Neowin's report on the release gives the build as 28000.3086. Microsoft's Windows Insider release notes give KB5124006 as build 28000.3079. Both are right, and the reason why tells you what you'd actually be installing.
KB5124006 Shipped Twice: Release Preview Build 28000.3079, Then Production Build 28000.3086
KB5124006 went out in two stages eleven days apart. Microsoft's Windows Insider release notes, dated September 11, 2026, describe "Windows 11 Build 28000.3079 (KB5124006) in the Release Preview Channel on Windows 11, version 26H1." That was the tester build. Windows 11 Forum (ElevenForum) logged that build under the Insider track on September 11 and filed it apart from the production cumulative updates. These release notes are for Windows 11 Build 28000.3079 (KB5124006) in the Release Preview Channel on Windows 11, version 26H1.
The second stage came on the fourth Tuesday of September. Microsoft's own 26H1 update-history list now includes September 22, 2026—KB5124006 (OS Build 28000.3086) Preview. The official @WindowsUpdate account announced it the same day with the same build number. Germany's Deskmodder followed both stages. It reported that Microsoft revised KB5124006 and released it to everyone as the September optional update, with the version number changing to Windows 11 26H1 28000.3086, and that the changes include the fixes from the out-of-band update of 14.09.2026.
That explains the seven-build gap. Between the Release Preview build and the public release, Microsoft shipped an emergency update. The September 14 out-of-band package, KB5129194 (OS Build 28000.2956), includes protections documented in CVE-2026-62721, which refers to a Windows User-Mode Power Service (UMPS) Elevation of Privilege vulnerability. It also covers CVE-2026-85921, a Windows Secure Kernel Mode elevation-of-privilege flaw. And it addresses an issue affecting Remote Desktop Services (RDS) after installing the September 2026 Windows security update (KB5124012). The German site it-blogger.net reports that the public KB5124006 rolls up the September 8 Patch Tuesday release (KB5124012), that out-of-band fix, and the previous month's optional improvements.
In practice, build 28000.3086 is a superset of 28000.3079. It has every feature and fix from the Release Preview notes, plus the security and RDS fixes that shipped in between. Anyone who installed the Release Preview build in mid-September and then applied KB5129194 already has most of this. Anyone who skipped the out-of-band patch gets those protections here.
Here is the September 2026 servicing sequence for 26H1, from Microsoft's update-history listing:
| Date | KB | OS Build | Type |
|---|---|---|---|
| August 27, 2026 | KB5120996 | 28000.2804 | Optional preview |
| September 8, 2026 | KB5124012 | 28000.2954 | Monthly security update |
| September 11, 2026 | KB5124006 | 28000.3079 | Release Preview Channel (Insiders) |
| September 14, 2026 | KB5129194 | 28000.2956 | Out-of-band |
| September 22, 2026 | KB5124006 | 28000.3086 | Optional preview (public) |
For most people this is a routine fourth-Tuesday release. It is optional and non-security, and it is Microsoft's usual way of previewing next month's features. If the pattern holds, the same changes will be folded into October's mandatory Patch Tuesday update. It is available now via Windows Update: open Settings › Windows Update, select Check for updates, and choose Download and install.
Windows 11 26H1 Is a Hardware Branch, So Few PCs Will See KB5124006
This update does not reach the typical Windows 11 PC, and the reason is 26H1 itself. Microsoft's February 2026 support note (KB5079944) describes 26H1 as a release built to enable new silicon. It "is not designed to be offered or installed on existing devices." It ships only on select new devices launching in the first quarter of 2026, and existing 24H2 or 25H2 machines cannot move to it as an in-place update. According to the note, the first devices use Qualcomm Snapdragon X2 Series processors.
The note also sets a limit on the future. Microsoft says 26H1 devices get the same monthly security, quality, and feature updates as 24H2 and 25H2. But they "will not be able to update to the next annual feature update in the second half of 2026" because 26H1 sits on a different Windows core. Those devices will get an upgrade path in some later release. Deskmodder repeats the point: 26H1 cannot be upgraded to 26H2. That matters now, because 26H2 builds are already in Release Preview.
