{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/july-2026-windows-security-update-deployment-checks/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/july-2026-windows-security-update-deployment-checks/",
        "slug": "july-2026-windows-security-update-deployment-checks",
        "url": "https://update.dsesecurity.com/updates/july-2026-windows-security-update-deployment-checks/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/july-2026-windows-security-update-deployment-checks.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/july-2026-windows-security-update-deployment-checks/"
        },
        "title": "July 2026 Windows security update: deployment checks for managed environments",
        "summary": "Microsoft’s July 2026 Windows update enforces Kerberos RC4 protections, while a July 18 out-of-band release resolves the limited Dell and Intel IPF compatibility hold.",
        "format": {
            "slug": "briefing",
            "name": "Briefing"
        },
        "priority": {
            "slug": "important",
            "name": "Important"
        },
        "featured": false,
        "image": {
            "theme": "managed-it",
            "label": "Managed IT operations",
            "alt": "A controlled technology lifecycle progressing from assessment to approved production.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/managed-it-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/managed-it-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-07-16T14:00:00+00:00",
        "modified_at": "2026-07-19T19:29:33+00:00",
        "reviewed_on": "2026-07-19",
        "reading_minutes": 3,
        "word_count": 444,
        "potentially_affected": "Supported Windows client and server environments, especially Active Directory workloads with legacy RC4 dependencies and the limited Dell systems identified by Microsoft as using affected Intel IPF drivers.",
        "dse_recommendation": "Review current Microsoft release health, identify RC4 dependencies, confirm device-specific update applicability, pilot representative systems, verify recovery paths, and deploy through controlled waves.",
        "primary_source": {
            "name": "Microsoft Windows message center",
            "url": "https://learn.microsoft.com/en-us/windows/release-health/windows-message-center",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>What Microsoft published</h2>\n<p>Microsoft released the July 2026 security update for supported Windows versions on July 14. The <a href=\"https://learn.microsoft.com/en-us/windows/release-health/windows-message-center\" target=\"_blank\" rel=\"noopener noreferrer\">Windows message center</a> recommends prompt installation and links administrators to version-specific release notes and known-issue status.</p>\n<p>The release also begins the enforcement phase for Kerberos RC4 protections associated with CVE-2026-20833. Microsoft says domain controllers now enforce updated service-ticket behavior, with AES expected for supported configurations. Workloads that still depend on legacy RC4 behavior can experience authentication failures, so service accounts, older applications, appliances, and non-Windows Kerberos integrations need deliberate validation.</p>\n<h2>The limited Dell and Intel hold has been resolved</h2>\n<p>Microsoft initially withheld KB5101650 from a limited number of Dell devices using Intel Innovation Platform Framework drivers. On July 18, Microsoft published <a href=\"https://support.microsoft.com/en-us/servicing/os/windows-11/2026/07/kb5121767-out-of-band\" target=\"_blank\" rel=\"noopener noreferrer\">out-of-band update KB5121767</a> to address the issue and allow the affected devices to move forward.</p>\n<p>Microsoft states that the out-of-band update is intended for devices affected by that specific issue. Eligible devices can receive it through Windows Update; administrators should confirm model, driver, and update applicability rather than deploying an out-of-band package indiscriminately.</p>\n<h2>Why change control still matters</h2>\n<p>Prompt patching and controlled deployment are complementary. The Kerberos change can expose dependencies that were not visible during ordinary operation, while device-specific safeguards and out-of-band releases can change the correct update path for a subset of the fleet. A representative pilot makes those conditions visible before they become a broad service disruption.</p>\n<h2>DSE deployment checklist</h2>\n<ol>\n<li>Inventory supported Windows client and server versions, build numbers, device models, and servicing channels.</li>\n<li>Review Microsoft release health and the release notes for every version in scope.</li>\n<li>Use documented Microsoft guidance and relevant event data to identify accounts, applications, devices, or integrations that still rely on RC4-based Kerberos behavior.</li>\n<li>Confirm which Dell and Intel IPF devices were affected and whether normal Windows Update now offers the applicable resolution.