Microsoft released KB5083769 on April 14, 2026 โ the fourth Patch Tuesday of 2026 and the mandatory cumulative security update for Windows 11 versions 25H2 and 24H2. It moves systems to OS builds 26200.8246 and 26100.8246.
This is the fourth Patch Tuesday release in 2026, and it is based on 24H2, which means 25H2 gets the same update. There are no exclusive or special changes โ you get the same fixes across both versions of Windows 11.
The security content is the headline โ as part of the April 2026 Patch Tuesday, Microsoft patched 167 vulnerabilities across its ecosystem. But KB5083769 also ships with meaningful usability improvements: Smart App Control can finally be toggled without a complete OS reinstall, Narrator’s image description capability expands to all Windows 11 PCs powered by Copilot, and a persistent Reset This PC bug from March gets fixed.
There is also a known BitLocker recovery bug that enterprise administrators specifically need to understand before deploying broadly.
Here is everything.
What Is KB5083769?
KB5083769 is the April 14, 2026 mandatory cumulative security update for Windows 11 versions 25H2 and 24H2. This security update contains fixes and quality improvements from KB5079473 released March 10, 2026, KB5085516 released March 21, 2026, KB5079391 released March 26, 2026, and KB5086672 released March 31, 2026.
It appears in Windows Update as “2026-04 Security Update (KB5083769) (26200.8246)” on Windows 11 25H2 systems and “(26100.8246)” on 24H2. Restart is required after installation.
Like February and March before it, this April update continues Microsoft’s push in 2026 to make Windows 11 more reliable, more accessible, and better suited for modern hardware.
167 Vulnerabilities and Two Zero-Days
As part of the April 2026 Patch Tuesday, Microsoft patched 167 vulnerabilities across its ecosystem โ a significant number highlighting how critical it is to install these updates as soon as possible.
Two of those vulnerabilities are zero-days โ either actively exploited before the patch was ready or publicly disclosed before Microsoft’s fix was released. On any unpatched Windows 11 system running 25H2 or 24H2, those attacks remain viable until KB5083769 is installed.
The security patches cover components across Windows networking, authentication, graphics, and kernel components. Two areas worth specifically flagging for enterprise administrators:
SMB over QUIC with Compression โ If you use advanced networking features like SMB over QUIC with compression, this update is particularly important. Vulnerabilities in this networking path are addressed in KB5083769, making it a priority for organizations using modern SMB configurations.
Remote Desktop Protocol Hardening โ KB5083769 includes stronger RDP .rdp file protections against phishing attacks. Malicious .rdp files have been used in social engineering attacks โ this update hardens how Windows handles .rdp files opened from untrusted sources.
Every New Feature in KB5083769
Narrator + Copilot Image Descriptions โ For All PCs
The accessibility feature now offers rich image descriptions on all Windows 11 PCs. Users can either press Narrator key + Ctrl + D to get a description of the focused image, or Narrator key + Ctrl + S to get a description of the full screen.
This is a meaningful accessibility expansion. Although the Windows Narrator feature already included rich image descriptions using AI for Copilot+ PCs, starting with KB5083769, it now uses Copilot to generate these descriptions โ and the feature is available for all devices.
Previously, AI-powered image descriptions in Narrator were exclusive to Copilot+ PCs with dedicated NPU hardware. KB5083769 extends this capability to all Windows 11 25H2 and 24H2 devices by routing the image description request through Copilot rather than requiring on-device AI processing.
How to use it:
Narrator key + Ctrl + D โ describes the currently focused image element.
Narrator key + Ctrl + S โ describes the entire visible screen.
For users who rely on screen readers for accessibility, this is one of the most practically impactful additions in the April 2026 update โ Copilot-powered image descriptions provide context that previous Narrator versions could not generate for arbitrary on-screen visuals.
Smart App Control โ Toggle Without Clean Install
You can turn Smart App Control on or off without needing a clean install. To make changes, go to Settings, Windows Security, App and Browser Control, Smart App Control settings. When turned on, SAC helps block untrusted or potentially harmful apps.
This is a significant usability improvement for Smart App Control. Previously, changing SAC’s state required a complete Windows reinstallation โ the setting was locked after initial setup, meaning users who wanted to enable it after initially declining, or disable it after encountering compatibility problems, had no practical path except wiping and reinstalling Windows.
This feature was previously disclosed in January 2026 and is now beginning to roll out.
Smart App Control is a security feature that uses Microsoft’s cloud-based reputation service to evaluate applications before they are allowed to run. Apps that are known safe run normally. Apps that are unknown or suspicious are blocked or prompted. When enabled, SAC provides an additional layer of protection against untrusted software running on your system.
The ability to toggle it freely is particularly useful for developers and IT professionals who need to run internal or unsigned tools that SAC would otherwise block, and for users who want to try SAC without committing to it permanently.
