Windows 11 security patch disrupts Always On VPN for some enterprises

Microsoft has alerted IT administrators that the September 2026 Windows 11 cumulative updates can cause Always On VPN connections to fail, leaving them stuck in a connecting state or repeatedly retrying. The issue arises when the VPN profile uses automatic protocol selection, and affected systems may show an error about the port already being in use. As a temporary workaround, Microsoft recommends forcing the VPN to use either SSTP or IKEv2 exclusively until a permanent fix is released.
Always On VPN serves as Microsoft's modern replacement for DirectAccess, supporting domain-joined, non-domain-joined, and Microsoft Entra ID–joined devices on Windows 10, 11, and Server. The affected September updates include KB5124012 for version 26H1 and KB5124008 for versions 25H2 and 24H2.
The failure stems from automatic protocol selection, where the system attempts IKEv2 then SSTP if the first try fails. Microsoft's recommended mitigation directs administrators to lock the profile to a single protocol based on their environment's security and deployment needs. This month's updates have already triggered emergency fixes for Hyper-V, Remote Desktop Services, USB audio, domain login, and File History issues.
This disruption could significantly hamper remote and hybrid workforces, as Always On VPN is a core component of enterprise network access for many organizations. IT teams may face urgent troubleshooting burdens while employees experience connectivity failures, potentially reducing productivity and delaying critical operations. Organizations relying on automatic protocol failover may be especially vulnerable, though the single-protocol workaround offers a path forward. The broader pattern of September update issues suggests enterprises may grow more cautious about deploying monthly patches promptly, weighing security benefits against operational disruption risks.