Microsoft is cleaning up Windows 11 and removing multiple legacy features, starting with WMIC, in hopes that it makes the OS more secure. And it’s necessary, as the company itself warned that AI is a major security threat and even recommended that users not delay updates for more than three days.
Microsoft has now started laying the groundwork to fully remove the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11, which has been abused by malware and ransomware for years.
WMIC was disabled last year, but it wasn’t fully removed, and that changes with the August 2026 Update.
What is WMIC and why is it being removed for Windows 11’s security?

Windows 11 24H2, 25H2, and 26H2 will stop shipping with anything related to WMIC, but what exactly is it, and how did it make PCs vulnerable? WMIC was/is used by IT admins to automate and query Windows system settings or hardware/network configurations, so it’s primarily an enterprise tool, but it remained available on all PCs.
As a result, even “regular” home users were targeted by malware and ransomware that abused WMIC. Microsoft later confirmed it would remove WMIC because PowerShell and other tools are already more than enough for those who relied on the legacy tool, and Windows 11 25H2 finally disabled it.
However, right now, WMIC is not fully removed, and it’s still included in Windows 11 24H2 or 25H2 as a Feature on Demand (FoD). WMIC was already removed by default from newer Windows 11 installations, but administrators could still bring it back through Optional Features or DISM, which means the feature was never entirely gone.
In a new document, Microsoft says Windows 11 will no longer include WMIC starting with the August 2026 Patch Tuesday update, and you won’t be able to bring it back.
“Starting in August 2026, Windows 11, versions 24H2 and 25H2 no longer include the Windows Management Instrumentation Command-line (WMIC) utility,” Microsoft noted in the release notes spotted by Windows Latest.
“WMIC is already removed by default in new installations of Windows 11, versions 24H2 and 25H2, and is no longer available as a Feature on Demand (FoD).”
It’s good news for everyone because WMIC has been abused to attack even regular consumers, and its removal should improve Windows 11’s security, the company argues.
For those unaware, WMIC, which remained available in Windows 11 until August 2026, is considered a LOLBIN, or living-off-the-land binary. That means it is a real Microsoft-signed Windows executable that bad actors can abuse during an attack instead of deploying their own tools.
Threat actors have abused WMIC to identify installed antivirus products and even remove security apps, so they can access data on a compromised PC.
Microsoft has been removing WMIC in stages
Microsoft has not been ignoring WMIC as a security threat, but it’s taken a slow approach to avoid breaking integrations for enterprises.

For example, it first deprecated WMIC in Windows 10 21H1 in 2021, and version 22H2 converted WMIC into a Feature on Demand. Windows 11 25H2 disabled it by default, but you could still enable it. Now, WMIC will no longer simply be disabled or absent by default. The FoD itself is being removed.
“Microsoft recommends using PowerShell and other modern tools for any tasks previously done with WMIC. You can consider programmatic alternatives such as WMI’s COM API, .NET libraries, or scripting languages. Once you decide on your way forward, please update your internal IT documentation and processes,” the company said in a document.
Microsoft also explained that it’s been investing heavily in PowerShell, which now makes it easier to query WMI, and that WMIC is no longer required.
“Removing a deprecated component helps reduce complexity while keeping you secure and productive,” the company said in 2027.
Microsoft noted that the complete removal only affects the outdated WMIC command-line utility. Windows Management Instrumentation (WMI), the underlying Windows management infrastructure, remains supported.





















