Windows 11 25H2 BitLocker recovery fix (KB5089549)
Security Patch Release
Summary
Hide ▲
Show ▼
Microsoft shipped KB5089549 for Windows 11 25H2 to fix a BitLocker Recovery problem that could trap devices after the April 2026 security updates. The issue involved certain TPM validation settings and could force users to enter a recovery key at restart. Windows 10 and Windows Server are still waiting for a permanent fix, so administrators must rely on temporary policy changes until a broader update arrives. The patch matters because it restores boot access for enterprise-managed systems that were getting stuck in recovery mode.
Related Happenings
Microsoft BitLocker hardware-accelerated rollout in Windows 11
Security Tool/Service
First: 23.12.2025 22:03
Last: 23.12.2025 22:03
Sources 1
About this happening:
Microsoft is rolling out **hardware-accelerated BitLocker** in **Windows 11**, improving **encryption performance** and **key protection** on supported devices. The new mode offlo...
Microsoft BitLocker hardware-accelerated rollout in Windows 11
Security Tool/ServiceAbout this happening: Microsoft is rolling out **hardware-accelerated BitLocker** in **Windows 11**, improving **encryption performance** and **key protection** on supported devices. The new mode offlo...
Windows 11 password sign-in icon disappears after KB5064081 updates
Service Disruption
First: 28.11.2025 20:07
Last: 28.11.2025 20:07
Sources 1
About this happening:
Microsoft's **Windows 11** updates since **August 2025** are causing the **password sign-in icon** to disappear from the **lock screen**, creating a login usability disruption for...
Windows 11 password sign-in icon disappears after KB5064081 updates
Service DisruptionAbout this happening: Microsoft's **Windows 11** updates since **August 2025** are causing the **password sign-in icon** to disappear from the **lock screen**, creating a login usability disruption for...
Microsoft Windows 11 FIDO2 sign-in may prompt for PIN after WebAuthn-aligned updates
Security Tool/Service
First: 26.11.2025 16:43
Last: 26.11.2025 16:43
Sources 1
About this happening:
**Windows 11** FIDO2 sign-ins may now prompt users to create or enter a **PIN** after recent **WebAuthn**-aligned updates, changing passwordless authentication behavior on managed...
Microsoft Windows 11 FIDO2 sign-in may prompt for PIN after WebAuthn-aligned updates
Security Tool/ServiceAbout this happening: **Windows 11** FIDO2 sign-ins may now prompt users to create or enter a **PIN** after recent **WebAuthn**-aligned updates, changing passwordless authentication behavior on managed...
Windows 10 KB5072653 ESU install error fix
Security Patch Release
First: 18.11.2025 02:22
Last: 18.11.2025 02:22
Sources 1
About this happening:
Microsoft released **KB5072653** for **Windows 10 ESU** to fix **0x800f0922** installation failures, restoring access to the **November 2025** extended security update. The out-of...
Windows 10 KB5072653 ESU install error fix
Security Patch ReleaseAbout this happening: Microsoft released **KB5072653** for **Windows 10 ESU** to fix **0x800f0922** installation failures, restoring access to the **November 2025** extended security update. The out-of...
Microsoft 365 desktop app installs on Windows blocked by misconfigured authentication components
Service Disruption
First: 17.11.2025 16:54
Last: 17.11.2025 16:54
Sources 1
About this happening:
A **misconfiguration** in newly released authentication components is blocking **Microsoft 365 desktop app** installs on **Windows devices**, leaving some customers unable to comp...
Microsoft 365 desktop app installs on Windows blocked by misconfigured authentication components
Service DisruptionAbout this happening: A **misconfiguration** in newly released authentication components is blocking **Microsoft 365 desktop app** installs on **Windows devices**, leaving some customers unable to comp...
Timeline
-
13.05.2026 18:42 1 articles · 14d ago
Microsoft acknowledges BitLocker recovery prompts on Windows 10, Windows 11, and Windows Server
Initial DisclosureMicrosoft acknowledged a BitLocker recovery issue affecting Windows 10, Windows 11, and Windows Server devices with an unrecommended BitLocker Group Policy configuration, warning that affected systems could prompt users to enter the BitLocker recovery key on the first restart after installing the April 2026 security update (KB5083769).
Show sources
- Microsoft fixes BitLocker recovery issue only for Windows 11 users — www.bleepingcomputer.com — 13.05.2026 18:42
-
13.05.2026 18:42 2 articles · 14d ago
Microsoft releases KB5089549 for Windows 11 25H2 to fix BitLocker recovery
Mitigation Patch UpdateMicrosoft addressed the BitLocker recovery issue with the KB5089549 cumulative update for Windows 11 25H2, fixing cases where devices might enter BitLocker Recovery after updating boot files on systems with certain Trusted Platform Module (TPM) validation settings, including invalid PCR7 configurations; Windows 10 and Windows Server remain pending a future update.
Show sources
- Microsoft fixes BitLocker recovery issue only for Windows 11 users — www.bleepingcomputer.com — 13.05.2026 18:42
- Microsoft fixes BitLocker recovery issue only for Windows 11 users — www.bleepingcomputer.com — 13.05.2026 18:42