The table explains the unusual build number. The mainstream branches ship together. The same day KB5124006 arrived, Microsoft released KB5124006 Windows 11 Cumulative Update Preview build 28000.3086 (26H1) for the 28000-series branch and KB5124010 for the 26100 (24H2), 26200 (25H2), and 26300 (26H2) builds. Neowin's piece also points to KB5124010, the companion release for mainstream PCs. The two carry similar feature text, but they are different packages for different codebases.
There's one wrinkle on hardware. The first 26H1 devices are Arm-based, but Deskmodder notes that Windows 11 26H1 can also be installed normally as x64. Enthusiasts who built x64 test machines on 26H1 will get this update too. Microsoft's official language still describes 26H1 as a release that comes preinstalled on new devices, not one you install yourself.
To check whether this applies to you, run winver or open Settings > System > About. A version of 26H1 with a build starting "28000" means KB5124006 is yours. Builds starting 26100, 26200, or 26300 mean you want KB5124010.
The Taskbar Moves at Last: Top, Left and Right Positions and a Small Size in KB5124006
For users, the headline is the taskbar. Windows 11 launched with the taskbar fixed to the bottom of the screen. Moving it to the sides or top was one of the most requested features and one of the most visible things Windows 10 users lost. KB5124006 puts it back as a supported option.
Microsoft's release notes say you can now choose whether the taskbar sits at the bottom, top, left, or right of the screen. In the other positions, tooltips, flyouts, and animations still come from the taskbar. Most customization settings, such as never combining taskbar icons, work in every position. The control is at Settings > Personalization > Taskbar > Taskbar behaviors > Taskbar position.
There are two limits. The search box and the new smaller taskbar work only in the top and bottom positions. If you move the taskbar to a side edge, you lose the inline search box and the compact size. That's a real trade-off on a narrow laptop screen, where a vertical taskbar is supposed to save height.
The second change is a Small taskbar size, aimed at smaller screens. Microsoft says it shrinks both the icons and the bar's height, and Start, Search, and the system tray stay available. The setting is at Settings > Personalization > Taskbar > Taskbar behaviors > Taskbar size, and choosing Small shrinks both. Windows 10 had a "use small taskbar buttons" option that Windows 11 dropped, so this also restores an old setting.
To make these easier to find, the Taskbar behaviors section of the Taskbar settings page now opens expanded by default. The notes also list a reliability fix for loading the system tray on non-touch PCs.
To change the taskbar on a 26H1 PC once the gradual rollout reaches it:
- Open Settings and go to Personalization > Taskbar.
- Find Taskbar behaviors, which is now expanded by default.
- Set Taskbar position to Bottom, Top, Left, or Right.
- If you picked Top or Bottom, set Taskbar size to Small if you want the compact bar.
If the Taskbar position control isn't there after installing the update, your device hasn't received that feature yet. That's how the gradual rollout works, not a sign of a failed install. Microsoft's release notes say a gradual rollout "delivers an update in phases, so features reach devices over time instead of all at once, meaning availability varies by device."
Start, Search and File Explorer Get New Controls Instead of Redesigns
The Start menu, Windows Search, and File Explorer changes follow one pattern: Microsoft is adding switches to existing surfaces rather than rebuilding them.
Start menu sizing and the "Recommended" to "Recent" rename
The Start menu gets explicit Small and Large sizes alongside the current Automatic default, at Settings > Personalization > Start > Start menu size. The "Recommended" section becomes "Recent" in both the Start menu and the Start settings page. It's a small wording change, but it reads less like a suggestion feed. You can also hide your name and profile picture in Start via Settings > Personalization > Start > Hide your name and profile picture on Start. That helps anyone presenting, recording, or sharing their screen.
The Start settings page itself is redesigned, with separate toggles that show or hide the Pinned, Recent, and All sections independently. Neowin's copy of the changelog calls these sections "Pinned, Recommended, and All" and uses "Personalize" as the Settings category. Microsoft's release notes use "Recent" for the renamed section and "Personalization" in the path. Follow Microsoft's wording when you look for the controls.
Windows Search gets source labels and a web-suggestions switch
Microsoft describes the Search changes as making results more dependable, easier to scan, and clearer before you click. Search home is simplified to cut clutter and get you back to recent searches faster. Results now show more clearly where they come from: an app, a setting, a file, a web result, or a Microsoft Store suggestion. So you can tell before clicking whether you're about to open a local file or a browser tab.
