Improvements and fixes
This update includes quality improvements. No new operating system features are being introduced in this update. Key changes include:
Addresses issue where some customers on a small subset of older AMD processors get into an unbootable state.
Addresses issue with printing PDFs in Microsoft Edge.
Addresses issue with the App-V package folder access that cause the access control list to be handled incorrectly.
Addresses issue where backwards compatibility for managing Microsoft User Experience Virtualization (UE-V) with group policy is lost. Windows 10 version 1607 group policy isn't compatible with Windows 10 version 1703 or higher group policy. Because of this bug, the new Windows 10 Administrative Templates (.admx) cannot be deployed to the Group Policy Central Store. This means that some of the new, additional settings for Windows 10 aren't available.
Addresses issue where some Microsoft-signed ActiveX controls don't work when Windows Defender Application Control (Device Guard) is enabled. Specifically, class IDs related to XMLHTTP in msxml6.dll don't work.
Addresses issue where, when attempting to change the Smart Card for Windows service start type from Disabled to Manual or Automatic, the system reports an error: “Cannot create a file when that file already exists.”
Addresses issue where some applications are blocked from running by Windows Defender Device Guard or Windows Defender Application Control when the application runs in Audit only enforcement mode.
- Addresses issue where the virtual TPM self-test isn't run as part of virtual TPM initialization.
- Addresses issue with NoToastApplicationNotificationOnLockScreen GPO that causes Toast notifications to appear on the lock screen.
- Addresses issue originally called out in KB4056891 where calling CoInitializeSecurity with the authentication parameter set to RPC_C_AUTHN_LEVEL_NONE resulted in the error STATUS_BAD_IMPERSONATION_LEVEL.
- Addresses issue where an Azure point-to-site VPN connection that uses IKEv2 may fail when the user's device contains a large number of trusted root certificates.
If you installed earlier updates, only the new fixes contained in this package will be downloaded and installed on your device.
For more information about the resolved security vulnerabilities, see the Security Update Guide.
Known issues in this update
Because of an issue that affects some versions of antivirus software, this fix applies only to computers on which the antivirus ISV updated the ALLOW REGKEY.
This issue is resolved in KB4088782.
|After installing this update, some users may experience issues logging into some websites when using third-party account credentials in Microsoft Edge.||This issue is resolved in KB4074592.|