Microsoft has confirmed a Windows 11 issue that can leave users with a black screen after sign-in or prevent the desktop from loading automatically.
The problem affects devices that installed the August 2026 non-security preview updates and potentially later cumulative updates, with Azure Virtual Desktop environments using FSLogix profile containers most frequently affected.
The issue was formally added to Microsoft’s Windows release-health dashboard on September 24 and is currently marked as mitigated.
Windows 11 Update Causes Black Screen
However, the company has not yet released a permanent code-level fix; instead, it is using a Known Issue Rollback (KIR) policy to disable the problematic non-security change until a future Windows update resolves the defect.
For Windows 11 version 26H1, Microsoft traced the regression to KB5120996, the August 27 preview release carrying OS Build 28000.2804. Windows 11 versions 25H2 and 24H2 are also in scope, with Microsoft identifying KB5120998 as the originating update for those releases.
Organizations should therefore assess their wider virtual-desktop estate rather than treating the incident as a 26H1-only issue. Affected users can authenticate successfully but may see a blank black display instead of a functional Windows desktop.
In other cases, the desktop session does not initialize automatically, leaving users without normal access to the taskbar, Start menu, desktop shortcuts, File Explorer, and other shell-dependent functions.
Microsoft said Application event logs on affected devices may record Windows Explorer crashes. Explorer.exe is responsible for much of the Windows interactive shell, including rendering the taskbar, desktop, and File Explorer.
If it crashes during shell startup, the underlying user session can remain active while appearing to be frozen or unusable. The condition has been seen mainly on Azure Virtual Desktop session hosts using FSLogix, Microsoft’s profile-management technology for virtual desktop deployments.
FSLogix is widely used to provide roaming profile containers across shared, pooled, persistent, and non-persistent desktop environments. Microsoft noted that the issue appears more likely to affect certain existing user profiles.
Users who encounter the black screen can manually restore their desktop without restarting the system. They can press Ctrl+Shift+Esc to open Task Manager, select Run new task, type explorer.exe, and choose OK.
This launches the Windows shell and can restore the session, but it does not eliminate the underlying update regression. For managed environments, Microsoft has published KIR Group Policy packages that reverse only the problematic non-security code change while retaining the rest of the installed update.
Windows 11 version 26H1 administrators should deploy the KB5124006 rollback policy, while Windows 11 24H2 and 25H2 environments require KB5124010. Administrators must install and configure the policy appropriate to their Windows version, then restart affected devices.
The incident highlights the operational risk of deploying optional preview updates broadly across virtual desktop infrastructure.
IT teams should identify hosts running the affected builds, correlate user reports with Explorer crash events, validate rollback policies against representative FSLogix profiles, and monitor Microsoft’s release-health guidance for the permanent fix.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

