"Administrator protection is not classified as a formal security boundary; it hardens the security against elevation‑of‑privilege attacks with the introduction of profile separation," Microsoft said.
Administrator protection and just‑in‑time privileges
Microsoft has begun rolling out an "administrator protection" feature in the KB5120998 preview cumulative update for Windows 11 versions 25H2 and 24H2. The company describes the capability as a hardening against elevation‑of‑privilege attacks by introducing profile separation. The feature is turned off by default and can be enabled centrally using OMA‑URI in Microsoft Intune or through Group Policy. Microsoft explicitly notes the feature is not a formal security boundary.
Taskbar and Start menu customization
The August 2026 preview adds a long‑requested level of flexibility to the taskbar and Start menu. Users can move the taskbar to the bottom, top, left, or right of the screen via Settings > Personalization > Taskbar > Taskbar behaviors > Taskbar position; most customization settings such as never combining taskbar icons will work in every position. A new smaller taskbar option reduces taskbar height and icon size to preserve screen space on smaller devices. The update also introduces small and large Start menu size options (Settings > Personalization > Taskbar > Taskbar behaviors > Taskbar size dialog) and lets users independently show or hide the Pinned, Recommended, and All sections, as well as hide the account name and profile picture.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildSearch indexing, app update coordination, and reliability fixes
Windows will now automatically index a user's most‑used folders so those files appear higher in subsequent search results; this behavior is user‑controllable at Settings > Privacy & Security > Search > Automatically find additional relevant locations. The update also adds support for participating applications to coordinate their updates with Windows Update through the Windows Update Orchestration Platform (UOP), which Microsoft says can improve scheduling and streamline the update experience for supported apps. Separately, the preview includes improvements to resiliency and recovery from potential VPN process‑related background issues that could cause processes to stop responding.
Deployment model, builds, and reboot guidance
KB5120998 is a monthly optional, non‑security preview update intended for IT administrators to test bug fixes, quality improvements, and new features ahead of the broader roll‑out during next month's Patch Tuesday release. By design, monthly optional updates do not include security fixes. Installing this optional update upgrades Windows 11 25H2 devices to build 26200.9278 and Windows 11 24H2 devices to build 26100.9278.
Administrators and users can install KB5120998 via Windows Settings > Windows Update > Check for Updates and then clicking "Download and install" unless the device has the "Get the latest updates as soon as they're they're available" option enabled. The update can also be manually downloaded from the Microsoft Update Catalog.
Microsoft warned customers that a limited number of consumer and business devices might experience one additional restart during installation, a one‑time restart that occurs after a Secure Boot certificate update is applied as part of the Secure Boot update process.
WMIC removal, support timelines, and upgrade advice
Starting in August 2026, Windows 11 versions 24H2 and 25H2 will no longer include the Windows Management Instrumentation Command‑line (WMIC) utility. WMIC is already removed by default in new installations of those versions and will no longer be available as a Feature on Demand. Microsoft also reminded customers that devices running Home and Pro editions of Windows 11 24H2 will stop receiving updates in two months, while 24H2 Enterprise and Education editions will remain under mainstream support until October 2027. The company advised users to upgrade to Windows 11 25H2 (also known as the Windows 11 2025 Update), which became generally available in September 2024.
What this means for IT administrators, end users, and security teams
- IT administrators: Will want to test administrator protection and taskbar/Start changes in controlled environments before broad deployment; the OMA‑URI and Group Policy controls allow centralized enablement. Administrators must also plan for the one‑time additional reboot some devices may experience and manage WMIC removal in scripts and tooling.
- End users and device managers: Gain new customization options for taskbar placement and size and can opt into improved search indexing and app update coordination, but should note that this optional update does not contain security fixes and must be manually installed unless automatic optional updates are enabled.
- Security teams: Should evaluate the administrator protection feature's profile separation and the operational impact of WMIC removal, and track the Secure Boot certificate update that may trigger an extra reboot during installation. The source material also cites a broader finding: "Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply," from the Blue Report 2026, a data point security teams may factor into risk assessments.
KB5120998 bundles a mix of user‑facing customization, app‑coordination plumbing, and security‑adjacent changes intended for testing ahead of the next Patch Tuesday. Administrators and users who want the new features can opt in now; those requiring security updates will continue to rely on the scheduled cumulative updates that follow the preview cycle.




