P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

September Windows updates quietly stop File History backups; Entra's 1 February SMS cut-off has no opt-out

Microsoft says September's Windows updates can stop File History backups, with a false drive warning and no fix date. Separately, Entra ID stops sending SMS and voice codes on 1 February 2027, and enforcement has no opt-out.

By Parminder Kumar Sharma · · 18 min read

Editorial illustration for the briefing: September Windows updates quietly stop File History backups; Entra's 1 February SMS cut-off has no opt-out

Eleven days, five known issues, and a backup that stops without saying so

Microsoft shipped KB5124008 on 8 September 2026. On 19 September, eleven days later, it added a fifth known issue to that update's release notes: File History might stop working. The same entry now sits on the release notes for every September client update from Windows 10 Enterprise LTSB 2016 to Windows 11 26H1. The other four known issues listed on KB5124008 are the domain trust failure this site covered on 17 September, USB audio failures, Hyper-V Plan9 folder shares, and Remote Desktop Services instability.

So the File History fault comes from the same Windows 11 24H2 and 25H2 update as the domain trust problem. It is the second September regression this site has written up, but the fifth that Microsoft has attached to KB5124008, and it reaches further, into Windows 10 and Windows 11 23H2 through their own September packages.

Here is what that count does not establish. It says nothing about how many devices are affected: Microsoft says "some customers". It says nothing about the cause, which Microsoft has not given. And the symptom that matters most for anyone who relies on File History is described in one ambiguous line: previously backed up files "might show 'No previous version available'". Microsoft does not say whether the copies on the backup drive are intact, damaged or gone. This briefing treats that as unknown, because it is.

The second notice is quieter but has a date attached. On 18 September Microsoft posted Message Center item MC1474104, reminding workforce tenants that SMS first-factor sign-in in Microsoft Entra ID ends on 1 February 2027. That sits beside a larger change Microsoft announced in July: from the same date it stops delivering SMS and voice codes itself. From today, 21 September, that is 133 days. Microsoft's own documentation says of enforcement: "There is no opt out". It also says customers will not be locked out. Both statements are true, and the gap between them is where the planning work sits.

File History: what Microsoft has put on the record

The primary record is the known issue text that Microsoft added on 19 September to each September update's support page. The wording is identical on all six pages we read. It says some customers "might be unable to create or update backups", that devices "might incorrectly display a 'Reconnect your drive' message even when a compatible backup drive is connected and functioning properly", that the "Last Backup" timestamp "might not update", and that Event Viewer "might record application crash events referencing FileHistory.exe and KERNELBASE.dll". The resolution reads, in full, that Microsoft "is working on a resolution for this issue in a future Windows update".

September 2026 updates carrying the File History known issue. Source: Microsoft support pages for each KB, change logs dated 19 September 2026.

Windows versionSeptember updateKnown issue listed?
Windows 11 26H1KB5124012 (build 28000.2954)Yes
Windows 11 25H2 and 24H2KB5124008 (builds 26200.9445, 26100.9445)Yes
Windows 11 23H2KB5122880Yes
Windows 10 ESU (22H2) and Enterprise LTSC 2021 (21H2)KB5122878 (builds 19045.7725, 19044.7725)Yes, in both sections
Windows 10 Enterprise LTSC 2019KB5122876Yes
Windows Server 2019KB5122876No, not in the Server section
Windows 10 Enterprise LTSB 2016KB5123099Yes
Windows Server 2016KB5123099No, not in the Server section

Three details in the record are worth an administrator's attention. First, the shared KB pages for Windows Server 2019 and 2016 list the issue only under the client LTSC and LTSB sections, not under Server. Microsoft has not said servers are unaffected; it has simply not listed them. Second, every page, including those for 26H1, 23H2 and Windows 10, says the problem follows "the September 2026 Windows security update KB5124008". That is the Windows 11 24H2 and 25H2 package, so on the other versions' pages the reference appears to be a copy error. Search your patch tooling for the KB that actually applies to each build. Third, the out-of-band update of 14 September for 24H2 and 25H2, KB5129195, does not mention File History at all, even though Microsoft says that package "is cumulative". Nor does the Windows 10 equivalent, KB5129236. Whether devices on KB5129195 are affected is not stated. The sensible reading is that they are, because they carry the September changes, but that is our inference.

