Microsoft’s optional July update for Windows 11, KB5101684, landed on July 28, smoothing over Start menu and taskbar reliability gremlins while quietly patching a critical flaw that blocked corporate access for Intune-managed PCs. The preview release, available now for both version 24H2 and the newer 25H2, is not a security update—but it addresses a laundry list of daily annoyances and one silent showstopper that IT administrators will celebrate.

A Closer Look at the Fixes

The headline attraction, as PCWorld first highlighted, is the performance and responsiveness boost for the Start menu and taskbar. Microsoft’s official notes are more concrete: the update improves reliability when the Start menu and taskbar load at boot, preserves your chosen Start menu view preferences more consistently, and fixes keyboard navigation when the focus lands on the apps list. On touch-first devices in tablet posture, the system tray on the taskbar now loads more reliably.

Build numbers bump to 26100.8973 for 24H2 and 26200.8973 for 25H2 after applying this patch. The changes aren’t flashy, but they target the shell components that grind against muscle memory every single day.

File Explorer Gets Practical Tweaks

File Explorer’s Details view finally respects your sanity: file sizes now display in appropriate units (KB, MB, GB) instead of vomiting everything in raw kilobytes. You can also middle-click a folder in the address bar or on the Home page to open it in a new tab—a small addition that power users have craved.

Search Learns to Tolerate Typos

Windows Search received a quiet intelligence upgrade. It now better recognizes partial application names and is more forgiving of typos when you’re hunting for an installed program. Settings results also rank more relevant options higher, so you spend less time scrolling past junk results.

Explorer.exe Reliability Across the Board

Microsoft says the update improves explorer.exe stability across Jump Lists, recent files, sharing, Task View, and multiple desktops. These are the invisible fixes that prevent File Explorer from randomly crashing or hanging when you right-click a taskbar icon or switch virtual desktops.

The Intune Compliance Nightmare Ends

For IT departments, the most urgent fix is for newly provisioned or recovered devices enrolled in mobile device management (MDM) services such as Microsoft Intune. Machines running Windows releases dated July 14, 2026 or later could remain incorrectly marked as noncompliant after enrollment, blocking access to corporate resources. KB5101684 resolves this false-positive compliance failure, which could silently cripple deployment workflows.

Other Hidden Repairs

  • DFS mapped drives: If a device started offline and later reconnected, files from DFS shares were wrongly tagged as Internet-originated, triggering Mark of the Web warnings and preview pane blockades. That’s fixed.
  • File History to SMB: Backups to SMB network shares that failed with a bogus invalid-credentials error now work again.
  • Secure Boot certificates: The update includes additional targeting data to expand automatic deployment of new Secure Boot certificates. Original certificates began expiring in June 2026, but Microsoft assures that affected systems can still boot and receive normal updates while the new certs roll out gradually.

Why This Update Matters for Your PC

For Everyday Users

If you’ve cursed a sluggish Start menu, watched File Explorer show a 2GB file as “2,097,152 KB,” or typed “Phootoshop” and got no results, this update quietly erases those papercuts. The middle-click tab support and search improvements alone make it worth grabbing early, especially if you live inside File Explorer.

There’s no dramatic speed guarantee—the performance boost depends on your hardware’s age and configuration—but even on newer devices, the reduced latency in shell interactions is noticeable. The update is not security-related, so there’s no immediate risk to skipping it, but the quality-of-life bump is genuine.

For IT Administrators

The Intune compliance fix is non-negotiable. If your organization provisions Windows 11 devices with July 2026 or later base images, you will hit this false noncompliance wall without KB5101684. Apply it to pilot groups immediately and verify that freshly enrolled devices report compliance correctly.

The DFS Mark of the Web bug could also silently trigger support tickets from users who can’t open innocuous files from shared drives. Patching now saves those headaches. And if you use File History to SMB shares, the credential error fix restores a backup safety net that may have been broken without obvious alerts.

The Backstory

Windows 11’s Start menu and taskbar have been a rehabilitation project since launch. Early 2026 updates tackled performance regressions, but lingering jank during session startup persisted. Microsoft has been incrementally patching shell reliability via monthly previews, and KB5101684 is the latest in that thread.

The Intune false compliance issue, by contrast, is a recent regression tied to the July 14, 2026 servicing baseline. It flew under the radar because it required specific enrollment timing, but for affected orgs, it was a zero-day workflow blocker.

The Secure Boot certificate rollout has been a multi-year saga. With certificates expiring since June 2026, Microsoft has been drip-feeding updated certs via servicing updates. KB5101684’s “additional targeting data” is the next step to widen deployment, ensuring older firmware trusts newer Windows boot components.

Should You Install It Now?

Yes, with a small asterisk. This is an optional, non-security preview—the same fixes will arrive automatically on August’s Patch Tuesday. If you’re running a production-critical machine and can’t afford any unexpected behavior, waiting two weeks is prudent. Microsoft reports no known issues with this build at publication time, but preview updates occasionally surface edge-case bugs that get squashed before the wider rollout.

For everyone else, the daily usability improvements are worth the early install. Home users can grab it by heading to Settings > Windows Update > Advanced options > Optional updates and selecting KB5101684. IT admins can also pull the standalone package from the Microsoft Update Catalog for offline deployment.

After applying, the update requires a restart. Once back in, test the Start menu responsiveness, try a middle-click in File Explorer, and marvel at human-readable file sizes.

What’s Next

August’s security update will bake these fixes into the mandatory servicing channel, so even the cautious will get them soon. Expect further Secure Boot certificate deployment progress in coming months, and watch for additional shell refinements as Microsoft continues its quiet war on interface friction.

If the Intune issue affected your org, monitor the Microsoft Intune admin center after patching to confirm compliance states flip correctly. Any lingering problems should be reported through your support channel immediately—this fix’s effectiveness in diverse environments will be the real test.