Table of Contents
Why Won’t My Enterprise PC Shut Down After Installing KB5073455?
Microsoft has released an emergency out-of-band update, KB5077797, to resolve a critical bug introduced in the January 2026 security patch (KB5073455). This bug prevented Windows 11 23H2 Enterprise and Education devices using Secure Launch from shutting down or entering sleep mode properly. Administrators must manually download this fix from the Microsoft Update Catalog.
The Issue: Shutdown and Sleep Failures in Windows 11 23H2
On January 13, 2026, Microsoft rolled out the cumulative security update KB5073455. This patch was intended for Windows 11 version 23H2, specifically targeting Enterprise and Education editions. While it delivered essential security improvements and quality enhancements, it inadvertently introduced a significant disruption for specific hardware configurations.
Shortly after deployment, administrators reported that affected devices would not shut down or enter hibernation. Instead, these systems would initiate the shutdown process but immediately restart. Microsoft acknowledged this behavior in a “Known Issues” support bulletin published on January 15, 2026.
Root Cause: Secure Launch Conflict
The investigation identified the conflict within the Secure Launch feature. Secure Launch utilizes Virtualization-based Security (VBS) to safeguard the system against firmware-level attacks during the boot sequence. The January security update (KB5073455) created an instability within this specific security protocol, causing the power state transition failure.
Affected Systems:
- OS: Windows 11, version 23H2.
- Editions: Enterprise, Education, and IoT Enterprise.
- Configuration: Devices with “Secure Launch” enabled.
The Solution: Out-of-Band Update KB5077797
Recognizing the severity of power management failures in enterprise environments, Microsoft expedited a solution. On January 17, 2026, the company released an out-of-band (OOB) update: KB5077797.
This cumulative update serves two purposes:
- Retention: It includes all previous security patches and improvements from the original January release.
- Remediation: It specifically corrects the code responsible for the Secure Launch restart loop.
Action Plan for System Administrators
Unlike standard monthly patches, Microsoft is not pushing this update automatically via Windows Update or Windows Server Update Services (WSUS) immediately. You must take proactive steps to apply this fix.
Step-by-Step Deployment:
- Verify Impact: Confirm your managed devices are running Windows 11 23H2 (Enterprise/Education) and are experiencing shutdown failures.
- Access the Catalog: Navigate to the Microsoft Update Catalog.
- Search & Download: Search for “KB5077797” and download the appropriate package for your architecture (x64 or ARM64).
- Manual Installation: Deploy the .msu file to affected machines using your standard deployment tools (SCCM, Intune, or manual execution).
Advisory Note: If your environment does not utilize Secure Launch or has not experienced power state issues, you may choose to wait for the next scheduled cumulative update (Patch Tuesday), which will likely incorporate this fix. However, for affected units, immediate application of KB5077797 is necessary to restore normal power functionality.