</li>\n<li>Pilot representative domain controllers, servers, workstations, remote users, and line-of-business applications.</li>\n<li>Verify monitoring, current backups, recovery access, and a tested rollback or recovery path before broad deployment.</li>\n<li>Validate authentication, endpoint health, business applications, printing, remote access, and security tooling after installation.</li>\n<li>Record deferred systems, the reason, compensating safeguards, an owner, and a review date.</li>\n</ol>\n<h2>Keep the evidence with the change</h2>\n<p>Record the Microsoft references reviewed, approval, pilot population, observed results, exception list, deployment waves, and post-change validation. That record makes it easier to distinguish a patch issue from an application, identity, driver, or network dependency and supports a safer follow-up if Microsoft changes the release status again.</p>\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://learn.microsoft.com/en-us/windows/release-health/windows-message-center\" target=\"_blank\" rel=\"noopener noreferrer\">Windows message center</a> — Microsoft’s July 14 update and Kerberos enforcement announcements.</li>\n<li><a href=\"https://support.microsoft.com/en-us/servicing/os/windows-11/2026/07/kb5121767-out-of-band\" target=\"_blank\" rel=\"noopener noreferrer\">KB5121767 out-of-band update</a> — Microsoft’s July 18 resolution for the affected Windows 11 devices.</li>\n<li><a href=\"https://learn.microsoft.com/en-us/windows-server/security/kerberos/detect-remediate-rc4-kerberos\" target=\"_blank\" rel=\"noopener noreferrer\">Detect and remediate RC4 usage in Kerberos</a> — Microsoft’s discovery and remediation guidance.</li>\n</ul>",
        "content_text": "What Microsoft published\nMicrosoft released the July 2026 security update for supported Windows versions on July 14. The Windows message center recommends prompt installation and links administrators to version-specific release notes and known-issue status.\nThe release also begins the enforcement phase for Kerberos RC4 protections associated with CVE-2026-20833. Microsoft says domain controllers now enforce updated service-ticket behavior, with AES expected for supported configurations. Workloads that still depend on legacy RC4 behavior can experience authentication failures, so service accounts, older applications, appliances, and non-Windows Kerberos integrations need deliberate validation.\nThe limited Dell and Intel hold has been resolved\nMicrosoft initially withheld KB5101650 from a limited number of Dell devices using Intel Innovation Platform Framework drivers. On July 18, Microsoft published out-of-band update KB5121767 to address the issue and allow the affected devices to move forward.\nMicrosoft states that the out-of-band update is intended for devices affected by that specific issue. Eligible devices can receive it through Windows Update; administrators should confirm model, driver, and update applicability rather than deploying an out-of-band package indiscriminately.\nWhy change control still matters\nPrompt patching and controlled deployment are complementary. The Kerberos change can expose dependencies that were not visible during ordinary operation, while device-specific safeguards and out-of-band releases can change the correct update path for a subset of the fleet. A representative pilot makes those conditions visible before they become a broad service disruption.\nDSE deployment checklist\n\nInventory supported Windows client and server versions, build numbers, device models, and servicing channels.\nReview Microsoft release health and the release notes for every version in scope.\nUse documented Microsoft guidance and relevant event data to identify accounts, applications, devices, or integrations that still rely on RC4-based Kerberos behavior.\nConfirm which Dell and Intel IPF devices were affected and whether normal Windows Update now offers the applicable resolution.\nPilot representative domain controllers, servers, workstations, remote users, and line-of-business applications.\nVerify monitoring, current backups, recovery access, and a tested rollback or recovery path before broad deployment.\nValidate authentication, endpoint health, business applications, printing, remote access, and security tooling after installation.\nRecord deferred systems, the reason, compensating safeguards, an owner, and a review date.\n\nKeep the evidence with the change\nRecord the Microsoft references reviewed, approval, pilot population, observed results, exception list, deployment waves, and post-change validation. That record makes it easier to distinguish a patch issue from an application, identity, driver, or network dependency and supports a safer follow-up if Microsoft changes the release status again.\nOfficial references\n\nWindows message center — Microsoft’s July 14 update and Kerberos enforcement announcements.\nKB5121767 out-of-band update — Microsoft’s July 18 resolution for the affected Windows 11 devices.\nDetect and remediate RC4 usage in Kerberos — Microsoft’s discovery and remediation guidance.",
