Action1 5 Blog 5 Microsoft Windows Emergency / Out-of-Band Update Coverage

Microsoft Windows Emergency / Out-of-Band Update Coverage

Published:
August 22, 2026
Last Updated:
August 26, 2026

By Peter Barnett

First 200 endpoints free, no feature limits.

No credit card required, full access to all features.

TL;DR

  • Windows out-of-band (OOB) updates are emergency updates released outside Microsoft’s normal monthly update schedule when an issue cannot wait for the next Patch Tuesday.
  • OOB updates are typically cumulative, meaning they include the fixes from the update they replace as well as the new emergency fix, so administrators generally don’t need to install the superseded update first.
  • In August 2025, Microsoft issued OOB updates after security updates broke Windows recovery and reset functionality, including Reset this PC, Windows Update recovery, and RemoteWipe scenarios.
  • In January 2026, Microsoft released emergency updates after Patch Tuesday introduced shutdown, hibernation, and Remote Desktop problems. KB5077797 addressed both issues on affected Windows 11 23H2 systems, while KB5077744 addressed Remote Desktop issues on Windows 11 24H2 and 25H2.
  • OOB updates can be obtained through Windows Update, Windows Update for Business, or the Microsoft Update Catalog, depending on the update and how the environment is managed. Organizations using Intune may also be able to expedite applicable quality updates.
  • OOB updates and Known Issue Rollbacks (KIRs) aren’t the same thing. An OOB release provides a new update package, while a KIR can disable a problematic non-security change without requiring another cumulative update.
  • Organizations don’t necessarily have to deploy an emergency update immediately. Group Policy, Windows Update for Business policies, and applicable registry settings can provide time for compatibility testing before deployment.
  • Deferring security updates indefinitely is not a safe alternative. A better strategy is staged deployment: validate the emergency fix on test devices, monitor results, and then expand deployment to production endpoints.
  • Windows Release Health and the Windows message center are key sources for determining whether an OOB update applies to your environment and what action Microsoft recommends.
  • For managed fleets, Action1 can centralize OOB update deployment by identifying affected endpoints, deploying specific KBs, testing updates through Update Rings, controlling reboots, and reporting which devices successfully installed the emergency fix.

Microsoft ships updates on two tracks:

  • Routine updates follow a fixed calendar: security updates on the second Tuesday of the month (Patch Tuesday), plus an optional non-security preview update in the third or fourth week.
  • Out-of-band (OOB) updates, also called emergency updates, are shipped whenever a routine update introduces a serious bug that cannot wait for next month’s Patch Tuesday. Recent examples include:
  • The August 2025 security updates that broke Windows recovery and reset tools on Windows 10 and Windows 11.
  • The January 2026 security updates that prevented some Windows 10 and Windows 11 devices from shutting down or hibernating properly.
  • The July 2026 security update that caused performance, overheating, and unexpected shutdown issues on certain Windows 11 devices

OOB updates are cumulative, which means that they include everything from the update they’re patching plus the fix. Microsoft maintains a public history of these releases.

The August 2025 incident and fix: Windows recovery and reset failures

The issue

After installing the August 2025 Windows security updates, some users found that the “Reset my PC” option and the “Fix problems using Windows Update” recovery tool did not work when they attempted to reinstall Windows while keeping their personal files. IT administrators using the “RemoteWipe” Configuration Service Provider (CSP) to remotely reset devices encountered the same problem.

The fix

Microsoft acknowledged the issue on August 18 and released OOB updates the next day, August 19, 2025.

KBs that Caused the Issues Affected Windows Versions KBs that Resolved the Issues
KB5063875 Windows 11, versions 23H2 and 22H2 KB5066189
KB5063709 Windows 10 22H2, Windows 10 Enterprise LTSC 2021, and Windows 10 IoT Enterprise LTSC 2021 KB5066188
KB5063877 Windows 10 Enterprise LTSC 2019 and Windows 10 IoT Enterprise LTSC 2019 KB5066187

Each fix is a cumulative out-of-band update, meaning no prior updates need to be installed first. Microsoft recommended that anyone who had not yet installed the August 2025 security update install this OOB version instead.

How to apply the fix

You can install the updates in one of three ways:

  • Windows Update: Go to Settings > Windows Update > Check for updates. OOB fixes are offered as optional updates, so you’ll need to turn on “Get the latest updates as soon as they’re available” to receive them automatically.
  • Windows Update for Business: Deploy the update through your organization’s Windows Update for Business policies.
  • Microsoft Update Catalog: Download the standalone .msu package and install it manually.

Additional information

Microsoft also resolved two other update-related issues during the same update cycle:

  • A Known Issue Rollback (KIR) for a separate problem that prevented the Windows Update Standalone Installer (WUSA) from installing updates from network shares.
  • A fix for the 0x80240069 error, which affected Windows 11 version 24H2 devices managed through Windows Server Update Services (WSUS).