Secure Boot Certificate Status in Windows Security
The status of Secure Boot certificate updates on your device may be displayed in the Windows Security app at Settings, Privacy and Security, Windows Security. These enhancements are disabled by default on commercial devices.
KB5083769 adds a new status indicator in the Windows Security app showing whether your device has received the updated Secure Boot certificates. The phased Secure Boot certificate rollout โ which began in earlier 2026 updates โ has been a source of confusion for users who are not sure whether their device has received the new certificates.
This visibility improvement gives users a clear way to check their certificate status without needing PowerShell or advanced tools.
Microsoft 365 Family Plan Upgrade From Settings
Microsoft 365 Family subscribers can upgrade to a different Microsoft 365 plan from Settings, Accounts.
A small but convenient addition: Microsoft 365 Family subscribers can now initiate a plan upgrade directly from Windows Settings without navigating to the Microsoft 365 website or account portal. To remove this option if you prefer not to see it, turn off Suggested content in Settings, Personalization, Device usage.
Vulnerable Driver Blocklist Update
This update introduces a security hardening change that adds known vulnerable kernel drivers to the Microsoft vulnerable driver blocklist. Backup applications that rely on blocked drivers might experience failures when attempting to mount or manage disk images.
Microsoft maintains a list of kernel drivers with known security vulnerabilities that can be exploited by attackers to gain kernel-level access. KB5083769 adds newly identified vulnerable drivers to this blocklist, preventing them from loading.
The practical impact for most users is zero โ the blocked drivers are ones with documented vulnerabilities. However, some backup and disk management applications that use drivers from this list for mounting virtual disk images may encounter failures after KB5083769. If your backup software stops working correctly after this update, check with the vendor for an updated driver that is not on the blocklist.
File Explorer and Settings Improvements
The April release brings significant accessibility improvements, display and hardware enhancements, and several quality-of-life additions across Settings and File Explorer.
Settings loads faster in KB5083769 โ the time between clicking Settings and seeing the first page is reduced, particularly on systems where Settings was slow to open. File Explorer receives additional reliability improvements building on the multi-drive search work in KB5079473.
Reset This PC Bug Fixed
This update addresses an issue that might cause device reset to fail when using the Keep my files or Remove everything options. This might occur after installing the March 2026 KB5079420 Hotpatch security update.
Users who installed the March 2026 Hotpatch and subsequently tried to reset their PC โ using either “Keep my files” or “Remove everything” โ found the reset process failing without completing. KB5083769 fixes the underlying issue that caused this failure.
This is one of the more important bug fixes in the April update for users who rely on Reset This PC as a troubleshooting tool or for repurposing devices.
Full Feature and Fix Summary Table
| Item | Type | Details |
|---|---|---|
| Narrator Copilot images | New | All Windows 11 PCs โ not just Copilot+ |
| Smart App Control toggle | New | On/off without reinstall |
| Secure Boot status | New | Visible in Windows Security app |
| M365 plan upgrade | New | From Settings, Accounts |
| Vulnerable driver blocklist | Security | May affect some backup apps |
| File Explorer | Improved | Reliability improvements |
| Settings | Improved | Faster loading |
| SMB over QUIC | Security | Networking vulnerability fixes |
| RDP file protections | Security | Phishing hardening |
| Reset This PC bug | Fixed | Fails after March hotpatch โ now resolved |
| Secure Boot certificates | Ongoing | Continued phased rollout |
Known Issues โ The BitLocker Recovery Bug
Microsoft initially said the update does not have any bugs but has now added a known issue that forces users into BitLocker recovery. The company has issued workarounds.
This is the most significant known issue in KB5083769 and deserves specific attention from enterprise administrators.
Despite fixing a known BitLocker issue, Microsoft has acknowledged a paradoxical bug in KB5083769.
After installing KB5083769, some devices boot into BitLocker recovery mode โ requiring users to enter their BitLocker recovery key before Windows loads. This affects a subset of devices, particularly those with custom BitLocker policy settings in managed enterprise environments.
Who is most at risk:
Organizations managing BitLocker through Group Policy or Intune with non-default settings. Devices where BitLocker configuration deviates from Microsoft’s recommended defaults. Systems where BitLocker recovery keys have not been backed up to Active Directory or Azure AD.
Microsoft’s workaround:
Ensure BitLocker recovery keys are backed up before deploying KB5083769 broadly. Check that recovery keys are available in Active Directory, Azure AD, or your organization’s key management system. If a device enters BitLocker recovery after the update, enter the recovery key to unlock and boot normally โ the system will function correctly once unlocked.
For enterprise administrators:
Administrators should review the documented BitLocker known issue before broad deployment, especially in managed enterprise environments that use custom BitLocker policy settings.
Test KB5083769 on a representative sample of your fleet before broad deployment. Verify that BitLocker recovery keys are accessible for all managed devices before the update reaches them.