The most useful Search item is a new control at Settings > Privacy & security > Search. It decides whether web and Microsoft Store suggestions appear next to local results. People who want the Start search box to find only local apps, settings, and files have long relied on registry edits or policy workarounds. On 26H1, that choice is now a supported setting on the Settings page where users would look for it.
The other Search change works the opposite way. Windows now automatically indexes your most-used folders so files in them show up in later searches. You control it at Settings > Privacy & security > Search > Automatically find additional relevant locations. The release notes don't say whether it's on by default after the update. Users with strict ideas about what gets indexed should check that toggle once the feature arrives.
File Explorer Home and system-wide progress indicators
Microsoft says File Explorer Home now launches faster and responds more quickly, and the Recommended carousel on Home now supports touch scrolling. These are Microsoft's performance claims, and no independent measurements have been published. Since the first 26H1 hardware is Arm-based and often touch-enabled, the touch-scrolling fix is aimed squarely at that hardware.
The update also brings refreshed progress indicators across Windows during startup, sign-in, restart, shutdown, and update installation. It's purely cosmetic, but it's the kind of change help-desk staff will notice when users ask why the boot screen looks different.
Several smaller reliability items belong here too. Switching between virtual desktops is smoother and more responsive. The Settings > System > Display page is more reliable to open and use. Your previous brightness setting sticks better after Energy Saver turns off. Task Manager shows app history more reliably. Windows Setup makes it easier to skip adding a second keyboard layout. And the Get Started app gains App install, Site pinning, and Theme pages.
One Windows Update fix will appeal to laptop owners. PCs that were manually put to sleep now go back to sleep after finishing an update, even when automatic sleep is set to Never. Before this, a laptop could wake to install an update and then stay awake because of the power setting.
Administrator Protection, Autopilot Device Association and Share Suggestions Need IT's Attention
Enthusiasts will look at the taskbar. Administrators should look at three other items, because each one changes how managed devices behave or how they can be controlled.
Administrator protection begins its rollout, off by default
Administrator protection is the biggest security change in KB5124006. Microsoft's release notes say it "aims to protect free-floating admin rights for administrators" by letting users do administrative tasks with just-in-time privileges. In plain terms, an admin account no longer carries standing elevated rights all the time. Elevation is granted when a task needs it. The feature uses profile separation to harden Windows against elevation-of-privilege attacks, the class of bug that lets malware running as an ordinary user gain admin control.
Microsoft also states that Administrator protection "isn't classified as a formal security boundary." In Microsoft's security-servicing terms, that likely means a way around it wouldn't automatically be handled as a vulnerability the way a break of a true boundary would. That's an inference from the wording; the release notes don't spell out the servicing consequences. What it means in practice is clear: Administrator protection makes attacks harder. It doesn't replace least-privilege account design, application control, or endpoint protection.
The feature is off by default. It can be enabled with an OMA-URI setting in Microsoft Intune or through Group Policy. Microsoft first disclosed it in the October 2025 update KB5067036 and says it "is now beginning to roll out." Nothing changes on a managed 26H1 fleet until an administrator deliberately turns it on. It should be piloted before any broad rollout, because changing how elevation works can break scripts, installers, and support tools that expect an admin session to have standing rights.
The timing is worth noting. This update ships the week after the out-of-band fix for two elevation-of-privilege CVEs, one in the User-Mode Power Service and one in Secure Kernel Mode. Administrator protection is not a patch for those specific flaws, and Microsoft doesn't present it that way. But they're the kind of attack it's meant to make harder.
Windows Autopilot device preparation: device association reaches general availability
The notes mark one item as generally available instead of in preview: device association for Windows Autopilot device preparation. Microsoft says it helps organizations identify trusted devices before enrollment. That enables device-targeted policies, automatic corporate device enrollment, and more setup customization during the out-of-box experience (OOBE).
This addresses a gap organizations have noticed in the newer Autopilot device preparation model. Without a way to know a device is corporate-owned before enrollment, policy tends to follow the user, not the hardware. Device association lets IT aim configuration at the machine from the first boot. The release notes only establish GA status for this capability as it appears in the 26H1 update. Admins running device preparation on 26H1 hardware should test it against their existing enrollment profiles before relying on it.