        "content_markdown": "## What Microsoft published\n\nMicrosoft released the July 2026 security update for supported Windows versions on July 14. The [Windows message center](https://learn.microsoft.com/en-us/windows/release-health/windows-message-center) recommends prompt installation and links administrators to version-specific release notes and known-issue status.\n\nThe release also begins the enforcement phase for Kerberos RC4 protections associated with CVE-2026-20833. Microsoft says domain controllers now enforce updated service-ticket behavior, with AES expected for supported configurations. Workloads that still depend on legacy RC4 behavior can experience authentication failures, so service accounts, older applications, appliances, and non-Windows Kerberos integrations need deliberate validation.\n\n## The limited Dell and Intel hold has been resolved\n\nMicrosoft initially withheld KB5101650 from a limited number of Dell devices using Intel Innovation Platform Framework drivers. On July 18, Microsoft published [out-of-band update KB5121767](https://support.microsoft.com/en-us/servicing/os/windows-11/2026/07/kb5121767-out-of-band) to address the issue and allow the affected devices to move forward.\n\nMicrosoft states that the out-of-band update is intended for devices affected by that specific issue. Eligible devices can receive it through Windows Update; administrators should confirm model, driver, and update applicability rather than deploying an out-of-band package indiscriminately.\n\n## Why change control still matters\n\nPrompt patching and controlled deployment are complementary. The Kerberos change can expose dependencies that were not visible during ordinary operation, while device-specific safeguards and out-of-band releases can change the correct update path for a subset of the fleet. A representative pilot makes those conditions visible before they become a broad service disruption.\n\n## DSE deployment checklist\n\n- Inventory supported Windows client and server versions, build numbers, device models, and servicing channels.\n\n- Review Microsoft release health and the release notes for every version in scope.\n\n- Use documented Microsoft guidance and relevant event data to identify accounts, applications, devices, or integrations that still rely on RC4-based Kerberos behavior.\n\n- Confirm which Dell and Intel IPF devices were affected and whether normal Windows Update now offers the applicable resolution.\n\n- Pilot representative domain controllers, servers, workstations, remote users, and line-of-business applications.\n\n- Verify monitoring, current backups, recovery access, and a tested rollback or recovery path before broad deployment.\n\n- Validate authentication, endpoint health, business applications, printing, remote access, and security tooling after installation.\n\n- Record deferred systems, the reason, compensating safeguards, an owner, and a review date.\n\n## Keep the evidence with the change\n\nRecord the Microsoft references reviewed, approval, pilot population, observed results, exception list, deployment waves, and post-change validation. That record makes it easier to distinguish a patch issue from an application, identity, driver, or network dependency and supports a safer follow-up if Microsoft changes the release status again.\n\n## Official references\n\n- [Windows message center](https://learn.microsoft.com/en-us/windows/release-health/windows-message-center) — Microsoft’s July 14 update and Kerberos enforcement announcements.\n\n- [KB5121767 out-of-band update](https://support.microsoft.com/en-us/servicing/os/windows-11/2026/07/kb5121767-out-of-band) — Microsoft’s July 18 resolution for the affected Windows 11 devices.\n\n- [Detect and remediate RC4 usage in Kerberos](https://learn.microsoft.com/en-us/windows-server/security/kerberos/detect-remediate-rc4-kerberos) — Microsoft’s discovery and remediation guidance."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/july-2026-windows-security-update-deployment-checks/",
                "url": "https://update.dsesecurity.com/updates/july-2026-windows-security-update-deployment-checks/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-07-19"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/july-2026-windows-security-update-deployment-checks/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "July 2026 Windows security update: deployment checks for managed environments",
                        "item": "https://update.dsesecurity.com/updates/july-2026-windows-security-update-deployment-checks/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/july-2026-windows-security-update-deployment-checks/#article",
                "identifier": "https://update.dsesecurity.com/updates/july-2026-windows-security-update-deployment-checks/",
