Windows IT Pro Blog:
From device recovery and unattended remote support to post-quantum cryptography readiness and Windows 365 improvements, August delivered a broad set of updates for IT admins. In this edition of Windows news you can use, explore new recovery and management tools, security enhancements designed to strengthen protection by default, Windows Server updates, AI-related improvements in Windows, and upcoming lifecycle milestones that may require action in your environment.
New in Windows update and device management
- [RECOVERY] – From automated, cloud-based fixes to full device rebuilds, a new Windows device recovery guide helps you find the right recovery tools to help you address everything from mass-scale outages to isolated issues.
- [BACKUP] – New PowerShell scripts available on GitHuband the PowerShell Gallery offer a simpler way to manage Windows settings backup and restore data using Microsoft Graph APIs.
- [AUTOPILOT] – Windows Autopilot device preparation now supports device association, making it possible to bind a physical Windows 11 device to your organization before enrollment. Associated devices are automatically marked as corporate-owned and can receive device-targeted policy assignments, device naming, and additional out-of-box experience (OOBE) customizations.
- [INTUNE] – Remote Help unattended support with remote sign-in a new Intune capability that lets helpdesk staff remotely access physical Windows devices by signing in with credentials they have access to, without requiring the user to grant access or even be logged in. Explore Remote Help on Windows for details on prerequisites and setup guidance.
- [UPDATE DELIVERY] – If you've ever had to troubleshoot a content delivery issue with Delivery Optimization or Microsoft Connected Cache, the Delivery Optimization Troubleshooter can quickly help you identify why things aren't working as expected.
- [W365] [AGENTS] – Currently in preview, Windows 365 for Agents Cloud PC agent pools now support linking either a Microsoft Entra group or a Windows Autopilot device preparation profile. Target security and compliance policies, deploy required applications, and maintain consistent configurations across Windows 365 for Agents using existing Intune workflows. See Cloud PC agent pool device grouping and preparation for more details.
- [W365] [AUTOPILOT] – You can now assign Device Preparation policies to Windows 365 Reserve provisioning policies so required applications and configurations are applied during provisioning before users connect to their Cloud PCs. In addition, Windows Autopilot device preparation is now generally available for Windows 365 Enterprise and Windows 365 Flex in dedicated mode in Government environments.
- [W365] [RESERVE] – Windows 365 Reserve now supports bulk provisioning and deprovisioning of up to 1,000 Cloud PCs in a single request.
- [W365] [CONNECTIVITY] – Windows 365 has started the rollout of Modern Auto-Reconnect, a new connection recovery experience designed to improve resiliency during temporary network interruptions.
- [ARM] – New signals show that momentum for Windows on Arm is accelerating. Explore the latest device announcements and trends in the expanding catalog of more than 7,000 optimized apps across key workloads.
New in Windows security
- [VBS] [KERNEL PROTECTION] – Beginning in October 2026, Microsoft will expand memory integrity protection across eligible devices, helping you benefit from stronger kernel-level protection from sophisticated attacks by default with little or no additional configuration.
- [PQC] [CODE-SIGNING] – Microsoft has published guidance to help software publishers, developers, and IT administrators prepare for the next generation of Windows code signing. Changes coming in the next few months will strengthen software supply chain security through modern cryptographic protections.
- [W365] [AGENTS] – A dedicated security baseline for Windows 365 for Agents is now generally available in Microsoft Intune. Apply Microsoft-recommended security configurations to agent Cloud PCs, helping establish a consistent security posture and protect agent workloads from common security risks.
New in AI
- [TASK MANAGER] – Windows Task Manager now provides deeper visibility into AI workloads running on a device. Some newer devices will now see neural processing unit (NPU) or graphics processing unit (GPU) neural engine activity familiar CPU and standard GPU activity on the Processes tab, with utilization on the Performance tab.
New in Windows Server
For the latest features and improvements for Windows Server, see the Windows Server 2025 release notes and Windows Server 2022 release notes.- [HARDENING] – The October 2026 monthly security updates for Windows Server will begin Enforcement mode for Active Directory Federation Service (AD FS) Distributed Key Manager (DKM) container ACL hardening, a change designed to address the elevation of privilege vulnerability documented in CVE-2026-56155. Organizations using AD FS should use the remaining Audit mode period to review DKM container permissions and address compatibility issues before enforcement begins.