Windows Share can now suggest apps to work and school users
The third item is small but relevant to IT. Users signed in with a work or school account can now discover and install relevant apps directly from the share window. It's controlled at Settings > System > Share > Show suggested apps in share surfaces.
The release notes describe only that per-user Settings control. They don't document a policy or Intune setting for it. Organizations that tightly control app installs through Intune, Store policy, or application control should know about this new discovery surface and check whether their existing Store restrictions cover installs started from Share. Microsoft's notes don't say how the feature interacts with those policies, and that's the detail a locked-down environment needs to confirm in a pilot.
MXC Process Isolation and Agent Tagging Build Windows 11 Plumbing for AI Agents
Two items in KB5124006 matter less for today's users than for where Microsoft is taking the platform. Both are aimed at software agents that write and run code or act for users.
The first is Process Isolation for Microsoft Execution Containers (MXC). Microsoft calls it "a fast, lightweight boundary for responsive workloads such as coding agents and model-generated code." It uses Windows' built-in containment features to restrict access to files, networking, the user interface, and other OS capabilities according to policy. The use case is easy to see: an AI coding assistant that generates and runs a script shouldn't automatically get the full rights of the user who asked for it. The release notes don't describe the policy format, how developers call the containers, or how it compares with other Windows isolation options. For now it's something developers should know exists, not something admins can configure.
The second is preview platform support for tagging agentic processes. Authorized components can attach an opaque agent identifier to a process token, the security object Windows uses to track a process's identity and privileges. Windows protects the tag and passes it automatically to child processes, so a program an agent launches inherits the label. When a tagged process signs in through Web Account Manager (WAM), the Windows component that handles account sign-in for apps, WAM includes the agent identifier in the authentication request.
Put simply, identity systems can now tell whether an access token was requested by a human-driven app or by an agent acting for that human. Services that receive the request could apply different rules, log differently, or refuse agent access. Microsoft marks the feature as preview and warns that the identifier format "might change in future releases." Developers shouldn't hard-code assumptions about its structure yet.
ML-KEM becomes a standalone TLS key-exchange option
The cryptography change is narrow but concrete. The post-quantum algorithm ML-KEM can now be used on its own for TLS key exchange, in addition to the hybrid groups added earlier. Hybrid groups pair a classical key exchange with a post-quantum one, so the connection stays secure as long as either holds. A standalone mode depends on ML-KEM alone. Security architects planning post-quantum migration now have both options in the Windows TLS stack on 26H1. The release notes don't say how applications opt in or whether any defaults change, so treat this as a new capability to test, not a behavior change you'll see automatically.
App update coordination and WinUI 3 in-app purchases
Two developer items round out the platform list. The Windows Update Orchestration Platform (UOP) lets participating apps coordinate their updates with Windows Update, which Microsoft says brings better scheduling and a smoother update experience. The notes describe it as opt-in for apps, so nothing changes until developers adopt it. Separately, packaged WinUI 3 apps that need elevation can now offer in-app purchases through Microsoft's commerce platform. That closes a gap for developers whose apps need admin rights and who want to sell through the Microsoft Store.
WMIC Removal and the Quieter Fixes in KB5124006
One item in the release notes isn't about 26H1 at all, and it's easy to misread. Microsoft includes a notice about the Windows Management Instrumentation Command-line (WMIC) utility: starting in August 2026, Windows 11 versions 24H2 and 25H2 no longer include it. WMIC is already absent by default from new installs of those versions and is no longer available as a Feature on Demand. The change affects only the wmic.exe tool. Microsoft states that Windows Management Instrumentation (WMI) itself remains supported.
There's a tense difference. Neowin's copy of the changelog says 24H2 and 25H2 "will no longer include" WMIC, which reads like a future change. Microsoft's release notes use the present tense, since August 2026 has already passed. For admins, the takeaway is the same either way. Any script, scheduled task, monitoring agent, or install routine that calls wmic.exe on 24H2 or 25H2 needs rewriting against a supported interface. The usual replacement is PowerShell's CIM cmdlets, which query the same WMI classes. Because the notice names 24H2 and 25H2 specifically, it shouldn't be read as a new removal announced for 26H1.