Does it fail silently? Mostly yes, and where it speaks, it points the wrong way

The house view on backups is simple. A backup that fails silently is worse than no backup at all, because the person relying on it believes they are covered and behaves accordingly. So the question for this fault is not whether File History breaks. It is whether anyone would notice.

Each File History symptom Microsoft lists, set against what it tells the user. Source: KB5124008 known issue text, 19 September 2026; Microsoft File History support pages.

Symptom Microsoft listsWhat the user is toldDoes it reveal the real fault?
Backups cannot be created or updatedNothing, unless another symptom appearsNo
"Reconnect your drive" messageThe drive is disconnectedNo. It is false and blames working hardware
"Last Backup" timestamp stops movingOnly visible if someone opens File HistoryOnly on inspection
Crash events for FileHistory.exe and KERNELBASE.dllOnly visible in Event ViewerOnly on inspection
"No previous version available" on backed-up filesSeen when trying to restoreYes, at the worst possible moment

So, plainly: this fault fails quietly for most users. Nothing in Microsoft's description is a clear error that says "your backup has stopped". Where the device does say something, it tells the user their drive is missing when it is plugged in and working. Two of the other symptoms show up only if someone goes looking. The last shows up when a user needs a file back and finds no versions. Microsoft uses "might" throughout, so not every affected device will show every symptom. That makes the silent case more likely, not less.

Diagram of File History after the September 2026 updates. Four symptoms Microsoft lists lead to what the user is told: failed backups produce no message; a false Reconnect your drive prompt blames a working drive; a stale Last Backup time and FileHistory.exe crash events are visible only if someone checks. The failure is found at restore, when No previous version available appears. A footer lists what Microsoft has not stated, including cause, scale and a fix date.
Drawn from Microsoft's File History known issue text on the September 2026 KB pages, added 19 September 2026.

A comforting label is not a control

The "Reconnect your drive" message is a friendly name for a condition that is not happening. That matters because Microsoft's own troubleshooting page for that message tells users backing up to a network location to open File History and "reselect the network". Separately, Microsoft's File History set-up guide says that when you choose a drive, "If prompted, you can choose to move existing files to the new drive or start fresh." A user on an affected device who follows Microsoft's standard advice in good faith is being walked towards reconfiguring a backup that was never disconnected. At that point one wrong click could start again from nothing. Microsoft's known issue text does not warn about this interaction. We are flagging it as a risk, not a documented outcome.

"Last Backup" is the other comforting label. A date on a settings page looks like evidence of protection. It is only evidence if someone reads it and knows what date it ought to show. On affected devices it simply stops. File History is set up per device in Control Panel. Microsoft's pages describe no central signal an administrator would see; every symptom they list is on the device itself.

What Microsoft has not said about File History

File History known issue: what is on the record and what is not. Source: Microsoft KB pages for the September 2026 updates, read 21 September 2026.

QuestionStatedNot stated
Which updatesSix September KB packages (table above)Whether the 14 September out-of-band updates are affected
What breaksNew and updated backups; false reconnect prompt; stale timestamp; crash eventsThe cause
How many devices"Some customers"Any number or pattern
Existing backupsFiles "might show 'No previous version available'"Whether copies already on the drive are intact
WorkaroundNone givenAny interim step
Known Issue RollbackNot mentionedWhether one is possible
Fix"A future Windows update"A date or a target release
ServersNot listed under Server 2016 or 2019Whether servers with File History enabled are affected

The absence of a Known Issue Rollback is not proof that Microsoft cannot issue one. It means the record does not mention one, and administrators should not plan around it.