KIRs disable a problematic non-security change introduced by a recent update, usually without requiring a new cumulative update. OOB updates, by contrast, deliver a new update package that has to be installed.

January 2026: Windows 11 shutdown and remote desktop issues

The January 2026 Patch Tuesday release caused two unrelated but disruptive issues, and Microsoft had to issue OOB updates just a few days later.

Root cause

Microsoft’s January 13, 2026 Patch Tuesday update introduced a regression that affected Windows 11 version 23H2 devices with Secure Launch enabled, a firmware-based security feature that verifies system integrity during startup. After installing that update, affected PCs would restart instead of shutting down or entering hibernation when users selected Shut Down or Hibernate.

The same monthly update cycle also caused a separate Remote Desktop issue that prevented some users from signing in to Windows 10 and Windows 11 devices because the credentials prompt failed to appear.

Affected Windows versions / editions

The shutdown issue affected a much smaller set of devices than the Remote Desktop issue:

Issue Affected Windows versions / editions
Shutdown/hibernate failure

Windows 11, version 23H2, on devices with Secure Launch and Virtual Secure Mode enabled

This configuration is common on Enterprise and IoT images and less common on consumer PCs

Remote Desktop sign-in failure Windows 11 versions 23H2, 24H2, and 25H2, plus supported Windows 10 versions

To check if Secure Launch is enabled for your device:

  • Open Start, type msinfo32, and press Enter.
  • Under System Summary, look for the Secure Launch entry.
  • If the entry is missing or shows as off, the shutdown/hibernation bug doesn’t apply to you. The Remote Desktop issue, however, may still apply.

KB number / update identifier for the fix

Microsoft released two OOB updates on January 17, 2026, just four days after Patch Tuesday, to resolve the issues. Both are cumulative, so you don’t need to install January’s original security update first.

KB Number Applies To Notes
KB5077797 Windows 11, version 23H2 (OS Build 22631.6494) Fixes both the shutdown/hibernate regression and the Remote Desktop sign-in issues.
KB5077744 Windows 11 versions 24H2 and 25H2 (OS Builds 26100.7627 and 26200.7627) Fixes the Remote Desktop sign-in issue only. The shutdown bug doesn’t affect these versions.

Microsoft incorporated these emergency fixes into the regular February 10, 2026 security update (KB5075941). Any device that installs that update or a later cumulative update gets the fixes and doesn’t need the January OOB package.

How and where to get the fix

You have four ways to get the fixes:

  • Windows Update: Go to Settings > Windows Update > Check for updates. OOB fixes are offered as optional updates, so you’ll need to turn on “Get the latest updates as soon as they’re available” to receive them automatically.
  • Windows Update for Business: IT administrators can deploy the updates through their existing Windows Update for Business deployment and deferral policies.
  • Microsoft Update Catalog: Download the .msu package and deploy it manually. This method is useful for offline machines or importing updates into WSUS.
  • Intune expedited deployment: Organizations managing devices with Microsoft Intune can use expedited quality updates to push an OOB update outside their normal deployment rings. This lets administrators get the fix onto affected Enterprise and IoT devices without waiting for the standard rollout.

Workarounds to defer or pause emergency updates

Even after Microsoft ships a fix, organizations prefer to complete their own compatibility testing before installing it. Here are some common ways to temporarily defer or pause an OOB update.

Group Policy (Pro, Enterprise, and Education)

  1. Open Local Group Policy Editor (gpedit.msc) and go to Computer Configuration > Administrative Templates > Windows Components > Windows Update > Windows Update for Business.
  2. Enable “Select when Quality Updates are received” and set a deferral of up to 30 days.
    If you need a complete stop instead of a rolling deferral, use the ‘Pause quality updates’ policy in the same node. This pauses quality updates for up to 35 days.

On newer versions of Windows 11, Microsoft recommends that you manage update deployment through Windows Update for Business policies (such as Intune) instead of relying on the older “Select when Quality Updates are received” Group Policy.

Registry (works on any edition, including Home)

Windows Home doesn’t include the Local Group Policy Editor, but it uses the same registry values behind the scenes.

Under HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate, create these DWORD values:

Value Data
DeferQualityUpdates 1
DeferQualityUpdatesPeriodInDays 0–30

This enables Windows Home edition users to defer updates through the registry instead of Group Policy.

Things to watch for

Feature updates may reset your deferral

Some feature updates and OS upgrades remove or reset these registry values during installation. If updates begin installing sooner than expected after a feature update, verify that these registry values are still present before troubleshooting other causes.

WSUS and deferral policies can conflict

Windows Update for Business deferral policies can conflict with WSUS because of a behavior known as Dual Scan. In some configurations, a device may check both WSUS and Windows Update, causing deferral policies to be bypassed. To fix the problem, disable Dual Scan via Group Policy.

