KB5087420


Microsoft released cumulative update KB5087420 for Windows 11, version 23H2 (2023 Update) as part of the May 2026 Patch Tuesday. The cumulative update package KB5087420 (Build 22631.7079) is intended for Windows 11, version 23H2 (Windows 11 2023 Update) on x64 (amd64) and ARM64 processors for Enterprise and Education editions. This update includes quality improvements; no new system features are introduced.

Known issue: BitLocker. On devices with a non-recommended BitLocker group policy configuration, after the first reboot following the update installation, a BitLocker recovery key may be required. The issue affects a limited set of systems where all conditions are met simultaneously: BitLocker is enabled on the system drive; the Configure TPM platform validation profile for native UEFI firmware configurations group policy is set, and PCR7 is included in the validation profile (or the corresponding registry parameter is manually set). On personal devices not managed by corporate IT, these conditions are unlikely.

Cumulative update 5087420 for PCs installs automatically via Windows Update for Enterprise and Education editions. To check, go to Settings > Windows Update and click Check for updates.

Feature / Change Performance Increase / Decrease Optimization PC Speed Gaming Optimization
Expansion of Secure Boot targeting data 🟢 Slight increase (faster certificate delivery) 🟢 High (phased rollout reduces update risk) ⚪ No direct impact ⚪ No impact
COSA profile update ⚪ No impact 🟢 Medium (better mobile operator settings) 🟡 Slight improvement (network stability) 🟡 Low (less connectivity issues)
Support for daylight saving time changes in Egypt ⚪ No impact 🟢 Low (correct time display) ⚪ No impact ⚪ No impact
Enterprise State Roaming management via Windows Backup for Organizations ⚪ No impact 🟢 Medium (simplified device setup) ⚪ No impact ⚪ No impact
Microsoft Defender SmartScreen improvement 🟡 Slight decrease (hash computation overhead) 🟢 High (better security reputation checks) ⚪ No direct impact 🟡 Low (possible minor stutter on file launch)
Servicing stack quality improvements (SSU) 🟢 Slight increase (faster future updates) 🟢 High (more reliable update installs) 🟡 Low (less post-update slowdown) ⚪ No impact
Known issue: BitLocker recovery key prompt 🔴 Temporary decrease (boot delay) 🔴 Low (only misconfigured systems) 🔴 Temporary slowdown (recovery screen) ⚪ No impact

Find and Change Settings

Setting Where to find How to change
Secure Boot Targeting Data Expansion Settings > Windows Update > Advanced options
Computer Configuration > Administrative Templates > Windows Components > Secure Boot
This expansion is delivered automatically through Windows quality updates. To ensure your device receives new Secure Boot certificates, keep Windows Update enabled and install quality updates regularly. In managed environments, administrators can monitor rollout using Windows Update for Business deployment rings or Intune update policies. No manual user action is required for certificate delivery.
COSA Profile Update Settings > Network & internet > Cellular
Settings > Windows Update > Advanced options > Optional updates
COSA profile updates are applied automatically with Windows quality updates. To verify mobile operator settings on your device, open Settings > Network & internet > Cellular and check available networks. If issues occur, go to Settings > Windows Update > Advanced options > Optional updates and install any pending driver or COSA-related updates.
Daylight Saving Time Changes in Egypt Settings > Time & language > Date & time
Control Panel > Clock and Region > Date and Time > Change time zone
Support for Egypt's 2023 daylight saving time rule changes is included automatically. To ensure correct time display, open Settings > Time & language > Date & time and enable "Set time zone automatically" or manually select (UTC+02:00) Cairo. You can also adjust DST settings via Control Panel > Date and Time > Change time zone and check "Automatically adjust clock for Daylight Saving Time".
Enterprise State Roaming Management via Windows Backup for Organizations Settings > Accounts > Windows Backup
Microsoft Intune admin center > Devices > Configuration profiles
Group Policy Editor > Computer Configuration > Administrative Templates > Windows Components > Windows Backup
ESR management has transitioned to Windows Backup for Organizations policies starting May 2026. To manage ESR, open Microsoft Intune admin center > Devices > Configuration profiles and create a new policy for Windows Backup for Organizations. In Group Policy Editor, navigate to Computer Configuration > Administrative Templates > Windows Components > Windows Backup and configure the relevant ESR policies. On user devices, ESR settings can be checked under Settings > Accounts > Windows Backup.
Microsoft Defender SmartScreen Improvement Settings > Privacy & security > Windows Security > App & browser control
Windows Security > App & browser control > Reputation-based protection
This improvement sends hash values of unsigned files from the shell to enhance application reputation checks. To manage SmartScreen settings, open Settings > Privacy & security > Windows Security > App & browser control. Under Reputation-based protection, you can enable or disable "Check apps and files", "SmartScreen for Microsoft Edge", and other SmartScreen features. This functionality uses modern security models automatically.
Servicing Stack Quality Improvements (SSU) Settings > Windows Update > Update history
Settings > Windows Update > Advanced options > Optional updates
Servicing stack updates are installed automatically with Windows quality updates. To verify installation, open Settings > Windows Update > Update history and look for "Servicing Stack" entries. If a servicing stack update is offered as an optional update, go to Settings > Windows Update > Advanced options > Optional updates and install it manually. No user configuration is required.
BitLocker Recovery Key Issue (Known Issue) Settings > Privacy & security > Device encryption
Control Panel > System and Security > BitLocker Drive Encryption
Group Policy Editor > Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption
On affected devices with non-recommended BitLocker group policy configuration, a BitLocker recovery key may be required after the first reboot following update installation. To avoid this issue, ensure the "Configure TPM platform validation profile for native UEFI firmware configurations" group policy is not set to include PCR7 in the validation profile. If a recovery key is required, retrieve it from your Microsoft account, Azure AD, or organization administrator. To change the validation profile, open Group Policy Editor > Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives and modify the TPM validation profile settings.

Official announcement on the Microsoft website.

The last 10 Windows updates:

Update Build Version Windows Channel Date
KB5121132 28120.2760 26H1 Windows 11 Experimental 2026-08-21
KB5124040 26220.9223 25H2 Windows 11 Beta 2026-08-21
KB5124042 26340.9233 26H2 Windows 11 Experimental 2026-08-21
KB5121106 28020.2731 26H1 Windows 11 Beta 2026-08-17
KB5121109 28120.2738 26H1 Windows 11 Experimental 2026-08-17
KB5124036 26220.9202 25H2 Windows 11 Beta 2026-08-17
KB5124038 26340.9212 26H2 Windows 11 Experimental 2026-08-17
KB5120996 28000.2796 26H1 Windows 11 Preview 2026-08-14
KB5120998 26200.9267 25H2 Windows 11 Preview 2026-08-14
KB5120240 22631.7517 23H2 Windows 11 Stable 2026-08-11