Microsoft released cumulative update KB5087420 for Windows 11, version 23H2 (2023 Update) as part of the May 2026 Patch Tuesday. The cumulative update package KB5087420 (Build 22631.7079) is intended for Windows 11, version 23H2 (Windows 11 2023 Update) on x64 (amd64) and ARM64 processors for Enterprise and Education editions. This update includes quality improvements; no new system features are introduced.
- Expansion of Secure Boot targeting data. Microsoft expanded the targeting data composition in Windows quality updates, increasing the scope of devices ready to automatically receive new Secure Boot certificates. Certificates are delivered only after sustained signals of successful update installation — ensuring controlled phased rollout ahead of certificate expirations starting June 2026.
- COSA profile update. Country and Operator Settings Asset (COSA) profiles have been updated, improving support for mobile operator settings on compatible devices.
- Support for daylight saving time changes in Egypt. Added support for the 2023 daylight saving time rule changes in the Arab Republic of Egypt.
- Enterprise State Roaming management via Windows Backup for Organizations. Management of the Enterprise State Roaming (ESR) feature is now possible through Windows Backup for Organizations policies, simplifying device configuration setup and management in organizations. Microsoft transitioned ESR management into Windows Backup for Organizations starting May 2026.
- Microsoft Defender SmartScreen improvement. Microsoft Defender SmartScreen can now send hash values of unsigned files from the shell to improve application reputation checks using modern security models.
- Servicing stack quality improvements (SSU). The update includes servicing stack quality improvements — the component responsible for installing Windows updates.
Known issue: BitLocker. On devices with a non-recommended BitLocker group policy configuration, after the first reboot following the update installation, a BitLocker recovery key may be required. The issue affects a limited set of systems where all conditions are met simultaneously: BitLocker is enabled on the system drive; the Configure TPM platform validation profile for native UEFI firmware configurations group policy is set, and PCR7 is included in the validation profile (or the corresponding registry parameter is manually set). On personal devices not managed by corporate IT, these conditions are unlikely.
Cumulative update 5087420 for PCs installs automatically via Windows Update for Enterprise and Education editions. To check, go to Settings > Windows Update and click Check for updates.
| Feature / Change | Performance Increase / Decrease | Optimization | PC Speed | Gaming Optimization |
|---|---|---|---|---|
| Expansion of Secure Boot targeting data | 🟢 Slight increase (faster certificate delivery) | 🟢 High (phased rollout reduces update risk) | ⚪ No direct impact | ⚪ No impact |
| COSA profile update | ⚪ No impact | 🟢 Medium (better mobile operator settings) | 🟡 Slight improvement (network stability) | 🟡 Low (less connectivity issues) |
| Support for daylight saving time changes in Egypt | ⚪ No impact | 🟢 Low (correct time display) | ⚪ No impact | ⚪ No impact |
| Enterprise State Roaming management via Windows Backup for Organizations | ⚪ No impact | 🟢 Medium (simplified device setup) | ⚪ No impact | ⚪ No impact |
| Microsoft Defender SmartScreen improvement | 🟡 Slight decrease (hash computation overhead) | 🟢 High (better security reputation checks) | ⚪ No direct impact | 🟡 Low (possible minor stutter on file launch) |
| Servicing stack quality improvements (SSU) | 🟢 Slight increase (faster future updates) | 🟢 High (more reliable update installs) | 🟡 Low (less post-update slowdown) | ⚪ No impact |
| Known issue: BitLocker recovery key prompt | 🔴 Temporary decrease (boot delay) | 🔴 Low (only misconfigured systems) | 🔴 Temporary slowdown (recovery screen) | ⚪ No impact |
Find and Change Settings
| Setting | Where to find | How to change |
|---|---|---|
| Secure Boot Targeting Data Expansion |
Settings > Windows Update > Advanced options Computer Configuration > Administrative Templates > Windows Components > Secure Boot |
This expansion is delivered automatically through Windows quality updates. To ensure your device receives new Secure Boot certificates, keep Windows Update enabled and install quality updates regularly. In managed environments, administrators can monitor rollout using Windows Update for Business deployment rings or Intune update policies. No manual user action is required for certificate delivery. |
| COSA Profile Update |
Settings > Network & internet > Cellular Settings > Windows Update > Advanced options > Optional updates |
COSA profile updates are applied automatically with Windows quality updates. To verify mobile operator settings on your device, open Settings > Network & internet > Cellular and check available networks. If issues occur, go to Settings > Windows Update > Advanced options > Optional updates and install any pending driver or COSA-related updates. |
| Daylight Saving Time Changes in Egypt |
Settings > Time & language > Date & time Control Panel > Clock and Region > Date and Time > Change time zone |
Support for Egypt's 2023 daylight saving time rule changes is included automatically. To ensure correct time display, open Settings > Time & language > Date & time and enable "Set time zone automatically" or manually select (UTC+02:00) Cairo. You can also adjust DST settings via Control Panel > Date and Time > Change time zone and check "Automatically adjust clock for Daylight Saving Time". |
| Enterprise State Roaming Management via Windows Backup for Organizations |
Settings > Accounts > Windows Backup Microsoft Intune admin center > Devices > Configuration profiles Group Policy Editor > Computer Configuration > Administrative Templates > Windows Components > Windows Backup |
ESR management has transitioned to Windows Backup for Organizations policies starting May 2026. To manage ESR, open Microsoft Intune admin center > Devices > Configuration profiles and create a new policy for Windows Backup for Organizations. In Group Policy Editor, navigate to Computer Configuration > Administrative Templates > Windows Components > Windows Backup and configure the relevant ESR policies. On user devices, ESR settings can be checked under Settings > Accounts > Windows Backup. |
| Microsoft Defender SmartScreen Improvement |
Settings > Privacy & security > Windows Security > App & browser control Windows Security > App & browser control > Reputation-based protection |
This improvement sends hash values of unsigned files from the shell to enhance application reputation checks. To manage SmartScreen settings, open Settings > Privacy & security > Windows Security > App & browser control. Under Reputation-based protection, you can enable or disable "Check apps and files", "SmartScreen for Microsoft Edge", and other SmartScreen features. This functionality uses modern security models automatically. |
| Servicing Stack Quality Improvements (SSU) |
Settings > Windows Update > Update history Settings > Windows Update > Advanced options > Optional updates |
Servicing stack updates are installed automatically with Windows quality updates. To verify installation, open Settings > Windows Update > Update history and look for "Servicing Stack" entries. If a servicing stack update is offered as an optional update, go to Settings > Windows Update > Advanced options > Optional updates and install it manually. No user configuration is required. |
| BitLocker Recovery Key Issue (Known Issue) |
Settings > Privacy & security > Device encryption Control Panel > System and Security > BitLocker Drive Encryption Group Policy Editor > Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption |
On affected devices with non-recommended BitLocker group policy configuration, a BitLocker recovery key may be required after the first reboot following update installation. To avoid this issue, ensure the "Configure TPM platform validation profile for native UEFI firmware configurations" group policy is not set to include PCR7 in the validation profile. If a recovery key is required, retrieve it from your Microsoft account, Azure AD, or organization administrator. To change the validation profile, open Group Policy Editor > Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives and modify the TPM validation profile settings. |
Official announcement on the Microsoft website.
The last 10 Windows updates:
| Update | Build | Version | Windows | Channel | Date |
|---|---|---|---|---|---|
| KB5121132 | 28120.2760 | 26H1 | Windows 11 | Experimental | 2026-08-21 |
| KB5124040 | 26220.9223 | 25H2 | Windows 11 | Beta | 2026-08-21 |
| KB5124042 | 26340.9233 | 26H2 | Windows 11 | Experimental | 2026-08-21 |
| KB5121106 | 28020.2731 | 26H1 | Windows 11 | Beta | 2026-08-17 |
| KB5121109 | 28120.2738 | 26H1 | Windows 11 | Experimental | 2026-08-17 |
| KB5124036 | 26220.9202 | 25H2 | Windows 11 | Beta | 2026-08-17 |
| KB5124038 | 26340.9212 | 26H2 | Windows 11 | Experimental | 2026-08-17 |
| KB5120996 | 28000.2796 | 26H1 | Windows 11 | Preview | 2026-08-14 |
| KB5120998 | 26200.9267 | 25H2 | Windows 11 | Preview | 2026-08-14 |
| KB5120240 | 22631.7517 | 23H2 | Windows 11 | Stable | 2026-08-11 |