“Something didn’t go as planned. Undoing changes.” That’s the only message some Windows 11 users will receive when Microsoft’s May security update fails to install due to insufficient free space on the EFI System Partition (ESP), leaving their systems unprotected from the dozens of fixes it contained. This issue affects devices with limited available free space — typically 10MB or less — on the ESP.
See also: Microsoft is removing Teams' Together Mode

"On affected devices, the installation may proceed through the initial phases but fail during the reboot phase at approximately 35-36% completion," Microsoft said in an advisory.
It is recommended to change a setting in the Windows registry to force the update or to roll back the changes and wait for a future update that will fix the problem. Advisories said it was a potentially serious issue given the unexpected exposure and the time it took for the failed update to install. This is the kind of failure that keeps IT leaders up at night, said cybersecurity consultant Brian Levine, who serves as executive director of FormerGov.
“When a security update fails to install because the operating system misjudges the state of its own boot partition, the problem isn’t just storage. The real problem is trust in the update process,” he said. “This is a basic hygiene failure disguised as a technical issue. An update that can’t reliably detect available space on the EFI System Partition is no small oversight. It’s a reminder that even mature platforms still struggle with dependency awareness and pre-flight validation.”
See also: Microsoft: Rejects report of critical Azure Backup vulnerability

Eric Grenier, senior analyst director at Gartner, recommended increasing the disk partition size to 1.5GB so the update can proceed. "This will not hinder business needs in terms of the amount of space available to an end user," he said, adding that it will also allow the Windows Recovery Environment.
He warned that Microsoft's recommendation could lead to problems. "I would recommend that if an organization wanted to use the fixed registry setting, they would not only back up the registry beforehand but also test it on some pilot devices before rolling it out to the rest of the environment, and even then, I would do a slow rolling release to make sure nothing breaks," he said.
“While IT environments may contribute to partition pressure over time, Microsoft still owns the orchestration and validation logic that enabled the update push.” Khan added that this can become a very costly headache for IT businesses.
David Neuman, COO of consulting firm Acceligence, agreed that this is a major headache for IT.
See also: Windows Update will automatically roll back problematic drivers

“The update appears to pass the initial phases but then fails during the reboot phase, meaning IT may not discover it until the endpoint has already used up its maintenance window time and has rolled back. In an enterprise, it becomes a fleet hygiene issue rather than an isolated support issue,” he said. Microsoft did not respond to a request for comment.
