Windows 11 KB5124008 Breaking Domain Login? Microsoft Shares Temporary Fix


windows 11 wsus fixed
Image credit: Microsoft

Microsoft has shared a temporary workaround for a Windows 11 KB5124008 issue that can cause domain-joined devices to lose their secure trust relationship with an on-premises Active Directory domain. The problem can prevent users from signing in with valid domain credentials and trigger a message saying the trust relationship between the device and the domain failed. Not to forget, the September 2026 update is apparently also breaking printing or many Windows Server 2022 users.

Windows 11 KB5124008 can break domain authentication

According to Microsoft, the issue affects some Credential Guard-protected machine accounts after installing the September 8 security update or later updates. Offline sign-in with previously cached credentials may continue to work, while Active Directory replication and services on domain controllers are not affected.

Microsoft says the problem is connected to Machine Identity Isolation. KB5124008 causes Windows to begin honoring existing or policy-provisioned Machine Identity Isolation enforcement settings. However, the feature is supported only when devices are connected to domain controllers running at Windows Server 2025 Domain Functional Level or higher.

Microsoft has now provided the following workaround. Before modifying the registry, Microsoft recommends backing it up and making sure you know how to restore it if something goes wrong.

  1. If Machine Identity Isolation was enabled by Intune policy, disable Machine Identity Isolation with Intune.
  2. If Machine Identity Isolation was enabled by group policy, disable Machine Identity Isolation with Group Policy.
  3. If Machine Identity Isolation was enabled directly in the registry, use these steps to disable it:

On a Windows 11 version 24H2 or 25H2 device, locate the following registry paths:

HKLM\SYSTEM\CurrentControlSet\Control\Lsa\MachineIdentityIsolation

HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard\MachineIdentityIsolation

For either of these registry keys, if the value for MachineIdentityIsolation = 2, set MachineIdentityIsolation = 0.

After disabling Machine Identity Isolation, restart the device.

Then reset the secure channel using the following command:

Test-ComputerSecureChannel -Repair -Credential (Get-Credential)

KB5124008 has caused several other problems

The domain authentication failure isn’t the only issue faced by users following Windows 11 September 2026 Patch Tuesday update. We previously also reported that KB5124008 could cause Always on VPN connection failures and break shared folders in Hyper-V Linux virtual machines.

Microsoft has also documented Remote Desktop Services failures following the September updates. An out-of-band update released September 14 addressed that issue. That’s not all; the latest Patch Tuesday update also broke USB Audio Class 1.0 devices. Some devices can fail to start, produce no sound or show Code 10 in Device Manager. Microsoft’s September 14 OOB update fixed the 8-channel and 3D audio symptoms, although other USB audio problems remain under investigation.

Microsoft says it plans to address the domain trust problem in a future Windows update by temporarily preventing Machine Identity Isolation enforcement while improvements are made.

More about the topics: KB5124008, microsoft, patch tuesday, Windows 11, Windows Update

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages