Windows 11 login bug causes black screen on Azure Virtual Desktop with FSLogix

Microsoft - 4kodiak/ istockphoto.comMicrosoft - 4kodiak/ istockphoto.com

Microsoft - 4kodiak/ istockphoto.com

Microsoft has formally documented an operating system defect in Windows 11 that generates a blank black screen and stops the visual desktop from loading automatically after a user signs in. The failure predominantly targets corporate environments deployed on Azure Virtual Desktop that rely on the FSLogix profile container framework.

The disruption leaves corporate users unable to access their application shortcuts, the system taskbar, or the Start menu upon completing authentication. Technical documentation published on the Windows Release Health dashboard by the company, based in Redmond, Washington, outlines the symptoms observed across virtualized workstations: “After installing Windows 11, version 26H2, and subsequent updates, some devices may experience issues where the desktop does not load. This issue has been observed primarily on Azure Virtual Desktop (AVD) hosts, using FSLogix.”

Photo: Microsoft – NicolasMcComber/ Istockphoto.com

Technical root cause and Windows Explorer crashes in event logs

Diagnostic records stored within the Windows Application event log confirm critical crashes and unexpected terminations of the explorer.exe process during session initialization. The problem manifests at the exact instant the operating system attempts to generate the visual graphical interface, leaving authenticated accounts hanging in an unrendered state. Microsoft noted that the anomalous behavior appears more frequently when loading pre-existing user profiles on virtualized hosts rather than freshly provisioned ones.

The defect originated with the optional non-security cumulative preview updates released on August 27, 2026, and persisted into subsequent update packages distributed throughout September. One of those originating preview releases, KB5120998, had already prompted administrative headaches earlier in September 2026 by turning desktop backgrounds solid black and resetting custom mouse pointer preferences. While those earlier visual flaws received targeted fixes during the regular security releases on September 8, 2026, the underlying shell initialization conflict continued to affect virtual desktop logins.

Operating system editions and specific update packages involved

The regression spans multiple servicing branches of the operating system currently running in business and personal environments. Microsoft clarified that Windows Server editions remain unaffected by this login failure, confining the incident strictly to client builds of Windows 11. The software developer generated distinct Group Policy mitigation definitions corresponding to each affected build:

Keep reading: Microsoft plans Ninja Theory closure in new 268 job Xbox reduction

  • KB5120998: optional preview cumulative package for Windows 11 versions 24H2 and 25H2
  • KB5120996: preview cumulative update package delivered for Windows 11 build 26H1
  • KB5124010: Known Issue Rollback group policy package designed for editions 24H2, 25H2, and 26H2
  • KB5124006: rollback group policy definition file created specifically for edition 26H1

FSLogix is widely deployed across enterprise cloud installations to manage user profiles inside virtual hard disk containers, speeding up sign-in times and streamlining remote session handoffs. Due to the internal compatibility regression between the recent system patches and the profile mounting mechanism, Windows Explorer abruptly stops executing before the interactive workspace can appear. This crash forces remote workers into an unusable visual state until administrators apply remediation steps.

Manual recovery steps for users and administrator rollback guidelines

Workers who find themselves stranded at a black screen can manually start the graphic interface without severing their active remote session. The temporary end-user procedure involves launching Task Manager by pressing Ctrl+Shift+Esc on the keyboard, selecting the command to run a new task, entering explorer.exe into the prompt, and selecting the confirmation button to force the desktop shell to appear.

For system administrators managing enterprise fleets through centralized controls, Microsoft published out-of-band Group Policy packages powered by Known Issue Rollback technology. This rollback functionality disables solely the problematic update routine that interrupts shell execution, allowing devices to maintain the security protections delivered in the broader monthly updates.

Learn more: Microsoft files patent for dynamic in-game ads on Xbox consoles

Network administrators must manually deploy the corresponding policy template and restart managed virtual machines to enforce the temporary mitigation across their pools. Official technical guidance from Microsoft states: “You will need to install and configure the Group Policy for your version of Windows to resolve this issue. You will also need to restart your device(s) to apply the group policy setting.”

Microsoft has not released a specific deployment calendar for distributing an automated, permanent code fix through Windows Update. The company stated that engineering teams are finalizing a comprehensive resolution that will be integrated into a future cumulative update for Windows 11.