- [COMMUNITY] – Interested in staying informed about the latest in Azure Arc and Windows Server management, influencing product direction, and expanding your professional network? Join the Azure Arc Customer & Engineering Forum.
- [PQC] – Windows Server now supports hybrid post-quantum cryptography (PQC) key exchange in Transport Layer Security (TLS) 1.3 as well as composite cryptographic formats that combine traditional and post-quantum algorithms in a single signature or key. Looking for guidance on how to plan for new cryptosystems and prepare for future cryptographic changes? Watch Transitioning to post-quantum cryptography.
New in productivity and collaboration
Install the August 2026 security update for Windows 11, versions 25H2 and 24H2 to get these and other capabilities, which will be rolling out gradually:- [FILE EXPLORER] – File sizes in the Details view now display using appropriate units (KB, MB, GB) instead of KB-only. We hope it helps you understand them easier at a glance.
- [ACCESSIBILITY] – Voice Access now features Voice Isolation. As such, it recognizes your voice better by reducing interference from other speakers and background noise. Voice Access also now supports Korean.
- [SECURITY] – Use Administrator protection to help reduce the risk of elevation-of-privilege attacks by using profile separation and just-in-time administrative privileges. This feature is off by default and can be enabled through Microsoft Intune (OMA-URI) or Group Policy.
- [TASKBAR] – Choose whether the taskbar appears at the bottom, top, left, or right side of your screen. You can also try a smaller taskbar option to help maximize screen space on smaller devices.
- [SEARCH] – Windows Search home has been simplified to reduce visual clutter and make it easier to get back to recent searches quickly. A new setting lets you choose whether web and Microsoft Store suggestions appear alongside local results. And, Windows now automatically indexes your most used folders to make those files appear in subsequent search results.
- [START] – The Start menu now lets you select a small or large menu size; independently show or hide the Pinned, Recommended, and All sections; and hide your name and profile picture.
- [SHARE] – Users signed in with a work or school account can now discover and install relevant apps directly from the share window.
Lifecycle reminders
- [W11] [24H2] – On October 13, 2026, Windows 11, version 24H2 Home and Pro editions will reach end of updates. After this date, devices running these editions will no longer receive monthly security and non-security preview updates containing protections from the latest security threats. Enterprise and Education editions remain supported until October 12, 2027.
- [W10] [LTSB] [LTSC]- On October 13, 2026, Windows 10 Enterprise LTSB 2016 and Windows 10 IoT Enterprise LTSB 2016 will reach the end of extended support. Windows 10 Enterprise LTSC 2021 will reach end of support (EOS) on January 12, 2027. In both cases, we recommend updating to the latest LTSC release, Windows 11 Enterprise LTSC 2024. If you need additional time to complete the transition, explore options and Extended Security Update (ESU) offerings for Windows 10 Enterprise LTSB 2016and Windows 10 Enterprise LTSC 2021.
- [SERVER] [2022] – On October 13, 2026, Windows Server 2022 will reach end of mainstream support. After this date, Windows Server 2022 will transition to extended support, which includes security updates at no additional cost. These devices will continue to receive monthly security updates through October 14, 2031. For detailed information, see the Windows Server 2022 lifecyclepage.
- [WMIC] – The Windows Management Instrumentation command-line (WMIC) utility has been removed from Windows 11, version 24H2 and later. WMI itself remains supported and unaffected. If you have applications, scripts, deployment tools, or monitoring systems that use WMIC, migrate them to PowerShell or a supported WMI programming interface.
Additional resources
Looking for the latest news and previews for Windows, Copilot, Copilot+ PCs, the Windows and Windows Server Insider Programs? Find out this and more through the following resources:- Windows Roadmap for new Windows features – filter by platform, version, status, and channel or search by feature name
- Microsoft 365 Copilot release notes for latest features and improvements
- Windows Insider Blog for what's available in the Beta and Experimental channels
- Windows Server Insider for feature preview opportunities
- Understanding update history for Windows Insider preview features, fixes, and changes to learn about the types of updates for Windows Insiders
Source:
Windows news you can use: August 2026 - Windows IT Pro Blog
Discover August updates for Windows security, recovery, Windows Autopilot, Windows 365, AI, and lifecycle planning.