Why uninstalling the update is the wrong fix

The tempting response is to remove the September update from machines that depend on File History. Microsoft does not suggest this, and the cost is real. CISA's Known Exploited Vulnerabilities catalogue added two Windows flaws on 8 September 2026, CVE-2026-81963 and CVE-2026-85880. Both have a federal remediation due date of 22 September, which is tomorrow. September's Windows updates are where Microsoft fixed them. Our 17 September briefing set out the details. Check which of the two apply to each build you run, but do not trade a working backup for an exposed endpoint. The better answer is a second, independent backup while File History is unreliable.

Entra ID: two retirements on one date, not one

BleepingComputer's report of the Message Center post runs two separate changes together. Microsoft's own pages keep them apart, and the difference decides what you can do about each.

The first is SMS first-factor sign-in. This is the frontline-worker feature where a user types a phone number, receives a code, and signs in with no username or password. Microsoft's set-up page says it is "not recommended for Information workers". MC1474104, published 18 September, says that "Beginning February 1, 2027, SMS first-factor sign-in will be retired" for tenants in the Worldwide and GCC environments. It adds that "Existing SMS first-factor sign-in configurations will no longer be honored", and that sign-in attempts this way "will be blocked". Crucially, the retirement "applies even when you use Choose Your Own Telephony Provider". There is no paid route to keep it. Microsoft already switched it off for Entra ID Free tenants on 11 August 2026 (MC1448374).

The second is Microsoft-provided SMS and voice for multifactor authentication and self-service password reset. Microsoft's retirement page, last updated 16 September, says that from 1 February 2027, "Microsoft-provided telecom delivery for SMS and voice will be retired for all users except Global Administrators and external users". Those two groups follow on 1 July 2027. Internal guest users stay on the February date. The FAQ confirms the retirement "applies across Entra, including SSPR". Organisations that need SMS or voice can buy delivery from a third-party telecom provider through the Microsoft Security Store. Microsoft said provider information would be published from 18 September, and configuration opens on 30 October 2026.

The two retirements compared. Sources: MC1474104 and MC1448374 (Message Center text via the mc.merill.net archive); Microsoft Learn retirement page and FAQ, updated 16 September 2026.

AspectSMS first-factor sign-inMicrosoft-provided SMS and voice (MFA, SSPR)
Retirement date1 February 2027 (Free tenants: 11 August 2026)1 February 2027; 1 July 2027 for Global Administrators and external users
Environments namedWorldwide and GCCPublic cloud only; others "on a later schedule"
Paid telecom route to keep itNoYes, customer-managed provider via Security Store, per-message cost
Opt-out from enforcementNot stated; configurations "no longer honored"No: "There is no opt out for enforcement"
What users see after the dateSign-in attempt blockedBlocking passkey registration prompt if SMS or voice is their only MFA method
Timeline of Entra ID SMS and voice retirement dates: 11 August 2026 Free tenants lose SMS sign-in; 1 September passkeys default; 18 September provider details due; 30 October provider set-up opens; 4 January 2027 latest advised set-up; 1 February 2027 Microsoft SMS and voice and SMS sign-in retired, opt-out ends, blocking prompts; 1 July 2027 Global Administrators and external users. Today, 21 September 2026, is marked; 1 February is 133 days away.
Dates from Microsoft Learn's retirement page and FAQ (updated 16 September 2026), MC1426371, MC1448374 and MC1474104. Day counts are our arithmetic.

What Microsoft requires, and what it only recommends

The coverage reads as though every user must be on a phishing-resistant method by 1 February. Microsoft's documents do not say that. They enforce something narrower, and recommend something broader.

Required versus recommended in Microsoft's Entra SMS and voice changes. Sources: Microsoft Learn retirement page and FAQ; MC1426371; MC1474104; Microsoft Security blog, 13 July 2026.