Community sentiment on Microsoft’s update QA / reliability

If your feed is full of complaints about how often Microsoft ships emergency fixes lately, you’re not imagining it. OOB updates for shutdown bugs, sign-in failures, and recovery tool breakage have all landed within the past year, and each one generates a round of frustration from users and IT admins who feel like Patch Tuesday keeps creating the problems it’s supposed to prevent.

A recurring theme in discussions links this pattern to Microsoft’s growing use of AI-assisted coding and reduced manual quality testing. Be aware that this is opinion, not an established case.

Another common sentiment is growing concern over Windows reliability. Some users say repeated update problems have led them to switch to macOS or Linux, while others describe adopting a more cautious deployment strategy: delaying updates until early issues have been identified by the broader community.

Despite all this, avoiding updates is not the safer option. By skipping security patches, you trade one risk for a bigger one. What you can do is, track these releases, roll them out in stages, monitor release health dashboards, and keep a deferral policy ready to hold back a problem update.

Recent emergency/OOB updates — a running reference log

Microsoft’s Windows Release Health and Windows message center document every Windows update announcement, including routine cumulative updates, hotpatches, OOB releases, and servicing notices. These updates appear in a chronological feed, so it’s not easy to spot the emergency fixes. The following table lists some recent Windows OOB releases for quick reference.

Release Date What it fixed KB Update Affected editions
Jul 18, 2026 Performance, power, and shutdown issues on some Dell devices caused by a conflict with the Intel Innovation Platform Framework driver. KB5121767 Windows 11 25H2, 24H2
KB5121768 (Hotpatch) Windows 11 Enterprise LTSC 2024
Apr 19, 2026 Installation failures and repeated domain controller restarts introduced by the April 2026 security updates. KB5091157 and related version-specific KBs Windows Server 2016, 2019, 2022, and 2025
Mar 21, 2026 Microsoft account sign-in failures showing a false “no internet” error, introduced by the March 2026 security update. KB5085516 Windows 11 25H2 and 24H2
Mar 16, 2026 A bug that prevented some Bluetooth devices from appearing in Settings or Quick Settings. KB5084897 (Hotpatch) Windows 11 Enterprise 24H2 and 25H2 (Hotpatch)
Mar 13, 2026 Remote Access Service (RRAS) vulnerability that could allow remote code execution KB5084597 (Hotpatch) Windows 11 Enterprise 24H2 and 25H2 (Hotpatch)
Jan 17, 2026 Shutdown/hibernate failures and Remote Desktop sign-in failures introduced by the January security updates. KB5077797 Windows 11 23H2 (both issues)
KB5077744 Windows 11 24H2, 25H2 (sign-in only)

When an OUB update is released, Microsoft’s Windows message center and Windows Release Health pages are the best places to check whether your devices are affected and whether any action is required.

Related Windows update-program topics

Secure Boot certificate expiration, Kerberos RC4 hardening, and Windows end-of-support dates are all important Microsoft announcements, but they’re planned servicing changes rather than emergency fixes. They deserve attention, especially if you manage a fleet, but it’s better to track them as part of your Windows servicing strategy instead of your emergency update workflow.

How Action1 Helps Deploy Emergency Windows Updates?

When Microsoft releases an out-of-band update, the challenge for IT teams is not simply installing the KB. They first need to identify affected endpoints, test the fix, deploy it quickly, and verify that the emergency update did not introduce another problem.

Action1 centralizes this process for managed Windows endpoints.

Once the OOB update is available and detected as applicable, administrators can use Update Approval or Missing Updates in Action1 to identify the affected endpoints and select the specific Windows KB for deployment. Instead of asking users to check Windows Update or manually downloading an .msu package on every computer, the update can be pushed remotely to selected endpoints from the Action1 console.

For emergency updates that still require validation, Action1 Update Rings allow IT teams to deploy the fix in stages. For example:

IT test devices → early adopters → production endpoints

Action1 can evaluate deployment success before an update progresses to the next ring. If problems appear during testing, administrators can pause the update and prevent it from continuing to outer rings.

For an urgent fix that has already been validated, administrators can instead select the affected endpoints and use Install Now to begin deployment without waiting for the organization’s normal patching schedule.

Action1 also provides reboot controls so users can be notified before a required restart, rather than unexpectedly interrupting their work.

After deployment, reports such as Windows Update History, Missing Windows Updates, and Reboot Required help verify which endpoints successfully installed the OOB update, which still require it, and which encountered installation errors.

This makes Action1 particularly useful when an emergency Windows update must be deployed quickly across many endpoints while still maintaining centralized testing, rollout control, and visibility.

See What You Can Do with Action1

 

Join our weekly LIVE demo “Patch Management That Just Works with Action1” to learn more

about Action1 features and use cases for your IT needs.

 

spiceworks logo
getapp logo review
software advice review
trustradius
g2 review
g2 review