using Feedback Hub.
Fixed an issue where Narrator would add an additional announcement “contains style” whenever its focus is on text that has styling attributes such as bullets, numbers across applications such as Microsoft Edge, Teams, Outlook, etc.
Fixed an issue where few dialogs in Narrator were not adopting the 200% text scaling setting in Windows.
[Task Manager]
Fixed an issue causing Task Manager to show a 0 count for apps and processes.
[Audio]
Fixed an underlying issue that could lead to the audio on certain audio devices unexpectedly going to 100% on boot or after sleep.
Fixed a blank entry in Settings > Privacy, which was crashing Settings if you clicked it.
[Other]
Mitigated an issue resulting in Git not working for Insiders with Arm PCs in the previous flight.
Fixed an issue causing some insiders to see a bugcheck with KERNEL_MODE_HEAP_CORRUPTION in the previous flight.
Fixed an underlying issue which could potentially lead to not being able to join a domain.
Fixed an issue where DirectAccess wasn’t working and might stay stuck in a connecting state.
Known issues
[General]
[IMPORTANT NOTE FOR COPILOT+ PCs] If you are joining the Canary Channel on a new Copilot+ PC from the Dev Channel, Release Preview Channel or retail, you will lose Windows Hello pin and biometrics to sign into your PC with error 0xd0000225 and error message “Something went wrong, and your PIN isn’t available”. You should be able to re-create your PIN by clicking “Set up my PIN”.
We’re investigating reports that some Insiders are still experiencing rollbacks (with error code 0xc190010) when attempting to install the latest Canary builds.
[NEW] We’re working on the fix for an underlying issue causing some apps used for remoting into other PCs to crash in the latest Canary builds.
[NEW] This build has an issue with applying policy for the Digital Markets Act in EEA regions.
[Desktop]
We’re working on the fix for an issue where your desktop background may not show correctly sometimes with multiple monitors (showing big black areas).
As we advance into an era where cybersecurity threats are becoming increasingly sophisticated, it’s imperative to bolster our defenses to ensure the safety and integrity of our digital environments. One pivotal aspect of this defense is the encryption types used by the Kerberos protocol within an Active Directory (AD) domain. With the release of Windows 11 24H2, enabling higher encryption types for Kerberos isn’t just an option—it’s a necessity. Here’s why and how to make this crucial update.
Understanding Kerberos and Its Role
Kerberos is a network authentication protocol designed to provide strong authentication for client-server applications by using secret-key cryptography. It’s a cornerstone of security within AD environments, ensuring that data exchanged over the network is secure from unauthorized access and tampering.
The Evolution of Encryption Standards
Historically, older encryption standards like DES (Data Encryption Standard) were used within Kerberos. However, as computational power and techniques have advanced, these older standards have become vulnerable to attacks. The adoption of stronger encryption types, such as AES (Advanced Encryption Standard), is critical to maintaining a robust security posture.
Why Higher Encryption Types Matter
Enhanced Security: Higher encryption types offer stronger protection against brute-force attacks, eavesdropping, and other forms of cyber threats. By enabling AES encryption, you significantly reduce the risk of unauthorized access to sensitive data.
Compliance Requirements: Many regulatory standards and industry best practices mandate the use of strong encryption to protect sensitive information. Upgrading to higher encryption types ensures compliance with these regulations.
Future-Proofing: As new vulnerabilities are discovered and exploited, staying ahead with the latest encryption standards ensures that your network remains resilient against emerging threats.
Implementing Higher Encryption Types in Windows 11 24H2
To enable higher encryption types for Kerberos in your AD domain with Windows 11 24H2, follow these steps:
Update Group Policy: Access the Group Policy Management Console (GPMC) on your domain controller. Navigate to Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options. Look for the policy named “Network security: Configure encryption types allowed for Kerberos” and enable it.
Specify Encryption Types: In the policy settings, specify the encryption types you want to allow. For maximum security, select AES256_HMAC_SHA1 and AES128_HMAC_SHA1.
Update Domain Controllers: Ensure that all domain controllers in your environment are updated to Windows Server versions that support the selected encryption types.
Test and Monitor: After enabling higher encryption types, thoroughly test the changes to ensure compatibility with your existing applications and services. Monitor the environment for any authentication issues and address them promptly.
Conclusion
Enabling higher encryption types for Kerberos in your Active Directory domain with Windows 11 24H2 is a crucial step towards fortifying your network security. By adopting stronger encryption standards, you protect your organization against evolving threats and ensure compliance with security regulations. Embrace these changes to future-proof your environment and safeguard your digital assets.
Secure your realm—empower Kerberos with the encryption it deserves.
In some cases older AD networks run into issues when clients get updated or deployed with 24H2, mostly turns out to be caused by an old gpo setting forcing only old kerberos authentication methods to be supported on the network that no longer are part of 24H2, another good reason to get those methods updated asap.
To log who is using older Kerberos encryption types, you can follow these steps:
Enable Auditing: Ensure that auditing for Kerberos Service Ticket Operations is enabled on your Domain Controllers. This can be done via Group Policy:
Open the Group Policy Management Console (gpmc.msc). Navigate to Computer Configuration > Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Account Logon. Enable the Audit Kerberos Authentication Service policy and configure it to log both success and failure events.
Use PowerShell: You can use a PowerShell script to filter and identify events related to older encryption types. For example, to detect RC4 encryption, you can use the following script:
Review Logs: After running the script, review the output to identify users and services that are using older encryption types like RC4, make sure they are ready to work with higher encryption before diabling the old ones.
Hi all, last Friday Microsoft released Windows 11 Insider Preview Build 26120.2222 (KB5046746) to the Dev Channel.
Some quick tweaks & fixes in this build, one of my devices on this channel seemed to go non-responsive after the upgrade, no mouse or thouch imput resonse after logon, turned out to be a temporary issue, if you run into this give it a few minutes, after that all turned out fine.
Happy Upgrades!
Changes and Improvements gradually being rolled out to the Dev Channel with toggle on*
[General]
If you hold Shift and CTRL when clicking on a jump list item in Start menu or taskbar, this will now launch that item as admin, just like if you were to do Shift + CTRL and click the app icon itself. For example, if you right-click on Windows Terminal, and hold Shift and CTRL when you click PowerShell, it would open a PowerShell window as admin.
Fixes gradually being rolled out to the Dev Channel with toggle on*
[File Explorer]
Fixed an issue causing the See More (“…”) menu to open in the wrong direction (and potentially display offscreen as a result).
[Input]
Fixed an underlying issue which could cause the mouse to unlock from a game window on a system with multiple monitors after opening and closing Game Bar, so you couldn’t use it within the game.
[Windowing]
Fixed a recent issue causing windows to potentially unexpectedly move around after waking from sleep if you had multiple monitors.
[Other]
Fixed an underlying issue which could lead to Registry Editor going unresponsive if you pressed Alt after clicking on the license information in the About section.
Known issues
[Narrator]
[NEW] [IMPORTANT] There is an issue in this build which will cause Narrator to crash on launch if you use one of the natural voices (like Jenny). If you are a Narrator user, we recommend pausing updates from Settings under Windows Update > “Pause Updates”. If you do install this update and encounter this issue, switching to another voice, like Microsoft David, in Settings under Accessibility > Narrator will stop the crashes. As Narrator is crashing, you will need to use a secondary screen reader, or have someone assist in order to do this.
[Desktop]
We’re working on the fix for an issue where your desktop background may not show correctly sometimes with multiple monitors (showing big black areas).