ItemEnforced by date?What Microsoft's text says
Microsoft stops sending SMS and voice codesYes, 1 Feb 2027 (1 Jul 2027 for GAs, external users)"There is no opt out for enforcement"
SMS first-factor sign-in endsYes, 1 Feb 2027Configurations "will no longer be honored"
Users with only SMS or voice must register a passkeyYes, after their retirement dateBlocking prompt; "no opt out"
Passkeys auto-enabled, registration nudgesDefault from 1 Sep 2026, rolling out graduallySkippable, unlimited snoozes; temporary opt-out until 1 Feb 2027
Move everyone to phishing-resistant methodsNoRecommended: "We strongly recommend"
Retire Authenticator push, OATH codes, external MFANoNot part of this retirement; FAQ answers "No" for external MFA
Set up a telecom provider four weeks earlyNoRecommended: "at least 4 weeks before" 1 February

Read strictly, the enforced population is users whose only MFA method is SMS or voice, plus anyone signing in with SMS as a first factor. A user who also has Microsoft Authenticator push notifications will not meet the blocking prompt because of this retirement. That is our reading of the Learn text, and it matters for triage. Microsoft's July Security blog post put it more broadly, saying that after 1 February "Automatic prompts to register a passkey will be enforced for all users in all tenants". The later Learn page, updated 16 September, narrows this to users "whose only available MFA method is SMS or voice". Where the two differ, treat the Learn page as current. Microsoft's scanner repository calls it "the source of truth for the timeline".

The distinction does not make push notifications a destination. The UK's National Cyber Security Centre ranks MFA types with FIDO2 credentials first and message-based methods, including SMS, fifth of five. It says message-based methods are "only likely to be appropriate when no other strengthening method is possible". Microsoft's direction and the NCSC's ranking agree. The difference is that Microsoft enforces only the bottom rung, and the rest is left to you.

Four labels that promise more than they deliver

"Usage analyzer". Microsoft's retirement page tells admins to run a PowerShell script, published at microsoft/entra-sms-voice-usage-analyzer, "To find users enabled for SMS or Voice". The FAQ adds: "Any non-zero result means you're in scope." The script's own README is more careful. It calls itself a "read-only policy scope scanner, not a user inventory or usage report". It says it does not "expand group membership", "inspect registered methods, or read sign-in activity". It does not tell you which people have only a phone registered, and those are the people who will meet the blocking prompt. For that, use the Authentication methods activity report. Its user registration details list the methods each user has registered, with up to 36 hours' latency, and it needs an Entra ID P1 or P2 licence.

"Not locked out". The FAQ asks whether customers will be locked out on the retirement date, and answers "No". What happens instead is a registration prompt users "will no longer be able to skip". For a user with a compatible device, that is an inconvenience. For a user on a shared till, a locked-down handset, or a phone that cannot hold a passkey, a prompt they cannot complete has the same effect as a lockout. Microsoft's pages do not address that case.

"passkeyDynamicMigration". The temporary opt-out from the September changes is set through Microsoft Graph beta by setting a property called passkeyDynamicMigration to true, under optOutSettings. Setting a property named "migration" to true is how you stop the migration. Anyone reviewing a tenant configuration should read that value with care. The opt-out needs the Policy.ReadWrite.AuthenticationMethod permission and ends on 1 February regardless.

"Microsoft Managed". From 1 September Microsoft sets the passkey registration campaign to the "Microsoft Managed" state for in-scope users. The label describes who chose the setting, not whether it suits your users. Check the state in the Entra admin centre under Authentication methods, Registration campaign. Microsoft says the rollout "may take time to reach all tenants", so it may already be live in yours or may not.

