MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-16 · via BleepingComputer

Microsoft investigates Windows 11 patch disrupting Active Directory connections

Image via BleepingComputer
Image via BleepingComputer

Microsoft is looking into reports that the Windows 11 KB5124008 security update severs the secure channel between domain-joined computers and Active Directory, leading to login failures with valid credentials. Administrators have reproduced the issue on Windows 11 25H2 devices, with uninstalling the update and repairing the domain relationship restoring access. The problem appears linked to the Windows Machine Identity Isolation feature, though Microsoft has not confirmed a root cause.

Expanded Detail

The KB5124008 update appears to alter a registry setting tied to Windows' Virtualization-Based Security, shifting machine account credentials into Credential Guard in enforcement mode. This change can invalidate locally stored LSA secrets, severing the secure channel that domain-joined systems rely on for authentication. Administrators report the issue is reproducible across Windows 11 25H2 devices, with roughly 4 percent of machines affected in one deployment.

Microsoft has acknowledged the reports but has not yet confirmed a root cause or issued a fix. Affected administrators have found workarounds, including disabling the MachineIdentityIsolation feature and running the Test-ComputerSecureChannel repair command. Until a permanent solution arrives, enterprises may need to weigh uninstalling the update against leaving systems exposed to the security vulnerabilities the patch was designed to address.

Context

This disruption could significantly impact enterprise operations, as organizations depend on Active Directory for daily authentication across fleets of domain-joined workstations. Widespread login failures may force IT teams to divert resources toward manual repairs, potentially delaying productivity for affected employees. If the issue persists, businesses could face a difficult trade-off between maintaining security posture and ensuring operational continuity, though Microsoft's acknowledged investigation suggests a resolution may be forthcoming.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Windows 11 USB audio failures linked to September security patches · Software & cloud
Windows Server Patch Tuesday Causes Remote Desktop Outages Across Multiple Versions · Software & cloud
Excel Security Patch Causes Copy-Paste and Autofill Failures for Some Users · Software & cloud
Microsoft resolves startup crashes for Teams and Outlook on ARM devices after August updates · Software & cloud
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Windows 11 KB5124008 update breaks domain trust for some users.” Browse more stories.