Windows 11 update KB5074105, released on January 29, 2026, marks a significant shift in how Microsoft handles local system privacy and security visibility. Although officially classified as an optional non-security preview update for Windows 11 versions 24H2 and 25H2, this build contains critical structural changes that harden the operating system against unauthorized local reconnaissance and privilege escalation attempts.

The update pushes Windows 11 24H2 to Build 26100.7705 and Windows 11 25H2 to Build 26200.7705. While it does not contain the standard monthly security patches found in a "Patch Tuesday" release, the integration of new administrative barriers and cryptographic management tools makes it a noteworthy deployment for security-conscious users and enterprise IT administrators.

Understanding the New UAC Barrier for Storage Settings

The most immediate security enhancement in KB5074105 is the introduction of a User Account Control (UAC) prompt when accessing the Storage section within the Windows Settings app. Navigating to Settings > System > Storage now requires explicit administrative approval.

Historically, any user logged into a Windows session—regardless of their privilege level—could view detailed information about disk utilization, installed applications, and system-reserved files. While this seemed harmless, it provided a wealth of information for malicious actors or unauthorized users to perform local reconnaissance.

By enforcing a UAC checkpoint, Microsoft has closed a gap that allowed non-privileged users to:

  • Analyze disk usage patterns to identify sensitive data repositories.
  • Inspect temporary and cached files that might contain residual sensitive information.
  • Gain visibility into system-reserved storage areas that reveal the underlying OS configuration.

In an enterprise environment, this change aligns with the principle of "Least Privilege." It ensures that only authorized personnel can audit or manipulate the storage infrastructure of a workstation, thereby reducing the risk of accidental or intentional system tampering.

Cryptographic Enhancements and DPAPI Management

Beyond the visible UI changes, KB5074105 introduces significant improvements to the Data Protection Application Programming Interface (DPAPI). For administrators, the update now allows for more granular control over DPAPI domain backup key management.

Specifically, administrators can now configure the frequency at which these keys rotate automatically. This is a critical security layer that strengthens cryptographic protection for stored credentials and sensitive data. By reducing the lifespan of a single backup key, the system minimizes the potential window of opportunity for an attacker who might attempt to decrypt sensitive system blobs using older or compromised encryption algorithms.

This update effectively modernizes the cryptographic backend of Windows 11, ensuring that the operating system remains resilient against evolving decryption techniques and brute-force attempts on local security authorities.

Secure Boot Certificate Expiration Notifications

A major operational security component included in KB5074105 is the preparation for the upcoming Secure Boot certificate expiration scheduled for June 2026. Secure Boot is a fundamental security standard that ensures a device boots using only software that is trusted by the Original Equipment Manufacturer (OEM).

Microsoft is using this preview update to provide important notifications and status checks within the Windows Security app. This allows users to verify whether their hardware is ready for the transition to new Secure Boot certificates. Failing to address this expiration could lead to boot failures or compromised system integrity once the old certificates are deprecated. By surfacing this information now, KB5074105 serves as an early warning system for long-term platform stability.

Enhanced Sign-in Security for Windows Hello

For users on Copilot+ PCs and high-end desktops, KB5074105 expands the capabilities of Enhanced Sign-in Security (ESS). Previously, ESS features were often limited to built-in biometric sensors on laptops. This update extends support to peripheral fingerprint sensors, allowing users with external hardware to benefit from the same hardened authentication protocols.

ESS ensures that biometric data is processed in a protected environment, isolated from the rest of the operating system. This extension to peripheral devices means that desktop users can now achieve the same level of login security as mobile users, protecting against "spoofing" attacks that attempt to bypass the authentication process using simulated biometric inputs.

Cross-Device Integration and Productivity Features

While security is a major focus, KB5074105 also introduces several features aimed at improving the "Cross-Device Resume" experience. This feature allows users to seamlessly transition tasks between their Android devices and their Windows 11 PCs.

Resuming Activities from Android

If you are working on a document in Microsoft Office or listening to media on Spotify on your Android phone, you will now see options to continue those activities directly on your PC. This integration is managed through the Link to Windows and Phone Link services, creating a more cohesive ecosystem for users who move between different hardware platforms throughout the day.

