Relevant area(s)
WinGet CLI
Relevant command(s)
winget upgrade
Brief description of your issue
after installing August 27, 2026—KB5120998 (OS Builds 26200.9278 and 26100.9278) Preview update, WinGet is no longer usable from an elevated command prompt.
Now it only works from a non-elevated terminal and requires secure-desktop approval with PIN or Password.
Steps to reproduce
- install KB5120998 Preview update for Windows 11 Pro from Microsoft Update
- find that it now only works in non-elevated terminal windows and any upgrade action requires elevation with Windows Hello mandatory PIN/Password - a simple click on the yes button is no longer possible.
Expected behavior
expected: no hidden / surprise major changes
Actual behavior
actual behaviour: KB5120998 introduces an.... interesting security context privilege separation.
Now administrator accounts seem to use a completely different user profile when elevated than when non-elevated.
Environment
elevated environment:
PS C:\WINDOWS\system32> winget --info
winget : The term 'winget' is not recognized as the name of a cmdlet, function, script file, or operable program. Check the spelling of the name, or if a path was included, verify that
the path is correct and try again.
At line:1 char:1
+ winget --info
+ ~~~~~~
+ CategoryInfo : ObjectNotFound: (winget:String) [], CommandNotFoundException
+ FullyQualifiedErrorId : CommandNotFoundException
PS C:\WINDOWS\system32>
non-elevated environment:
C:\>winget --info
Windows Package Manager v1.29.290
© 2026 Microsoft. All rights reserved.
Windows: Windows.Desktop v10.0.26200.9278
System Architecture: X64
Package: Microsoft.DesktopAppInstaller v1.29.290.0
WinGet Directories
-------------------------------------------------------------------------------------------------------------------------------
Logs %LOCALAPPDATA%\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\DiagOutputDir
User Settings %LOCALAPPDATA%\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\settings.json
Portable Links Directory (User) %LOCALAPPDATA%\Microsoft\WinGet\Links
Portable Links Directory (Machine) C:\Program Files\WinGet\Links
Portable Package Root (User) %LOCALAPPDATA%\Microsoft\WinGet\Packages
Portable Package Root C:\Program Files\WinGet\Packages
Portable Package Root (x86) C:\Program Files (x86)\WinGet\Packages
Installer Downloads %USERPROFILE%\Downloads
Configuration Modules %LOCALAPPDATA%\Microsoft\WinGet\Configuration\Modules
Links
---------------------------------------------------------------------------
Privacy Statement https://aka.ms/winget-privacy
License Agreement https://aka.ms/winget-license
Third Party Notices https://aka.ms/winget-3rdPartyNotice
Homepage https://aka.ms/winget
Windows Store Terms https://www.microsoft.com/en-us/storedocs/terms-of-sale
Admin Setting State
--------------------------------------------------
LocalManifestFiles Disabled
BypassCertificatePinningForMicrosoftStore Disabled
InstallerHashOverride Disabled
LocalArchiveMalwareScanOverride Disabled
ProxyCommandLineOptions Disabled
ConfigurationProcessorPath Disabled
DefaultProxy Disabled
C:\>
Relevant area(s)
WinGet CLI
Relevant command(s)
winget upgrade
Brief description of your issue
after installing August 27, 2026—KB5120998 (OS Builds 26200.9278 and 26100.9278) Preview update, WinGet is no longer usable from an elevated command prompt.
Now it only works from a non-elevated terminal and requires secure-desktop approval with PIN or Password.
Steps to reproduce
Expected behavior
expected: no hidden / surprise major changes
Actual behavior
actual behaviour: KB5120998 introduces an.... interesting security context privilege separation.
Now administrator accounts seem to use a completely different user profile when elevated than when non-elevated.
Environment