Method, sources and interests

Both halves rest on Microsoft's own pages, read in full on 21 September 2026. For File History, those are the six September KB support pages, the two out-of-band KB pages of 14 September, and Microsoft's two File History help pages. For Entra, they are the Learn retirement page and FAQ, the Choose Your Own Telephony Provider page, the SMS sign-in page, the July Security blog post and the scanner's GitHub README. The Message Center posts MC1474104, MC1426371 and MC1448374 need an admin sign-in, so we read their text through the public Message Center archive at mc.merill.net. That is a mirror, not Microsoft's own site, and we cross-checked every date in it against the Learn pages. We could not read the admin centre release health alert WI1474330 directly; for that we rely on BleepingComputer's reporting.

Commercial interest is worth naming without drawing conclusions from it. Microsoft steps back from paying for SMS and voice delivery, and customers who still need it will pay third-party carriers through Microsoft's own Security Store. Passkeys, Microsoft notes, come "at no additional cost". On the Windows side, File History is an older feature: BleepingComputer describes it as replaced by Windows Backup, which backs up to OneDrive. Neither point changes the facts above. Both explain why the documentation reads as it does.

What to do, in order

Take this with you

File History, this week

  • Find out where File History is in use. It is configured per device in Control Panel, so ask your endpoint and service desk teams, and pay special attention to anyone for whom it is the only backup.
  • On devices with a September 2026 update installed, open File History and check the Last Backup time. If it has not moved since the update, treat backups as stopped.
  • Search the Application event log for crash events naming FileHistory.exe with KERNELBASE.dll. Add that pattern to your endpoint monitoring if you can.
  • Tell the service desk that a Reconnect your drive message on a patched device is probably false. Do not reselect the drive or network location, and never choose to start fresh, until the backup drive's contents have been checked read-only.
  • Give affected users a second, independent backup now, using whatever your standard is, such as OneDrive known folders, Windows Backup or your managed backup agent.
  • Do not uninstall the September updates to restore File History. They carry fixes for two Windows flaws on CISA's exploited list, CVE-2026-81963 and CVE-2026-85880.
  • Watch the KB support pages for each build and turn on admin centre release health notifications. On 21 September the public release health dashboard did not yet list this issue.

Take this with you

Entra ID, before 1 February 2027

  • Run Microsoft's SMS and Voice Policy Scanner to see which groups and users your SMS and voice policies target. Remember that it reports policy scope, not people or usage.
  • Use Authentication methods, Activity, User registration details to list users whose only registered methods are phones. They are the people who will meet the blocking passkey prompt.
  • Check whether SMS sign-in as a first factor is enabled for anyone, usually frontline staff. Plan passkeys or QR code authentication for them. No telecom provider can keep this feature alive after 1 February.
  • Move Global Administrators to phishing-resistant methods now. Their July 2027 date is later, but they should be first, not last.
  • Include internal guest users, which stay on the February date, and SSPR, which is in scope, in your migration plan.
  • Check the Registration campaign state. Decide deliberately whether to use the temporary opt-out, noting that it is set by making passkeyDynamicMigration true and that it ends on 1 February.
  • If you have a documented regulatory or operational need for SMS or voice, write it down, budget for per-message charges, and aim to finish provider set-up by 4 January 2027, four weeks before the cut-off as Microsoft advises. Configuration opens on 30 October.
  • Send users a notice explaining what is changing, when, and how to register a passkey on their device type, using Microsoft's end-user templates if helpful.

The question that exposes the gap

Both notices turn on signals that nobody reads until too late: a Last Backup date that stopped on 8 September, and a phone number that has been some users' only second factor for years. For File History, the fix is simple enough: look now. For Entra, Microsoft's pages leave one thing unanswered that every service desk should put to its Microsoft contact before February. After 1 February, when a user whose only registered method is SMS signs in and meets a passkey prompt they cannot skip, what proves it is really them before that passkey is created?

