Windows KB5124010 is Microsoft’s optional September preview update for Windows 11 24H2 and 25H2. It changes how File Explorer previews downloaded files, improves Bluetooth behaviour and remaps the Copilot key, but Microsoft also documents a domain-trust issue that makes staged business deployment more sensible than a fleet-wide rush.
- Disclosure: 22 September 2026
- Builds: 26200.9550 and 26100.9550
- Release type: Optional, non-security preview
Windows KB5124010: what changed
Microsoft’s support record says the update lets File Explorer automatically preview downloaded non-HTML files such as PDFs again. Downloaded HTML remains gated behind a warning and a new Preview anyway button. That split attempts to restore convenience without treating active web content like a passive document.
BleepingComputer independently reported 46 changes, including Bluetooth reliability improvements, support for remapping the Copilot key to Right Ctrl or the context-menu key, and an accessibility option that opens applications maximised. The update also moves 24H2 and 25H2 systems to builds 26100.9550 and 26200.9550.
Why file previews need two trust levels
A preview pane reduces the friction of identifying a file, but downloaded content carries origin risk. PDFs and images can be handled as previewable documents, while HTML can reference scripts, remote resources or misleading layouts. Requiring an explicit acknowledgement for HTML makes the trust boundary visible at the moment it matters.
The self-contained takeaway is this: Windows KB5124010 restores useful file previews while preserving an extra consent step for downloaded HTML, a practical compromise between workflow speed and the higher risk of rendering active web content.
That does not make every downloaded PDF harmless. Organisations should keep browser, endpoint and attachment controls in place. The preview distinction is one layer, not a substitute for malware scanning or user training.
The known issue changes enterprise timing
Microsoft says some Credential Guard-protected machine accounts can lose their secure channel with an on-premises Active Directory domain after the 8 September security update or later releases. Affected users may be unable to sign in with valid domain credentials and may see a trust-relationship error.
Because Windows KB5124010 is optional and contains no security fixes, administrators can test the update before wider deployment. A representative pilot should include domain-joined laptops, Bluetooth audio devices, File Explorer preview workflows and recovery procedures. Rollback instructions should be ready before the ring expands.
Recovery framing: what changed after disclosure
This is a seven-day recovery story using the actual 22 September disclosure date. Later coverage on 24 September does not reset freshness. It does, however, make the deployment consequence clearer: this is a feature and quality preview, not an urgent security patch.
Windows 11 24H2 Home and Pro reach end of updates on 13 October 2026, according to Microsoft. That deadline is separate from this optional preview, but it strengthens the case for administrators to plan version upgrades rather than treating one cumulative package as a long-term maintenance answer.
Facts at a glance
| Item | Verified detail | Source |
|---|---|---|
| Disclosure | 22 September 2026 | Microsoft |
| Builds | 26200.9550 and 26100.9550 | Microsoft |
| Release type | Optional non-security preview | Microsoft/BleepingComputer |
| File preview | PDFs auto-preview; downloaded HTML needs approval | Microsoft |
| Known issue | Some Credential Guard accounts may lose domain trust | Microsoft |
Related Lapaas Voice coverage: Windows Age API sends apps a bracket, not a birthday, Microsoft school AI safety standard becomes binding.
FAQs
What is Windows KB5124010?
It is Microsoft’s September 2026 optional non-security preview update for Windows 11 versions 24H2 and 25H2.
What changes in File Explorer previews?
Downloaded non-HTML files such as PDFs can preview automatically, while HTML files require the user to choose Preview anyway after a warning.
Should businesses deploy KB5124010 immediately?
Because it is optional and Microsoft documents a domain-trust issue affecting some Credential Guard protected accounts, businesses should test it on a representative ring before broad deployment.
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.



