What's new in Windows 11 IoT Enterprise, version 22H2

Overview

Windows 11, version 22H2 is a feature update for Windows 11 IoT Enterprise. Windows 11, version 22H2 includes all previous cumulative updates to Windows 11 IoT Enterprise, version 21H2 plus some new and updated features valuable for IoT scenarios.

Windows 11 IoT Enterprise follows the Modern Lifecycle Policy.

Release Version Availability End of Servicing
Windows 11 IoT Enterprise, version 22H2 22621 2022-09-20 2025-10-14

For more information, see Windows 11 IoT Enterprise support lifecycle.

Availability

Windows 11 IoT Enterprise, version 22H2 is available through Windows Server Update Services (including Configuration Manager), Windows Update for Business, and the Volume Licensing Service Center (VLSC). For more information, see How to get the Windows 11, version 22H2 update. Review the Windows 11, version 22H2 Windows IT Pro blog post to discover information about available deployment resources such as the Windows Deployment Kit (Windows ADK).

To learn more about the status of the update rollout, known issues, and new information, see Windows release health.

What's new

Note

Multi-app kiosk mode is not available for Windows 11 IoT Enterprise, version 22H2. Please refer to What's new about subsequent releases for information about its return.

Update - Multi-app kiosk mode is now available in Windows 11, version 22H2, as part of the Windows continuous innovation releases. To learn how you can take advantage of features introduced via Windows continuous innovation, see more about how you can access this feature in Windows 11 IoT Enterprise, version 22H2, see Delivering continuous innovation in Windows 11.

Feature Description
Microsoft Pluton Designed by Microsoft and built by silicon partners, Microsoft Pluton is a secure crypto-processor built into the CPU for security at the core to ensure code integrity and the latest protection with updates delivered by Microsoft through Windows Update. Pluton protects credentials, identities, personal data and encryption keys. Information is significantly harder to be removed even if an attacker has installed malware or has complete physical possession Microsoft Pluton can be enabled on devices with Pluton capable processors running Windows 11, version 22H2.

For more information, see Microsoft Pluton security processor.
Enhanced Phishing Protection Enhanced Phishing Protection in Microsoft Defender SmartScreen helps protect Microsoft passwords against phishing and unsafe usage. Enhanced Phishing Protection works alongside Windows security protections to help protect Windows 11 sign-in passwords.

For more information, see Enhanced Phishing Protection in Microsoft Defender SmartScreen and Protect passwords with enhanced phishing protection in the Windows IT Pro blog.
Smart App Control Smart App Control adds significant protection from malware, including new and emerging threats, by blocking apps that are malicious or untrusted. Smart App Control also helps to block potentially unwanted apps, which are apps that may cause your device to run slowly, display unexpected ads, offer extra software you didn't want, or do other things you don't expect. For more information, see Smart App Control.
Credential Guard Compatible Windows 11 IoT Enterprise, version 22H2 devices will have Windows Defender Credential Guard turned on by default. This changes the default state of the feature in Windows, though system administrators can still modify this enablement state.

For more information, see Manage Windows Defender Credential Guard.
Malicious and vulnerable driver blocking The vulnerable driver blocklist is automatically enabled on devices when Smart App Control is enabled and for clean installs of Windows.

For more information, see recommended block rules.
Security hardening and threat protection Windows 11, version 22H2 supports additional protection for the Local Security Authority (LSA) process to prevent code injection that could compromise credentials. For more information, see Configuring Additional LSA Protection.
Windows Update notifications You can now block user notifications for Windows Updates during active hours. This setting is especially useful for organizations that want to prevent Windows Update notifications from occurring during business hours. For more information, see Control restart notifications.

The organization name now appears in the Windows Update notifications when Windows clients are associated with an Azure Active Directory tenant. For more information, see Display organization name in Windows Update notifications.
Start menu layout Windows 11 IoT Enterprise, version 22H2 now supports additional CSPs for customizing the start menu layout. These CSPs allow you to hide the app list and disable context menus.

For more information, see Supported configuration service provider (CSP) policies for Windows 11 Start menu.
Improvements to task manager A new command bar was added to each page to give access to common actions. Task Manager will automatically match the system wide theme configured in Windows Settings. Added an efficiency mode that allows you to limit the resource usage of a process.
Windows accessibility Windows 11, version 22H2, includes additional improvements for people with disabilities: system-wide live captions, Focus sessions, voice access, and more natural voices for Narrator.

For more information, see New accessibility features coming to Windows 11 and How inclusion drives innovation in Windows 11. For more information, see Accessibility information for IT professionals.
High Efficiency Video Coding (HEVC) support Starting in Windows 11, version 22H2, support for High Efficiency Video Coding (HEVC) is now available. \HEVC is designed to take advantage of hardware capabilities on some newer devices to support 4K and Ultra HD content.

For devices that don't have hardware support for HEVC videos, software support is provided, but the playback experience might vary based on the video resolution and your devices performance.