How to Install KB5083769
Method 1 โ Windows Update
Go to Settings, Windows Update, Check for updates. KB5083769 appears as “2026-04 Security Update (KB5083769) (26200.8246)” on Windows 11 25H2. Click Download and install. Restart when prompted โ this update requires a restart.
Via Windows Update (recommended): Go to Settings, Windows Update, Check for updates. When you see “April 2026 Security Update (KB5083769)”, select Download and install.
Method 2 โ Microsoft Update Catalog
Go to catalog.update.microsoft.com. Search for KB5083769. Select the package for your Windows version โ 25H2 or 24H2 โ and architecture โ x64 or ARM64. Download and run the .MSU file. Restart when complete.
If you encounter error 0x80244022 during download, our complete fix guide covers every resolution step.
KB5043080 โ the September 2024 checkpoint SSU โ is required before KB5083769 can install. Most systems already have it. If KB5083769 fails with error 0x800F0838, install KB5043080 first.
How to Verify KB5083769 Installed Successfully
Go to Settings, System, About. Under Windows specifications:
Successful on Windows 11 25H2: build 26200.8246
Successful on Windows 11 24H2: build 26100.8246
Check Settings, Windows Update, Update History for KB5083769 with a Successfully installed status dated April 14, 2026.
Should You Install KB5083769?
Yes โ for most users immediately.
Yes โ without hesitation. With 167 vulnerabilities fixed, improved protections against phishing, and key system fixes, this update is one of the more important releases of the year.
The two zero-days and the 167 total vulnerabilities make this a high-priority security update.
Enterprise administrators โ test first:
The BitLocker edge case is a reminder that even security updates can introduce unexpected behavior โ especially in complex environments. Testing before deployment is recommended.
Verify BitLocker recovery key accessibility across your fleet. Test on a representative sample before broad deployment. Confirm that backup applications are not using any drivers on the updated blocklist.
KB5083769 in the 2026 Update Chain
KB5083769 is the April link in the continuous 2026 monthly update sequence for Windows 11 25H2 and 24H2.
KB5079473 โ March 10, 2026. Nine new features including Emoji 16, built-in Sysmon, Taskbar speed test.
KB5083769 โ April 14, 2026. This article. 167 vulnerabilities, Narrator Copilot, Smart App Control toggle, BitLocker bug.
KB5094126 โ June 9, 2026. Shared Audio, Low Latency CPU Profile, OLE Automation bug.
KB5095093 โ June 23, 2026. Point-in-Time Restore debut, Bluetooth fixes, Dell issue origin.
KB5101650 โ July 14, 2026. 570 vulnerabilities โ record. Point-in-Time Restore for all users.
Each update in the chain is cumulative โ KB5101650 contains all security content from KB5083769 and every update before it. A system that missed April and installs July directly receives all of April’s security patches automatically.
Frequently Asked Questions
What is KB5083769?
KB5083769 is the April 14, 2026 Patch Tuesday mandatory cumulative security update for Windows 11 versions 25H2 and 24H2. It moves systems to OS builds 26200.8246 and 26100.8246, fixes 167 vulnerabilities including two zero-days, and adds Narrator Copilot image descriptions, a Smart App Control toggle, and Secure Boot certificate status visibility.
What is the BitLocker issue with KB5083769?
After installing KB5083769, some devices boot into BitLocker recovery mode โ requiring the BitLocker recovery key before Windows loads. This primarily affects devices with custom BitLocker policy settings in managed environments. Microsoft has issued workarounds โ ensure recovery keys are backed up before deploying. Enterprise administrators should test on a representative sample before broad rollout.
Can I now toggle Smart App Control without reinstalling Windows?
Yes. KB5083769 introduces the ability to turn Smart App Control on or off from Settings, Windows Security, App and Browser Control, Smart App Control settings โ without requiring a clean OS reinstall. This was previously not possible.
How does Narrator image description work in KB5083769?
KB5083769 extends Narrator’s AI-powered image description capability to all Windows 11 PCs โ not just Copilot+ hardware. Use Narrator key + Ctrl + D to describe a focused image or Narrator key + Ctrl + S to describe the full screen. Descriptions are generated by Copilot.
What OS build does KB5083769 install?
KB5083769 installs OS build 26200.8246 on Windows 11 25H2 and build 26100.8246 on Windows 11 24H2.
Does KB5083769 require a restart?
Yes. Unlike some updates that can apply without a restart, KB5083769 requires a system restart to complete installation.
What does the vulnerable driver blocklist change in KB5083769 mean for backup software?
KB5083769 adds newly identified vulnerable kernel drivers to Microsoft’s blocklist. If your backup application uses a driver on this list to mount or manage virtual disk images, it may fail after installation. Check with your backup software vendor for an update that uses a non-blocked driver.
How many vulnerabilities does KB5083769 fix?
KB5083769 fixes 167 vulnerabilities as part of the April 2026 Patch Tuesday cycle, including two zero-days that were either actively exploited or publicly disclosed before the patch was available.