Understanding TextInputHost.exe and TabTip.exe roles in Windows 11 (24H2) touch keyboard behavior

Kadia, Gokul 0 Reputation points
2026-04-15T10:36:52.18+00:00

We understand that InputApp.exe is deprecated by Microsoft in Windows 11 (24H2). Could someone please clarify the roles of TextInputHost.exe and TabTip.exe in relation to the modern and legacy touch keyboards?

Scenario:

We have a custom application where we use the legacy touch keyboard in Kiosk mode, and everything works as expected. However, when we exit Kiosk mode, we observe that two keyboards appear (modern and legacy).

This issue does not occur in Kiosk mode, likely because explorer.exe is not running.

Observations:

  • If we rename TextInputHost.exe to disable the modern keyboard:
    • The entire touch input mechanism stops working (both modern and legacy keyboards stop functioning)
    • If we instead run a background process that continuously terminates TextInputHost.exe:
      • The legacy keyboard continues to work properly
        • The modern keyboard does not appear

Questions:

  1. What is the exact role of TextInputHost.exe in the touch input architecture?
  2. How does it interact with TabTip.exe for both modern and legacy keyboards?
  3. Why does renaming TextInputHost.exe completely break touch input, while terminating the process at runtime does not?
  4. Are there any risks or side effects of continuously killing TextInputHost.exe?
  5. Is there a recommended or supported approach to ensure that only the legacy keyboard is shown outside of Kiosk mode?We understand that InputApp.exe is deprecated by Microsoft in Windows 11 (24H2). Could someone please clarify the roles of TextInputHost.exe and TabTip.exe in relation to the modern and legacy touch keyboards?
Windows for home | Windows 11 | Desktop, Start, and personalization | Touch keyboard
0 comments No comments

1 answer

Sort by: Most helpful
  1. Carl-L 22,915 Reputation points Microsoft External Staff Moderator
    2026-04-16T06:55:46.1166667+00:00

    Hello Kadia, Gokul,

    Welcome to Microsoft Q&A forum.

    Regarding your questions:

    • TextInputHost.exe, as the name also stated, this is the UI/experience host for moder text input surface, which include the touch keyboard.
    • For modern keyboard, TabTip.exe will be the one who spawn TextInputHost.exe, which indicate it act like a trigger point. I think this might be the reason why you see 2 keyboards. Your app is invoking the legacy TabTip while Windows explorer create the modern one.
    • Renaming could break pathway that is using the affected process, many pathways was created assuming that the component exists and can be activated. Killing the component could force some of those pathways to fallback to legacy, while technically the component is still running when you rename it, so it could cause confusion in the system. In short, Renaming breaks the component’s presence/activation/registration, which can collapse multiple input paths. Killing is a runtime failure that can still leave enough plumbing for legacy invocation to continue.
    • Continuously killing a component is definitely not a supported method. What can lead to is possibly UAC misbehavior, issue with other input surface like emojis. Also, even if a script can do it repeatedly now. It might be irrelevant in the next update.
    • To prevent this, I've tried to find but it seems like there is no current supported ways for this. However, you can do so by preventing Windows invocation or create a shell with no explorer. You can change it in the settings by right clicking on the taskbar > Taskbar settings and set the Touch Keyboard to never. However, that will mean the modern touch keyboard won't appear at all.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    Was this answer helpful?

    1 person found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.