                "url": "https://update.dsesecurity.com/updates/july-2026-windows-security-update-deployment-checks/",
                "headline": "July 2026 Windows security update: deployment checks for managed environments",
                "description": "Microsoft’s July 2026 Windows update enforces Kerberos RC4 protections, while a July 18 out-of-band release resolves the limited Dell and Intel IPF…",
                "abstract": "Microsoft’s July 2026 Windows update enforces Kerberos RC4 protections, while a July 18 out-of-band release resolves the limited Dell and Intel IPF compatibility hold.",
                "articleBody": "What Microsoft published\nMicrosoft released the July 2026 security update for supported Windows versions on July 14. The Windows message center recommends prompt installation and links administrators to version-specific release notes and known-issue status.\nThe release also begins the enforcement phase for Kerberos RC4 protections associated with CVE-2026-20833. Microsoft says domain controllers now enforce updated service-ticket behavior, with AES expected for supported configurations. Workloads that still depend on legacy RC4 behavior can experience authentication failures, so service accounts, older applications, appliances, and non-Windows Kerberos integrations need deliberate validation.\nThe limited Dell and Intel hold has been resolved\nMicrosoft initially withheld KB5101650 from a limited number of Dell devices using Intel Innovation Platform Framework drivers. On July 18, Microsoft published out-of-band update KB5121767 to address the issue and allow the affected devices to move forward.\nMicrosoft states that the out-of-band update is intended for devices affected by that specific issue. Eligible devices can receive it through Windows Update; administrators should confirm model, driver, and update applicability rather than deploying an out-of-band package indiscriminately.\nWhy change control still matters\nPrompt patching and controlled deployment are complementary. The Kerberos change can expose dependencies that were not visible during ordinary operation, while device-specific safeguards and out-of-band releases can change the correct update path for a subset of the fleet. A representative pilot makes those conditions visible before they become a broad service disruption.\nDSE deployment checklist\n\nInventory supported Windows client and server versions, build numbers, device models, and servicing channels.\nReview Microsoft release health and the release notes for every version in scope.\nUse documented Microsoft guidance and relevant event data to identify accounts, applications, devices, or integrations that still rely on RC4-based Kerberos behavior.\nConfirm which Dell and Intel IPF devices were affected and whether normal Windows Update now offers the applicable resolution.\nPilot representative domain controllers, servers, workstations, remote users, and line-of-business applications.\nVerify monitoring, current backups, recovery access, and a tested rollback or recovery path before broad deployment.\nValidate authentication, endpoint health, business applications, printing, remote access, and security tooling after installation.\nRecord deferred systems, the reason, compensating safeguards, an owner, and a review date.\n\nKeep the evidence with the change\nRecord the Microsoft references reviewed, approval, pilot population, observed results, exception list, deployment waves, and post-change validation. That record makes it easier to distinguish a patch issue from an application, identity, driver, or network dependency and supports a safer follow-up if Microsoft changes the release status again.\nOfficial references\n\nWindows message center — Microsoft’s July 14 update and Kerberos enforcement announcements.\nKB5121767 out-of-band update — Microsoft’s July 18 resolution for the affected Windows 11 devices.\nDetect and remediate RC4 usage in Kerberos — Microsoft’s discovery and remediation guidance.",
                "datePublished": "2026-07-16T14:00:00+00:00",
                "dateModified": "2026-07-19T19:29:33+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/july-2026-windows-security-update-deployment-checks/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/july-2026-windows-security-update-deployment-checks/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "July 2026 Windows security update: deployment checks for managed environments"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Briefing",
                    "Important priority"
                ],
                "genre": "Briefing",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 444,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Microsoft Windows message center",
                    "url": "https://learn.microsoft.com/en-us/windows/release-health/windows-message-center"
                }
            }
        ]
    }
}