The remaining items are regional and reliability fixes. Recovery improves from VPN-related background problems that could make processes stop responding. The output of netsh wlan show wlanreport is better for Japanese users. The Japanese IME should hang less often. Voice typing settings for automatic punctuation and the launcher should stick more reliably.
The normal-rollout fixes: File History and localization
The gradual-rollout list is what reviewers focus on. The normal-rollout section is what every device that installs the update receives right away. Neowin's changelog lists two items there. The first improves accessibility and translations for the Intelligent Carveout interface. The second fixes a bug where File History could fail to back up or restore files to an external drive or network location, with affected PCs wrongly showing "Reconnect your drive" even though a working backup drive was connected.
That second fix is the most practical item in the update for anyone who uses File History. A backup tool that falsely claims the drive is missing is easy to ignore until you actually need to restore something. Microsoft's Release Preview notes contain the normal-rollout heading but no itemized fixes, so the File History detail comes from Neowin's copy of the public changelog.
Early user reports of anti-cheat trouble
The comment thread on Deskmodder's KB5124006 article has one early problem report worth mentioning. A commenter said EA's anti-cheat software misbehaved after the update, with Battlefield 6 launching and then crashing. Another wrote that all games with anti-cheat stopped working, so they went back to the old version by restoring a system restore point. These are individual user reports. Microsoft hasn't acknowledged a known issue, and no other outlet has reported the problem. Gamers running 26H1 who rely on titles with kernel-level anti-cheat have a reason to wait a few days before installing this optional update, or at least to create a restore point first.
What this means for you
Your first decision is whether this update applies to you at all. Your second is whether to install it now or let it arrive with October's Patch Tuesday. KB5124006 applies only to PCs running Windows 11 version 26H1 (build 28000.x), which mostly means new Snapdragon X2 devices and a few enthusiast test installs. Everyone on 24H2, 25H2, or 26H2 should look at KB5124010 instead.
For individual 26H1 users, this is a low-risk optional update with visible benefits, including the taskbar-position feature many have waited for since Windows 11 launched. Remember that installing the package doesn't guarantee the new features right away, because most arrive through the gradual rollout. The File History fix and the rolled-up September security fixes do come with the install. The main reason to wait is anti-cheat games, based on the early user reports.
For IT administrators with 26H1 hardware, the update is a pilot opportunity, not something to rush out broadly. Administrator protection needs a deliberate test of elevation workflows before you enable it through Intune or Group Policy. Autopilot device association is GA and worth validating against current device-preparation profiles. The new Share app-suggestion surface should be checked against your Store restrictions. Admins with 24H2 and 25H2 fleets should treat the WMIC notice as a script audit that's already overdue.
- Check
winverfirst. KB5124006 is for Windows 11 26H1 (builds 28000.x). The public release is OS Build 28000.3086, and 28000.3079 was the September 11 Release Preview build. - The public build includes the September 14 out-of-band fixes for CVE-2026-62721, CVE-2026-85921, and the Remote Desktop Services problem caused by KB5124012, so installing it also brings a skipped device up to date on those fixes.
- Taskbar position and the Small taskbar size are at Settings > Personalization > Taskbar > Taskbar behaviors, but the search box and Small size work only when the taskbar is at the top or bottom.
- Administrator protection is off by default and turned on with Intune OMA-URI or Group Policy. Microsoft says it is not a formal security boundary, so pilot it alongside your existing least-privilege controls, not in place of them.
- Users who want local-only search results should check Settings > Privacy & security > Search once the gradual rollout arrives. The web and Store suggestion switch and the automatic folder indexing toggle both live there.
- 26H1 devices cannot move to the second-half-2026 feature update, so plan hardware on 26H1 as a separate servicing branch until Microsoft announces its upgrade path.
KB5124006 shows the shape of Windows 11 26H1 as a product: a branch built for specific hardware that still gets the same monthly features as mainstream Windows. That includes the taskbar flexibility users have asked for since 2021 and the agent-security groundwork Microsoft is building into the OS. The optional release gives 26H1 owners and admins the next few weeks to try the changes. Unless Microsoft follows its usual pattern differently this month, these features and fixes will be folded into October's mandatory security update. After that, installing is no longer a choice, and the only thing left to decide is which gradual-rollout features you turn on.