Key facts

Sources

  1. PrimaryKB5124008 release notes (Windows 11 24H2 and 25H2): builds, the five known issues including File History, change log entry of 19 September 2026Microsoft Supportaccessed 2026-09-21
  2. PrimaryKB5124012 release notes (Windows 11 26H1): File History known issue and change logMicrosoft Supportaccessed 2026-09-21
  3. PrimaryKB5122880 release notes (Windows 11 23H2): File History known issue and change logMicrosoft Supportaccessed 2026-09-21
  4. PrimaryKB5122878 release notes (Windows 10 ESU and LTSC 2021): File History known issue in both sectionsMicrosoft Supportaccessed 2026-09-21
  5. PrimaryKB5122876 release notes (Server 2019 and Windows 10 LTSC 2019): File History listed only under LTSC 2019Microsoft Supportaccessed 2026-09-21
  6. PrimaryKB5123099 release notes (Server 2016 and Windows 10 LTSB 2016): File History listed only under LTSB 2016Microsoft Supportaccessed 2026-09-21
  7. PrimaryKB5129195 out-of-band update of 14 September 2026: cumulative, no File History entryMicrosoft Supportaccessed 2026-09-21
  8. PrimaryKB5129236 Windows 10 out-of-band update of 14 September 2026: no File History entryMicrosoft Supportaccessed 2026-09-21
  9. PrimaryWindows 11 25H2 release health: checked for a File History entry (none as of its 18 September update)Microsoft Learnaccessed 2026-09-21
  10. PrimaryBackup and restore with File History: drive selection prompt to move files or start fresh, restore warningMicrosoft Supportaccessed 2026-09-21
  11. PrimaryReconnect your File History drive: Microsoft's standard troubleshooting for the messageMicrosoft Supportaccessed 2026-09-21
  12. PrimaryKEV catalogue (JSON version 2026.09.18): CVE-2026-81963 and CVE-2026-85880 added 8 September, due 22 SeptemberCISAaccessed 2026-09-21
  13. PrimaryPasskeys by default and retirement of Microsoft-provided SMS and voice: timeline, enforcement, opt-out, updated 16 September 2026Microsoft Learnaccessed 2026-09-21
  14. PrimaryFAQ for the SMS and voice retirement: SSPR scope, lockout answer, cloud scope, external MFA, costsMicrosoft Learnaccessed 2026-09-21
  15. PrimaryChoose Your Own Telephony Provider: availability dates and customer responsibilitiesMicrosoft Learnaccessed 2026-09-21
  16. PrimarySMS-based sign-in: what first-factor SMS is and who it is meant forMicrosoft Learnaccessed 2026-09-21
  17. PrimaryAuthentication methods activity: user registration details, licence and latencyMicrosoft Learnaccessed 2026-09-21
  18. PrimaryAnnouncement of 13 July 2026 making passkeys the default and retiring Microsoft-provided SMS and voiceMicrosoft Security Blogaccessed 2026-09-21
  19. PrimaryEntra SMS/Voice Policy Scanner README: what the script does and does not reportMicrosoft (GitHub)accessed 2026-09-21
  20. PrimaryRecommended types of MFA: FIDO2 first, message-based methods fifthNCSCaccessed 2026-09-21
  21. Reported byText of Microsoft Message Center post MC1474104, 18 September 2026: SMS first-factor sign-in retirement; archive mirror of Microsoft's postMessage Center archive (mc.merill.net)accessed 2026-09-21
  22. Reported byText of MC1426371 (updated 15 September 2026): passkeys by default and SMS and voice retirement scheduleMessage Center archive (mc.merill.net)accessed 2026-09-21
  23. Reported byText of MC1448374: SMS first-factor sign-in retired for Entra ID Free tenants on 11 August 2026Message Center archive (mc.merill.net)accessed 2026-09-21
  24. Reported byOur 17 September 2026 briefing on KB5124008 and domain trustpk-sharma.comaccessed 2026-09-21
  25. Reported byNews report of 21 September 2026 pointing to the File History issue; source for the admin centre alert WI1474330BleepingComputeraccessed 2026-09-21
  26. Reported byNews report of 21 September 2026 pointing to MC1474104BleepingComputeraccessed 2026-09-21

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.