Windows Server · 2022 · Release · Security update (Patch Tuesday)

April 14, 2026—KB5082142 (OS Build 20348.5020)

Windows Server 2022: Supported LTSC release

Microsoft's known issues — KB5082142

  • Issue Known issue After installing this update, domain controllers in environments with multiple domains in the forest that use Privileged Access Management (PAM), might experience LSASS crashes during startup. As a result, affected domain controllers might restart repeatedly, preventing authentication and directory services from functioning, and potentially rendering the domain unavailable. Some devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key on the first restart after installing this update. This issue only affects a limited number of systems in which ALL of the following conditions are true. These conditions are unlikely to be found Workaround: This issue is addressed in out-of-band update KB5091575 . Note If your Windows Server 2022 device is enrolled in hotpatching, you should instead install the OOB hotpatch update KB5091576 . This hotpatch OOB update is released through Windows Update and does not require the device to restart. Remove the Group Policy configuration before installing the update (Recommended) Open Group Policy Editor ( gpedit.msc ) or your Group Policy Management Console. Navigate to: Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives . Set " Configure TPM platform validation profile for native UEFI firmware configurations " to " Not Confi

Microsoft's release notes for KB5082142 ›

Known issues — reported on the forum

In the news

Discussed on the forum

No member thread names 20348.5020 yet.

Search the forum for 20348.5020 Ask about this build