Automatically translated.View original post

New update, there are more bugs 🚨

Microsoft has already acknowledged that the Windows update around Patch Tuesday in April 2026 has a problem that could cause some machines to bounce into the BitLocker Recovery screen unexpectedly. Both boot episodes previously worked normally.

.

The main relevant updates are KB5083769 and KB5082052 on Windows 11, while Windows 10 and some versions of Windows Server are also affected. The cause of the problem is not all machines, but they are found on BitLocker-enabled devices on system drives. And there are some Group Policy settings associated with TPM and Secure Boot, especially the PCR7 values often found on enterprise machines.

.

Microsoft explains that this problem is caused by some settings that are not recommended. This results in the system viewing the boot environment as changing, so it calls the user to fill in the BitLocker Recovery Key. But in most cases, only one fill is finished, does not repeat every time it is turned on, and does not directly affect the local data except it does not remember the key.

.

The recommended solution is for administrators to adjust the associated Group Policy value back to its default (Not Configured) and then reorder the policy update, suspending and enabling BitLocker to automatically return to the PCR profile specified by Windows. Known Issue Rollback (KIR) can also be used to avoid problems before installing the update.

.

Overall, users may not have many opportunities for problems, but for machines that are in the organization or have deep security settings, check well before installing this round of updates, because even though they are security patches, they can also affect existing system settings.

.

Source: Neowin

# IT should know # IT News # Includes IT matters # IT

4/21 Edited to

... Read moreจากประสบการณ์ที่เคยใช้ Windows 11 พร้อมเปิดฟีเจอร์ BitLocker บนเครื่องทำงาน พบว่าอัปเดตแพตช์ตามรอบ Patch Tuesday มีผลกระทบบางครั้ง โดยเฉพาะถ้าตั้งค่าความปลอดภัยเชิงลึกอย่าง Group Policy ที่เกี่ยวข้องกับ TPM และ Secure Boot อยู่ก่อนหน้านี้ ทำให้เครื่องบูตเข้า BitLocker Recovery Screen โดยไม่คาดคิด การร้องขอ Recovery Key ซึ่งส่วนตัวเคยเผลอลืมเก็บคีย์นี้ไว้ในบัญชี Microsoft ทำให้เกิดอาการลำบากพอสมควร แนะนำว่า ก่อนติดตั้งอัปเดตแพตช์ ควรตรวจสอบการตั้งค่า Group Policy ที่เกี่ยวข้องและกลับค่าเป็น Not Configured ตามคำแนะนำของ Microsoft จากนั้นสั่งให้ระบบอัปเดตนโยบายใหม่ พร้อมกับการ Suspend และ Enable BitLocker ใหม่ เพื่อรีเซ็ตค่า PCR7 ให้กลับมาตรงตามค่ามาตรฐาน Windows วิธีนี้ช่วยลดโอกาสที่จะเจอหน้าจอ Recovery ซ้ำอีกได้เยอะมาก นอกจากนี้ Known Issue Rollback (KIR) ก็เป็นทางเลือกที่ดีสำหรับองค์กรที่ต้องการเลี่ยงปัญหานี้ก่อนติดตั้งอัปเดตโดยตรง ผมได้ทดลองใช้ KIR ในเครื่อง Test ของบริษัทก่อนแล้ว พบว่าสถานการณ์บูตเครื่องดำเนินไปปกติ ไม่เด้งเข้า BitLocker Recovery ช่วยลดความกังวลเรื่องเวลางานสูญเสียง่าย สำหรับผู้ใช้ทั่วไปที่ไม่ได้มีการตั้งค่าความปลอดภัยลึกซึ้ง อาจไม่เจอปัญหานี้มากนัก แต่ถ้าเริ่มเห็นหน้าจอ Recovery ขึ้นมาตอนบูต แนะนำให้เตรียมคีย์ Recovery ให้พร้อม และตรวจสอบนโยบายความปลอดภัยก่อนติดตั้งอัปเดตในแต่ละรอบ จะช่วยให้ใช้งาน Windows ได้อย่างราบรื่นยิ่งขึ้น