Windows 11 KB5124008 Security Update May Break Domain Authentication


windows 11 download more ram attack
Image credit: Microsoft

Windows administrators are reporting that the September 2026 KB5124008 update can break secure-channel trust relationships on domain-joined Windows 11 PCs.

Microsoft has not acknowledged the issue so far, and its emergency KB5129195 / KB5129242 out-of-band updates do not appear to resolve the domain trust failures.

Affected Windows 11 PCs lose their secure channel

One administrator reproduced the problem on six Windows 11 25H2 PCs running KB5124008.

The affected environment initially used Windows Server 2019 domain controllers, but other administrators later reported similar behavior with Windows Server 2022, suggesting the issue is not limited to one server version.

Affected systems return ERROR_NO_TRUST_LSA_SECRET when administrators check the domain secure channel.

Cached credentials can still work while the affected PC remains offline, but domain authentication fails once the system needs to communicate with the domain controller.

KB5124008 appears to trigger the problem

Administrators found that removing KB5124008 and rejoining affected PCs to the domain restored normal operation.

However, uninstalling the update carries security risks because the September Patch Tuesday release fixes 966 vulnerabilities.

Machine Identity Isolation may be involved

Administrators have also identified a possible connection to Microsoft’s Machine Identity Isolation feature.

Changing the MachineIdentityIsolation registry value from 2, which enables enforcement, to 0, which disables the feature, reportedly stopped the secure-channel failures.

Another organization found the setting configured as 1 for Audit mode. Disabling it and repairing the secure channel restored normal domain logins.

The administrator who originally reported the issue later confirmed that disabling Machine Identity Isolation also resolved the problem in their environment.

Group Policy offers another workaround

Administrators also found that setting Machine Identity Isolation to Disabled through Group Policy allows affected systems to repair their secure channel.

Machine Identity Isolation works alongside Credential Guard and changes how Windows protects and virtualizes a computer’s identity during domain authentication.

That connection could explain why domain trust relationships fail after installing KB5124008, although Microsoft has not confirmed the root cause.

For now, disabling Machine Identity Isolation appears to be the main administrator-reported workaround. Rolling back KB5124008 and rejoining the PC to the domain remains another option, though removing the security update is not recommended unless necessary.

Microsoft has also shared a workaround for Remote Desktop problems linked to the September updates.

Via Neowin

More about the topics: KB5124008, microsoft, Windows 11

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages