Microsoft investigates Windows 11 patch disrupting Active Directory connections

Microsoft is looking into reports that the Windows 11 KB5124008 security update severs the secure channel between domain-joined computers and Active Directory, leading to login failures with valid credentials. Administrators have reproduced the issue on Windows 11 25H2 devices, with uninstalling the update and repairing the domain relationship restoring access. The problem appears linked to the Windows Machine Identity Isolation feature, though Microsoft has not confirmed a root cause.
The KB5124008 update appears to alter a registry setting tied to Windows' Virtualization-Based Security, shifting machine account credentials into Credential Guard in enforcement mode. This change can invalidate locally stored LSA secrets, severing the secure channel that domain-joined systems rely on for authentication. Administrators report the issue is reproducible across Windows 11 25H2 devices, with roughly 4 percent of machines affected in one deployment.
Microsoft has acknowledged the reports but has not yet confirmed a root cause or issued a fix. Affected administrators have found workarounds, including disabling the MachineIdentityIsolation feature and running the Test-ComputerSecureChannel repair command. Until a permanent solution arrives, enterprises may need to weigh uninstalling the update against leaving systems exposed to the security vulnerabilities the patch was designed to address.
This disruption could significantly impact enterprise operations, as organizations depend on Active Directory for daily authentication across fleets of domain-joined workstations. Widespread login failures may force IT teams to divert resources toward manual repairs, potentially delaying productivity for affected employees. If the issue persists, businesses could face a difficult trade-off between maintaining security posture and ensuring operational continuity, though Microsoft's acknowledged investigation suggests a resolution may be forthcoming.