# Microsoft Releases KB5089573 Preview Update for Windows 11: Performance Gains, Secure Boot Refresh, and Windows Hello Enhancements
Microsoft has rolled out KB5089573, its May 2026 non-security preview cumulative update for Windows 11, bringing 30 performance and reliability improvements to versions 25H2 and 24H2. Released on May 27, this optional update represents the company's monthly pattern of introducing tested features and fixes ahead of the standard Patch Tuesday security cycle.
## Overview: What's Included in KB5089573
The KB5089573 update operates outside Microsoft's regular security patch schedule, allowing IT administrators and consumers to evaluate new functionality in a controlled environment before broader rollout. Once installed, affected systems will upgrade to builds 26200.8524 (version 25H2) and 26100.8524 (version 24H2).
Unlike Patch Tuesday cumulative updates, preview releases are entirely optional and carry no security patches. This distinction means organizations can evaluate the update's impact on their infrastructure without the urgency typically associated with security fixes.
## Performance Improvements: App Launch and Core Shell Optimization
Application Launch Acceleration
One of the headline improvements in KB5089573 addresses end-user experience directly. Microsoft reports that the update significantly accelerates app launch times and enhances core shell experiences, particularly affecting the Start menu, Search functionality, and the Action Center. These components represent some of the most frequently accessed features in Windows 11, making performance gains in these areas tangible for daily users.
The optimization effort reflects ongoing refinement of Windows 11's architecture. Since the OS's launch in 2021, performance tuning has remained a priority for enterprise customers—particularly those managing large deployments where startup time aggregates into significant productivity impacts across thousands of machines.
## Windows Hello Improvements: Enhanced Sign-In Security
Default Authentication Method and Behavioral Changes
KB5089573 introduces meaningful changes to Windows Hello authentication behavior. The update establishes biometric authentication—specifically face recognition and fingerprint scanning—as the default sign-in method on lock and login screens. This change applies regardless of the user's previously selected authentication method, representing a shift toward convenience-first security posture.
However, the update acknowledges user preference by allowing fallback to PIN-based authentication. If a user enters their Windows PIN three consecutive times, the system will retain PIN as the active sign-in method until the user manually switches to another method. This balances security with usability.
Additionally, KB5089573 reduces unexpected authentication blocks during Windows Hello Enhanced Sign-In Security processing, a feature introduced in recent Windows 11 builds that adds extra identity verification steps.
## Reliability Enhancements Across System Components
Beyond performance, the update addresses stability concerns in several critical areas:
| Component | Improvement |
|-----------|------------|
| File Explorer | Enhanced reliability and responsiveness |
| Sign-In/Lock Screens | Improved behavior and consistency |
| Settings/Themes | Better handling during theme changes |
| Touch Gestures | Enhanced support for touchscreen devices |
| Modern Standby Resume | Faster and more stable resume from sleep states |
The Modern Standby improvements are particularly significant for mobile workstations and hybrid devices, where power management directly affects battery life and user productivity.
## Power Management and Hardware Integration
Sensor Hub and Battery Optimization
KB5089573 includes updates addressing power consumption across multiple hardware interfaces. The sensor hub—responsible for accelerometers, gyroscopes, and proximity sensors—has been hardened against applications that could keep it unnecessarily powered, leading to battery drain.
Human Interface Device (HID) stack improvements target similar issues, preventing rogue HID transfers during system standby and improving battery life when HID devices malfunction or behave unexpectedly.
Shared Audio Feature
A new feature in this update allows two people to listen to the same audio simultaneously on a single Windows 11 PC—useful in collaborative environments, presentations, and educational settings where shared audio feedback is beneficial.
Task Manager Accuracy
The update corrects CPU speed display in Task Manager's Performance tab for virtual machines. Previously, virtual machines would report higher-than-expected CPU speeds after resuming from hibernation; this fix ensures accurate reporting for both administrators and users monitoring system performance.
## Secure Boot Certificate Rollout: The Security Angle
While not a security update per se, KB5089573 plays a supporting role in an important security maintenance initiative: the replacement of Secure Boot certificates expiring in June 2026.
The original Secure Boot certificates, issued in 2011, are reaching end-of-life. Microsoft is conducting a phased, device-by-device rollout of replacement certificates, with KB5089573 including enhanced targeting data. The company is using "high-confidence device signals" to ensure devices demonstrate successful update history before receiving new certificates, maintaining controlled distribution and reducing the risk of deployment issues.
Devices will only receive new certificates after meeting Microsoft's stability criteria—a precautionary measure reflecting lessons learned from past mass certificate deployments.
## Installation: Voluntary and Accessible
Users and administrators can install KB5089573 through two methods:
1. Automatic (Optional): Users with "Get the latest updates as soon as they're available" enabled will receive the update automatically.
2. Manual: Users can navigate to Settings → Windows Update → Check for Updates and select "Download and install" when prompted.
Because this is an optional preview update, machines without automatic updates enabled will require explicit user action—a distinction that gives organizations control over deployment timing.
---
## HackWire Analysis
While the KB5089573 release reads as routine maintenance, several aspects merit closer examination. First, the timing matters: May's preview cycle typically represents Microsoft's final opportunity to test changes before the June push to general availability. This particular update's focus on performance and reliability—rather than security—suggests confidence in the OS's security posture, but it also underscores that Windows 11 adoption remains incomplete among enterprises concerned with stability over new features.
Second, the Secure Boot certificate refresh deserves attention from a risk perspective. The controlled, phased rollout reflects institutional learning from past certificate deployment failures that have bricked systems. However, the June expiration deadline creates a hard deadline for organizations: devices with expired Secure Boot certificates may face authentication failures or boot restrictions. IT teams managing large Windows 11 fleets should verify their systems are eligible for the new certificates and prepare contingency plans if legacy devices cannot receive the update.
Third, the Windows Hello changes reveal Microsoft's push toward passwordless authentication. Making biometric sign-in default—even while allowing PIN fallback—reflects the industry's move away from password-centric security. For organizations with complex identity governance requirements, this behavioral shift may require policy updates or user communication to prevent confusion or support tickets.
Finally, the absence of security patches in a May update is noteworthy. This indicates Microsoft's main security pushes remain tied to Patch Tuesday. Organizations treating preview updates as optional should ensure they're not delaying critical security patches while waiting for bundled updates.
— HackWire Editorial
---
## Related Coverage