文章

Announcing Windows 11 Insider Preview Build 25905

What’s new in Build 25905

Rust in the Windows Kernel

Rust offers advantages in reliability and security over traditional programs written in C/C++. This preview shipped with an early implementation of critical kernel features in safe Rust. Specifically, win32kbase_rs.sys contains a new implementation of GDI region. While this is a small trial, we will continue to increase the usage of Rust in the kernel. Stay tuned!

[We are beginning to roll this out, so the experience isn’t available to all Insiders in the Canary Channel just yet as we plan to monitor feedback and see how it lands before pushing it out to everyone.]

Arm32 UWP App deprecation

Starting in this Insider Preview build in the Canary Channel, we have removed support for Arm32 UWP applications from Windows on Arm, as documented here: Windows 11 Specs and System Requirements. After the OS upgrade, any installed Arm32 applications will no longer launch on your device. Note that this does not affect Arm64 applications.

  • During setup, you will see a message with a list of applications that are currently Arm32 installed on the system.

  • In many cases, the list of impacted applications will be reduced by manually forcing the Microsoft Store to install any pending application updates prior to the OS upgrade. To do this, launch the Microsoft Store application, choose “library”, then click on the “Get Updates” button.

  • After the OS upgrade is complete, to fix any Arm32 applications, you will need to manually uninstall then reinstall those applications from the Microsoft Store. By doing so, you will install a compatible version that will run on your device.

New PostAuthenticationAction support for terminating individual processes in Windows LAPS

Thank you everyone who gave us feedback on the new Windows Local Administrator Password Solution feature which we shipped a few months ago. Several customers pointed out that the new Post Authentication Actions feature (PAA) only handled termination of interactive logon sessions. This meant that PAA was not able to terminate specific individual processes that were launched in an OTS (over-the-shoulder) elevation scenario, for example using runas.exe. We are announcing an improvement with this build that addresses this feedback on that limitation. A new option has been added to the PostAuthenticationActions Group Policy in this Insider Preview build:

20230712_Insider_release_PAA_specific_processes-1024x919.png

The new option is described as “Reset the password, logoff the managed account, and terminate any remaining processes”. This new option is basically a superset of the previous “Reset the password and logoff the managed account” option. When the new setting is configured, PAA will first notify and then terminate any interactive logon sessions, followed by enumerating and terminating any remaining processes that are still running under the Windows LAPS-managed local account identity. No notification precedes this termination.

In addition, we’ve greatly expanded the event logging messages that are emitted during post-authentication-action execution, to give you deeper insights into exactly what was done during the operation.

Note: “Reset the password and logoff the managed account” remains the default PAA action.

SMB Updates [Added 7/13]

Beginning with Build 25905 for the Pro and Education editions of Windows 11, SMB signing is now required by default for all connections. This the same behavior change first added in Build 25381 for the Enterprise editions. This changes legacy behavior, where Windows 10 and 11 required SMB signing by default only when connecting to shares named SYSVOL and NETLOGON and where Active Directory domain controllers required SMB signing when any client connected to them. This is part of a campaign to improve the security of Windows and Windows Server for the modern landscape.

For more information on this change, visit https://aka.ms/SMBSigningOBD

Recover your PC from Windows Update [Added 7/13]

A new Windows Update recovery feature in this build under Settings > System > Recovery and “Fix Problems using Windows Update”. On eligible Insider Channels such as the Canary Channel today, this feature will download and install a repair version of the OS. This operation reinstalls the OS that you have and will not remove any files, settings, or apps. The repair content is displayed on the Windows Update Settings page with the title appended with “(repair version)”. This capability can be useful in many instances but is intended to be used for keeping the device secure and up to date. Devices may need to complete in progress updates prior to this process taking effect.

emoji-colrv1-b-1024x609.png

Changes and Improvements

[General]

  • [ADDED 7/13] Starting with this build, we have adjusted the prerequisites (removal of Modern Standby/HSTI validation and untrusted DMA ports check) for enabling device encryption so that it is automatically enabled when doing clean installs of Windows 11.

[Emoji]

  • With the update of our color font format to COLRv1, Windows is now able to display richer emoji with a 3D like appearance with support coming soon to some apps and browsers. These emoji use gradients to bring the design style that our customers have been asking for. The new emoji will bring more expression to your communications.

wu-recovery-option-1024x678.png

[Zune]

  • In celebration of Marvel Studio’s Guardians of the Galaxy Volume 3, we temporarily re-launched Zune.net last month. We also took the opportunity to fix an issue that was causing some challenges in getting the original Zune drivers to install in Windows 11 with this build in the Canary Channel. So now it should be easier to use your (totally unsupported and still discontinued) Zune on Windows 11. Over time, the fix will make its way through the Insider Channels and eventually to all Windows 11 customers. For fun, check out how Scott Hanselman brought a few Zunes back to life.

Microsoft Store Update

Windows Insiders in all channels running version 22306.1401.x.x of the Microsoft Store and higher will see the following improvements rolling out:

More pricing information: To help you with your purchase decisions, you’ll now see information about the lowest price products have dropped to in the past 30 days.

Introducing AI Hub: Explore a new curated section in the Microsoft Store where we will promote the best AI experiences built by the developer community and Microsoft. This is a space where we will educate customers on how to start and expand their AI journey, inspiring them to use AI in everyday ways to boost productivity, spark creativity and so much more.

FEEDBACK: Please file feedback in Feedback Hub (WIN + F) under Microsoft Store.

Known issues

  • [NEW] This build will not be offered to some ASUS devices or PCs with ASUS motherboards due to an issue causing a bugcheck when attempting to update to this build.

  • [NEW] Ethernet-connected devices may lose network connectivity after updating to this build. Unplugging the ethernet cable and re-plugging the cable in should resolve the issue.

License:  CC BY 4.0