Windows MIDI Services Improvements

For professional audio users and developers, the update includes substantial enhancements to Windows MIDI Services. It provides better support for MIDI 1.0 and 2.0 standards, including shared port access. This allows multiple applications to communicate with the same MIDI device simultaneously without conflicts, a feature long requested by the music production community.

AI Component Updates to Version 1.2601.1268.0

The KB5074105 update also refreshes the underlying AI framework that powers many of the intelligent features in Windows 11. The following components have been updated to version 1.2601.1268.0:

  • Image Search: Improved local indexing and retrieval of visual content.
  • Content Extraction: Enhanced accuracy when parsing text and metadata from files.
  • Semantic Analysis: Better understanding of user intent within the Windows search and Settings ecosystem.
  • Settings Model: A more responsive AI model for predicting and suggesting system configuration changes.

These updates ensure that on-device AI processing remains efficient and secure, particularly for features that rely on local processing rather than cloud-based computation.

Core System Fixes and Stability Improvements

As with most preview updates, KB5074105 addresses a long list of technical bugs and performance bottlenecks. Notable fixes in this build include:

  • Explorer.exe: Resolved an issue where the file explorer would hang or stop responding during the login process.
  • GPU Stability: Fixed specific errors related to dxgmms2.sys that could cause system crashes (BSOD) during intensive graphical tasks.
  • iSCSI Boot: Addressed "Inaccessible Boot Device" errors that occurred during iSCSI boot sequences.
  • UAC Prompts: Added missing UAC prompts for specific storage settings configurations to ensure consistent administrative oversight.
  • Windows Boot Manager: Fixed a bug where the system would become unresponsive if boot manager debugging was enabled.

Is KB5074105 a Mandatory Update?

No, KB5074105 is an optional preview update. In the Windows Update ecosystem, these are known as "C" releases. They are intended for early adopters and IT professionals who want to test new features and fixes before they are included in the mandatory "Patch Tuesday" update the following month.

If your system is currently stable and you do not require the specific fixes or the new storage UAC feature, it is generally safe to skip this update. The improvements contained here will automatically be included in the mandatory security update scheduled for February 2026.

How to Install KB5074105

If you choose to install the update:

  1. Navigate to Settings > Windows Update.
  2. Click on Check for updates.
  3. Look for "2026-01 Cumulative Update Preview for Windows 11 Version 24H2 for x64-based Systems (KB5074105)".
  4. Select Download and install.

Summary of Key Changes in KB5074105

Feature Change Description Security Impact
Storage Settings Mandatory UAC prompt added for access. High (Prevents local recon)
Secure Boot New notifications for 2026 cert expiry. High (System integrity)
DPAPI Configurable rotation for backup keys. Medium (Cryptographic hardening)
Windows Hello ESS support for peripheral sensors. Medium (Auth security)
Cross-Device Resume Android activities on PC. Low (Usability)
MIDI MIDI 2.0 and shared port support. Low (Functional)

Frequently Asked Questions

Why does Windows now ask for my password to see storage settings?

This is a new security measure introduced in KB5074105. By requiring an administrator to authorize access to the storage menu, Windows prevents non-privileged users from seeing sensitive information about the system's disk structure, installed apps, and temporary files.

Does KB5074105 fix the dxgmms2.sys blue screen error?

Yes, this update specifically addresses a known bug where the dxgmms2.sys driver could cause a system crash under certain GPU-heavy workloads. If you have been experiencing graphical instabilities, this update may resolve them.

What happens if I don't install this update now?

Since it is a preview update, nothing negative will happen if you wait. All the features, security hardening, and bug fixes will be rolled into the mandatory security update released on the second Tuesday of February 2026.

Are there any known issues with KB5074105?

While Microsoft has not officially listed major known issues for this specific build, some users in community forums have reported minor instabilities common with "preview" software. Organizations are encouraged to test the update on a small subset of devices before a wide-scale rollout.

Does this update improve Copilot+ PC features?

Yes, KB5074105 includes version 1.2601.1268.0 of the AI framework, which enhances image search, content extraction, and semantic analysis specifically designed to take advantage of the Neural Processing Units (NPUs) in Copilot+ PCs.