Microsoft has released Windows 10 update KB5120249, bringing new security fixes, expanded Secure Boot certificate deployment and a fix for File History backup failures.
The update applies to Windows 10 versions 22H2 and 21H2, along with Windows 10 Enterprise LTSC 2021 and Windows 10 IoT Enterprise LTSC 2021.
Because Windows 10 has moved into its Extended Security Updates period, KB5120249 does not introduce new features. Its focus is on security maintenance and reliability fixes for supported systems.
Windows 10 KB5120249 key changes
| Area | What changed |
|---|---|
| Secure Boot | Expanded device targeting for new certificates |
| File History | Fixes SMB backup failures caused by incorrect invalid credentials errors |
| Microsoft Defender | Updated as part of the release |
| .NET Framework | Receives accompanying updates |
| Malicious Software Removal Tool | Updated |
| Download size | Just under 1GB |
| Availability | Windows 10 systems enrolled in ESU |
| ESU security coverage | Continues through at least October 2027 |
One of the more important parts of the update involves Secure Boot certificates.
Microsoft is continuing its rollout of replacement certificates to supported Windows devices. KB5120249 adds more high confidence device targeting information, increasing the number of eligible PCs that can automatically receive the newer certificates through Windows Update.
The deployment is expected to continue across supported consumer PCs and unmanaged business systems over the coming months.
File History backup issue has been fixed
KB5120249 also resolves a problem affecting File History backups to network locations.
On affected systems, automatic backups to Server Message Block network shares could fail with an incorrect invalid credentials message. When that happened, scheduled File History jobs would fail to copy any files.
The new update addresses that behavior, allowing affected backup jobs to operate normally again.

This is particularly relevant for people who use a NAS, another Windows PC or another SMB compatible network location for File History backups.
Secure Boot remains an important Windows maintenance issue
The Secure Boot changes are part of a broader effort affecting both Windows 10 and Windows 11.
Older Secure Boot certificates are being replaced, and Microsoft is gradually expanding automatic deployment to compatible devices instead of forcing every system to update at once.
KB5120249 increases coverage for Windows 10 machines that qualify for the automated process.
The update also includes security improvements outside Secure Boot, along with updates for Microsoft Defender, the .NET Framework and the Windows Malicious Software Removal Tool.
You need Extended Security Updates to receive the patch
Windows 10 standard security support ended in October 2025, so most consumer PCs still running the operating system now need to be enrolled in the Extended Security Updates program to continue receiving patches such as KB5120249.
The ESU program provides continued security updates through at least October 2027.
The update should install automatically on eligible systems when Windows Update makes it available. It can also be installed manually, and the download is just under 1GB.
For anyone remaining on Windows 10, KB5120249 is primarily a maintenance release, but the Secure Boot certificate work and File History fix make it more important than a routine background patch.



Discussion (0)
Be the first to comment.